Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Contoso has a hybrid identity with AD DS synced to Microsoft Entra ID. They want to block legacy authentication protocols that bypass MFA. Which security solution should they use?

⚠ Common exam trap

A common mix-up: candidates confuse Microsoft Entra ID Protection (which detects risky sign-ins) with the actual enforcement mechanism (Conditional Access) that can block legacy authentication, or they mistakenly think Password Protection or Connect Health can control authentication protocols.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Conditional Access policy

Conditional Access policies in Microsoft Entra ID can be configured to block legacy authentication protocols (such as POP3, IMAP, SMTP, and basic authentication) by targeting client apps that do not support modern authentication. This directly prevents bypass of MFA because legacy protocols do not support MFA challenges, making them a common attack vector. By creating a policy that blocks all access from legacy authentication clients, Contoso enforces MFA for all sign-ins that use modern authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Entra Password Protection

    Why it's wrong here

    Microsoft Entra Password Protection is designed to safeguard user accounts by preventing the use of weak, commonly used, or compromised passwords. It enforces password policies by checking against a global banned password list and custom banned lists defined by the organization. This service operates at the password creation and reset stage, ensuring strong password hygiene, but it does not inspect or block specific authentication protocols like legacy authentication.

  • Microsoft Entra ID Protection

    Why it's wrong here

    Microsoft Entra ID Protection focuses on detecting and reporting identity-based risks in real-time, such as leaked credentials, impossible travel, or sign-ins from unfamiliar locations. It uses machine learning to identify suspicious activities and can trigger automated responses like requiring multi-factor authentication or password resets based on risk levels. While it enhances security, its primary role is risk detection and response, not directly blocking authentication attempts based on the protocol used.

  • Microsoft Entra Connect Health

    Why it's wrong here

    Microsoft Entra Connect Health is a monitoring service that provides insights into the health and activity of your on-premises identity infrastructure components, including Microsoft Entra Connect synchronization services, Active Directory Federation Services (AD FS), and Active Directory Domain Services (AD DS). It offers reports on synchronization errors, performance metrics, and operational alerts. This tool is for monitoring and troubleshooting identity synchronization and federation, not for enforcing authentication policies or blocking specific client protocols.

  • Conditional Access policy

    Why this is correct

    A Conditional Access policy is the correct solution because it allows administrators to define conditions under which users can access cloud applications. By configuring a policy to target "Client apps" and specifically selecting "Other clients" or "Exchange ActiveSync clients," organizations can effectively block authentication attempts originating from applications using legacy protocols such as POP3, IMAP4, or older Office clients that do not support modern authentication. This directly addresses the requirement to block legacy authentication.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.