Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

An organization uses Microsoft Intune to manage devices. They need to ensure that only devices with a compliant antivirus solution can access corporate email. Which policy type should be configured?

⚠ Common exam trap

Candidates often confuse the role of Intune Device compliance policies (which only mark a device as compliant or non-compliant) with the enforcement mechanism of Conditional Access, assuming the compliance policy alone can block access to corporate resources.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Conditional Access policy in Microsoft Entra ID

Conditional Access policies in Microsoft Entra ID evaluate signals such as device compliance status before granting access to cloud apps like corporate email. By integrating with Intune device compliance policies, they can block access from devices that lack a compliant antivirus solution. This is the correct mechanism because Conditional Access enforces the access decision at the authentication layer, not just at the device management layer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • App protection policy in Microsoft 365

    Why it's wrong here

    App protection policies (MAM policies) are designed to safeguard organizational data within specific applications, irrespective of whether the device itself is managed. They enforce data loss prevention controls such as restricting copy/paste, "save as" to personal locations, or requiring a PIN for app access. However, these policies operate strictly at the application layer and do not assess or enforce device-level security postures, like the presence or operational status of antivirus software.

  • Conditional Access policy in Microsoft Entra ID

    Why this is correct

    Conditional Access policies in Microsoft Entra ID serve as the enforcement mechanism, evaluating conditions before granting access to cloud applications and resources. These policies can be configured to mandate that a device be marked as "compliant" by Microsoft Intune. This compliance status, in turn, is determined by Intune device compliance policies, which can include specific requirements for antivirus software being enabled and up-to-date. Consequently, Conditional Access acts as the critical gatekeeper, blocking access if the device's antivirus status, as reported by Intune, fails to meet the defined organizational compliance standards.

  • Device compliance policy in Intune

    Why it's wrong here

    A device compliance policy in Microsoft Intune defines the specific security and health requirements that a managed device must satisfy to be considered "compliant." These policies are crucial for specifying conditions such as the mandatory presence of antivirus software, a minimum operating system version, or disk encryption. While essential for defining the antivirus requirement and reporting a device's compliance status to Intune, this policy itself does not directly block or grant access to resources. It merely assesses and reports compliance; a separate mechanism is required to act upon that reported status.

  • Security baseline in Microsoft Defender for Cloud

    Why it's wrong here

    Security baselines within Microsoft Defender for Cloud are specifically utilized to assess and enhance the security posture of Azure resources, including virtual machines, storage accounts, and databases, against established industry standards and best practices. They provide actionable recommendations and identify misconfigurations within the Azure cloud environment. These baselines are entirely distinct from endpoint device management solutions and do not apply to, nor can they enforce, security settings like antivirus software on devices managed by Microsoft Intune.

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.