Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

An organization wants to implement a zero-trust security model. They plan to require multi-factor authentication (MFA) for all users accessing sensitive applications, but only when the sign-in risk is medium or higher. Which Microsoft Entra ID capability should they use?

⚠ Common exam trap

Candidates often confuse Microsoft Entra ID Protection (which detects risk) with the actual policy engine (Conditional Access) that enforces actions like MFA, leading them to select option D instead of B.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Entra ID Conditional Access policy with risk condition

B is correct because Microsoft Entra ID Conditional Access policies allow administrators to enforce MFA based on sign-in risk level, which is evaluated by Microsoft Entra ID Protection. By configuring a policy with a risk condition (e.g., medium or higher), the organization can require MFA only when the sign-in risk meets that threshold, aligning with a zero-trust model that grants access based on real-time risk assessment rather than a static rule.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Entra ID Privileged Identity Management (PIM)

    Why it's wrong here

    Microsoft Entra ID Privileged Identity Management (PIM) is designed to manage, control, and monitor access to important resources by providing just-in-time (JIT) or just-enough-administration (JEA) for privileged roles. While PIM can enforce multi-factor authentication (MFA) during the activation of a privileged role, its primary function is not to dynamically assess sign-in risk for all users to trigger MFA as part of a general Zero Trust strategy for every sign-in attempt. It focuses on limiting the duration and scope of elevated permissions.

  • Microsoft Entra ID Conditional Access policy with risk condition

    Why this is correct

    Microsoft Entra ID Conditional Access policies are the core enforcement engine for Zero Trust principles, allowing organizations to define precise conditions under which users can access resources. By incorporating a "sign-in risk" condition, these policies leverage real-time risk assessments from Microsoft Entra ID Protection. If the sign-in risk meets a predefined threshold, the policy can dynamically enforce specific controls, such as requiring multi-factor authentication (MFA) or blocking access, directly aligning with a risk-based Zero Trust model.

  • Microsoft Defender for Cloud Apps access policy

    Why it's wrong here

    Microsoft Defender for Cloud Apps (MDCA) access policies function as a Cloud Access Security Broker (CASB), primarily focusing on real-time session control and monitoring *after* a user has successfully authenticated to a cloud application. These policies can enforce controls like blocking downloads, monitoring activities, or restricting copy-paste within a session. However, they do not directly evaluate the initial sign-in risk to dynamically trigger multi-factor authentication during the authentication phase itself, which occurs prior to session establishment.

  • Microsoft Entra ID Protection risk detection policy

    Why it's wrong here

    Microsoft Entra ID Protection is instrumental in detecting potential identity-based risks, such as anomalous sign-ins, leaked credentials, or impossible travel, and calculates a user or sign-in risk level. While it identifies and reports these risks, its "risk detection policies" are configured to *detect* and *report* risk, not to *enforce* access controls like requiring MFA or blocking access. The actual enforcement mechanism for these detected risks is handled by Microsoft Entra ID Conditional Access policies, which consume the risk signals from ID Protection.

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.