Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

A company wants to ensure that only authorized users can access sensitive financial data stored in Microsoft SharePoint Online. Which identity feature should they use to require a second form of verification?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Multi-factor authentication

Multi-factor authentication (MFA) is the correct answer because it requires a second form of verification, such as a phone call or app notification, in addition to a password. Conditional Access is a policy engine that can enforce MFA but is not itself a verification method. Self-service password reset and Microsoft Authenticator are features that support MFA but are not the overarching concept.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Authenticator

    Why it's wrong here

    Microsoft Authenticator is a specific application that serves as a method for multi-factor authentication (MFA), often generating one-time passcodes or receiving push notifications. While it provides a second factor, it is merely a tool or an authenticator app, not the overarching security feature or policy that *requires* a second form of verification itself. The question asks for the fundamental security feature that mandates multiple verification factors.

  • Self-service password reset

    Why it's wrong here

    Self-service password reset (SSPR) is an Azure AD feature enabling users to reset their forgotten passwords without administrator intervention, typically by verifying their identity through pre-registered methods like an alternate email or phone number. This capability focuses on account recovery and convenience, not on adding a second, distinct verification factor to a standard login attempt to enhance security against unauthorized access. SSPR does not inherently provide a second form of verification during routine authentication.

  • Conditional Access

    Why it's wrong here

    Conditional Access is a policy engine within Azure Active Directory that evaluates various signals, such as user identity, location, device, and application, to make real-time decisions about access to resources. While it can be configured to *enforce* Multi-factor authentication under specific conditions, Conditional Access itself is not a verification method or a factor of authentication. It is the framework that determines *when* and *how* security controls, including MFA, are applied.

  • Multi-factor authentication

    Why this is correct

    Multi-factor authentication (MFA) is a security process that requires users to provide two or more distinct verification factors from independent categories to prove their identity. By combining something the user knows (e.g., a password), something the user has (e.g., a phone, smart card), or something the user is (e.g., a fingerprint), MFA significantly enhances security by making it much harder for unauthorized users to gain access, directly fulfilling the requirement for a second form of verification.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.