SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Which TWO of the following are benefits of using Microsoft Entra ID Conditional Access? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Block access from locations that are not trusted
Conditional Access policies can enforce multi-factor authentication based on user risk (D) and block access from untrusted locations (B). Option A (allow users to reset their own passwords) is a feature of self-service password reset (SSPR), not Conditional Access. Option C (automatically grant temporary admin access) is a benefit of Privileged Identity Management (PIM). Option E (eliminate the need for passwords entirely) is related to passwordless authentication, not Conditional Access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Allow users to reset their own passwords
Why it's wrong here
Self-Service Password Reset (SSPR) is a valuable feature of Azure AD that empowers users to securely reset their forgotten passwords without IT intervention. While SSPR is included in Azure AD Premium (a component of Microsoft E), it is a foundational identity management capability rather than a direct benefit of the advanced, adaptive access control and identity protection features typically highlighted within "Microsoft E" for dynamic security enforcement. The question seeks benefits related to intelligent access control.
- ✓
Block access from locations that are not trusted
Why this is correct
Microsoft Entra Conditional Access, a core component of Microsoft E (Enterprise Mobility + Security), enables organizations to define granular access policies based on various conditions, including network location. By configuring trusted IP ranges or blocking specific countries/regions, administrators can prevent unauthorized access attempts from untrusted geographical locations, significantly reducing the attack surface and enhancing security posture. This directly leverages the adaptive capabilities of Entra.
- ✗
Automatically grant temporary admin access
Why it's wrong here
Privileged Identity Management (PIM) is the Microsoft Entra feature designed to manage, control, and monitor access to important resources, including just-in-time (JIT) and just-enough-administration (JEA) for temporary administrative roles. While PIM is a crucial part of the Microsoft E suite, this capability focuses on privilege management rather than the dynamic access control and risk-based enforcement benefits that are typically emphasized when discussing the core security advantages of "Microsoft E" in the context of Conditional Access and Identity Protection.
- ✓
Enforce multi-factor authentication based on user risk
Why this is correct
Microsoft Entra Identity Protection, a key feature within Microsoft E, continuously monitors user sign-ins and behaviors for suspicious activities and risk indicators. When a high-risk sign-in or user risk is detected, Conditional Access policies can be configured to automatically enforce multi-factor authentication (MFA) challenges, requiring additional verification before granting access. This adaptive approach ensures stronger authentication is applied precisely when and where it's most needed, mitigating potential compromises.
- ✗
Eliminate the need for passwords entirely
Why it's wrong here
While Microsoft Entra ID supports various passwordless authentication methods like Windows Hello for Business, FIDO2 security keys, and the Microsoft Authenticator app, "eliminating the need for passwords entirely" represents a broader authentication strategy rather than a direct, inherent benefit of the core adaptive security features of "Microsoft E" like Conditional Access or Identity Protection. These features primarily focus on managing and securing access using existing or enhanced credentials, not solely on their complete replacement.
Go deeper
Related to this question
Learn chapter
Identity Concepts
Key term
Passwordless authentication
Passwordless authentication is a method of verifying a user's identity without requiring them to enter a password, using alternative factors like biometrics, hardware tokens, or one-time codes.
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.