Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

A multinational corporation wants to implement a Zero Trust security model. They plan to verify every access request explicitly, use least privilege access, and assume breach. Which Microsoft security solution should they use to enforce conditional access policies based on user, device, location, and risk?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra Conditional Access

Microsoft Entra Conditional Access is the correct solution for enforcing conditional access policies based on signals like user, device, location, and risk. Option A (Microsoft Sentinel) is a SIEM/SOAR solution for security analytics, not access control. Option B (Microsoft Intune) manages devices but does not enforce access policies on its own. Option D (Microsoft Defender for Cloud Apps) provides cloud app security but is not the primary conditional access engine.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a SIEM and SOAR platform for ingesting logs, detecting threats and automating response; it does not evaluate user, device, location and risk signals to grant or block access. It is tempting because Sentinel supports Zero Trust monitoring, but policy enforcement at sign-in belongs to Microsoft Entra ID Conditional Access.

  • ✗

    Microsoft Intune

    Why it's wrong here

    Microsoft Intune handles device enrolment, configuration profiles and compliance state, feeding signals into access decisions but not evaluating them. Conditional Access policies based on user, device, location and risk are enforced by Microsoft Entra ID. Intune is tempting because device compliance is one input those policies consume.

  • ✓

    Microsoft Entra Conditional Access

    Why this is correct

    Microsoft Entra Conditional Access evaluates signals including user identity, device compliance, location and sign-in risk, then enforces grant or block decisions per policy. This directly implements the explicit verification and least privilege requirements of the Zero Trust model described.

  • ✗

    Microsoft Defender for Cloud Apps

    Why it's wrong here

    Microsoft Defender for Cloud Apps is a CASB providing shadow-IT discovery, session controls and app governance, not the engine that evaluates sign-in signals. Conditional Access enforcement across user, device, location and risk sits in Microsoft Entra ID. Defender for Cloud Apps is tempting because it applies conditional access app control for sessions.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.