SC-900 Practice Question: Describe the concepts of security, compliance, and identity
Which TWO of the following are benefits of using Microsoft Entra ID for identity management? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access policies
Correct answers are B and C. Single sign-on (SSO) allows users to access multiple applications with one set of credentials, improving user experience and security. Conditional Access policies enable organizations to enforce access controls based on conditions like user location, device state, or risk level. Option A (storing passwords in plaintext) is never a benefit and is a security risk. Option D (local authentication for all apps) contradicts the cloud-based identity model of Microsoft Entra ID, which centralizes authentication. Option E (on-premises authentication only) is not a benefit as it limits cloud integration and modern features.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Storing passwords in plaintext
Why it's wrong here
Storing passwords in plaintext is a severe security vulnerability, directly contradicting fundamental security principles and industry best practices. Microsoft Entra ID, like any secure identity system, never stores user passwords in an unencrypted, readable format. Instead, it employs robust hashing and salting techniques to protect credentials, ensuring that even if a data breach occurs, passwords cannot be easily compromised or reverse-engineered. This practice is essential for safeguarding user accounts and organizational data.
- ✓
Conditional Access policies
Why this is correct
Conditional Access policies are a core security feature of Microsoft Entra ID, allowing organizations to enforce granular access controls based on specific, real-time conditions. These policies evaluate factors such as user location, device compliance, application sensitivity, and sign-in risk during an authentication attempt. By dynamically requiring multi-factor authentication, blocking access, or limiting session duration, Conditional Access significantly enhances security posture and compliance without impeding legitimate user productivity.
- ✓
Single sign-on (SSO)
Why this is correct
Single sign-on (SSO) is a fundamental benefit of Microsoft Entra ID, enabling users to authenticate once with a single set of credentials and gain seamless access to numerous connected applications, both cloud-based and on-premises. This significantly enhances user experience by eliminating the need to remember multiple passwords and reduces help desk calls for password resets. Furthermore, SSO improves security by centralizing authentication, facilitating stronger credential management, and simplifying the enforcement of security policies.
- ✗
Local authentication for all apps
Why it's wrong here
Local authentication for all applications means each app manages its own user identities and authentication process independently, creating isolated identity silos. This approach significantly increases administrative overhead, complicates user experience with multiple credentials, and makes centralized security management impossible. It directly opposes the unified identity management and single sign-on (SSO) capabilities offered by Microsoft Entra ID, which aims to centralize authentication across all applications.
- ✗
On-premises authentication only
Why it's wrong here
Relying solely on on-premises authentication severely limits an organization's ability to leverage cloud-based applications and modern identity features provided by Microsoft Entra ID. This approach prevents seamless integration with SaaS applications, restricts access to advanced security capabilities like Conditional Access and identity protection, and hinders the adoption of hybrid identity scenarios. Microsoft Entra ID is designed to extend identity to the cloud, supporting both on-premises and cloud resources for a comprehensive solution.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.