SC-900 Practice Question: Describe the concepts of security, compliance, and identity
A multinational corporation wants to implement a Zero Trust security model. They plan to verify every access request explicitly, use least privilege access, and assume breach. Which Microsoft security solution should they use to enforce conditional access policies based on user, device, location, and risk?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra Conditional Access
Microsoft Entra Conditional Access is the correct solution for enforcing conditional access policies based on signals like user, device, location, and risk. Option A (Microsoft Sentinel) is a SIEM/SOAR solution for security analytics, not access control. Option B (Microsoft Intune) manages devices but does not enforce access policies on its own. Option D (Microsoft Defender for Cloud Apps) provides cloud app security but is not the primary conditional access engine.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a SIEM and SOAR platform for ingesting logs, detecting threats and automating response; it does not evaluate user, device, location and risk signals to grant or block access. It is tempting because Sentinel supports Zero Trust monitoring, but policy enforcement at sign-in belongs to Microsoft Entra ID Conditional Access.
- ✗
Microsoft Intune
Why it's wrong here
Microsoft Intune handles device enrolment, configuration profiles and compliance state, feeding signals into access decisions but not evaluating them. Conditional Access policies based on user, device, location and risk are enforced by Microsoft Entra ID. Intune is tempting because device compliance is one input those policies consume.
- ✓
Microsoft Entra Conditional Access
Why this is correct
Microsoft Entra Conditional Access evaluates signals including user identity, device compliance, location and sign-in risk, then enforces grant or block decisions per policy. This directly implements the explicit verification and least privilege requirements of the Zero Trust model described.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps is a CASB providing shadow-IT discovery, session controls and app governance, not the engine that evaluates sign-in signals. Conditional Access enforcement across user, device, location and risk sits in Microsoft Entra ID. Defender for Cloud Apps is tempting because it applies conditional access app control for sessions.
Go deeper
Related to this question
Learn chapter
Insider Risk Management
Key term
SIEM
SIEM (Security Information and Event Management) is a system that collects and analyzes log data from across an IT environment to detect and respond to security threats in real time.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.