SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
An organization uses Microsoft Intune to manage devices. The security team wants to ensure that only devices with a minimum OS version and antivirus enabled can access corporate email. What should they configure?
⚠ Common exam trap
Many candidates confuse a device compliance policy (which only defines rules) with Conditional Access (which enforces access), leading them to select Option D, forgetting that compliance policies alone do not block access to corporate email.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access policy referencing device compliance
A Conditional Access policy referencing device compliance is correct because it allows the security team to enforce access controls based on real-time device health signals, such as minimum OS version and antivirus status. When a device is marked as non-compliant by Intune, the Conditional Access policy blocks access to corporate email (e.g., Exchange Online) until the device meets the required compliance criteria. This combines Intune's compliance evaluation with Azure AD's access enforcement, ensuring only healthy devices can access corporate resources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conditional Access policy referencing device compliance
Why this is correct
A Conditional Access policy is the mechanism that enforces access restrictions based on device health. It evaluates conditions, including the device's compliance status reported by Intune, to determine whether to grant or block access to specified cloud applications or resources. By referencing device compliance, it ensures that only devices meeting the organization's security standards can access sensitive data, effectively linking device posture to resource access control.
- ✗
Device enrollment restrictions
Why it's wrong here
Device enrollment restrictions in Intune control which devices can enrol based on platform, ownership, or model, but they cannot enforce runtime compliance checks such as minimum OS version or antivirus status. This option is tempting because it appears to gate access to corporate resources at enrolment; however, it would be correct only if the goal were to block entire device types or ownership categories from enrolling at all, not to enforce ongoing security configurations on already enrolled devices.
- ✗
App protection policies in Microsoft Defender for Cloud Apps
Why it's wrong here
App protection policies within Microsoft Defender for Cloud Apps (formerly MCAS) primarily focus on real-time session control and data protection within cloud applications, not on the overall compliance state of the device itself. These policies can enforce restrictions like blocking downloads or uploads from non-compliant sessions, but they do not assess the device's operating system version, encryption status, or antivirus presence to gate initial access to corporate resources based on device health.
- ✗
A device compliance policy
Why it's wrong here
A device compliance policy in Microsoft Intune defines the security baseline and configuration requirements that devices must meet, such as minimum OS version, password complexity, or encryption status. While it evaluates devices against these rules and reports their compliance status, a compliance policy alone does not actively block access to corporate resources. Its primary function is to identify non-compliant devices; enforcement of access restrictions requires integration with a Conditional Access policy.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Antivirus
Antivirus is software that detects, prevents, and removes malicious software (malware) from a computer or network.
Key term
Conditional Access policy
A Conditional Access policy is a set of rules in Microsoft Entra ID that automatically grants or blocks access to cloud apps based on signals like user identity, location, device health, and risk level.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.