Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

You are a compliance officer at a healthcare organization that uses Microsoft 365. The organization must comply with HIPAA regulations. You have Microsoft Purview, Microsoft Defender for Cloud Apps, and Microsoft Intune. You need to ensure that all devices accessing patient health information (PHI) are compliant with the organization's security policies, which require device encryption, a minimum OS version, and the use of a compliant mobile device management (MDM) provider. Currently, some devices are not managed by Intune. You need to enforce that only compliant devices can access PHI stored in SharePoint Online. What should you do?

⚠ Common exam trap

SC-900 often tests the boundary between Intune compliance policies (which only classify devices) and Conditional Access (which actually enforces access) — candidates pick the Intune policy thinking it blocks access on its own.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a conditional access policy in Microsoft Entra ID to require compliant devices

Conditional Access in Microsoft Entra ID is the policy engine that evaluates signals such as device compliance state at sign-in time and can grant, block, or require remediation. By creating a CA policy that requires a compliant device (or hybrid Microsoft Entra ID joined device) for the SharePoint Online cloud app, only devices that satisfy the Intune compliance policy (encryption, minimum OS, MDM enrollment) can reach PHI.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a device compliance policy in Microsoft Intune and assign it to all users

    Why it's wrong here

    Compliance policy alone does not enforce access; conditional access is needed.

  • ✗

    Deploy an app protection policy in Microsoft Intune to restrict data access

    Why it's wrong here

    App protection policies apply to apps, not device compliance.

  • ✓

    Configure a conditional access policy in Microsoft Entra ID to require compliant devices

    Why this is correct

    A Microsoft Entra ID conditional access policy with the compliant device grant control blocks unmanaged devices from SharePoint Online, enforcing encryption, minimum OS version and MDM enrolment. Intune compliance policies supply the device state that the policy evaluates.

  • ✗

    Create a DLP policy in Microsoft Purview to block access from non-compliant devices

    Why it's wrong here

    DLP does not enforce device compliance.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.