SC-900 Describe the capabilities of Microsoft Entra Practice Question
Exhibit
Refer to the exhibit.
```json
{
"conditions": {
"applications": { "includeApplications": ["Office365"] },
"users": { "includeUsers": ["All"] },
"locations": {
"includeLocations": ["All"],
"excludeLocations": ["AllTrusted"]
}
},
"grantControls": {
"operator": "OR",
"builtInControls": ["mfa", "compliantDevice"]
}
}
```You are reviewing a Conditional Access policy JSON:
{
"displayName": "Require MFA or compliant device for Office 365 from untrusted locations",
"state": "enabled",
"conditions": {
"users": {
"includeUsers": ["All"]
},
"applications": {
"includeApplications": ["Office365"]
},
"locations": {
"includeLocations": ["All"],
"excludeLocations": ["AllTrusted"]
}
},
"grantControls": {
"operator": "OR",
"builtInControls": ["mfa", "compliantDevice"]
}
}What is the result of this policy?
⚠ Common exam trap
The trap here is that candidates often misread the 'OR' condition as 'AND' or assume the policy applies to all cloud apps instead of the specific app (Office 365), leading them to choose options A or C.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Users from untrusted locations must complete MFA or use a compliant device to access Office 365
The policy JSON grants access to Office 365 if the user is from an untrusted location and either completes MFA or uses a compliant device. This matches option B exactly. The 'OR' condition between MFA and compliant device is key, and the scope is limited to Office 365, not all cloud apps.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
All users must complete MFA to access all cloud apps
Why it's wrong here
This statement is incorrect because a Conditional Access policy JSON would explicitly define the targeted cloud applications. If the policy targets "Office 365," it would specify `cloudApp` as `Office 365` or a specific set of Microsoft cloud services, not a broad `All cloud apps`. Furthermore, the grant controls might include more than just MFA or use an OR condition, making the "must complete MFA" part potentially incomplete.
- ✓
Users from untrusted locations must complete MFA or use a compliant device to access Office 365
Why this is correct
This statement accurately describes a common Conditional Access policy configuration. The policy's `locations` condition would typically `exclude` "Trusted locations," thereby targeting users originating from *untrusted* IP ranges. The `cloudApp` condition would specify `Office 365`, and the `grantControls` would require `multiFactorAuthentication` *or* `compliantDevice`, indicating that either condition satisfies the access requirement.
- ✗
Users must complete MFA and use a compliant device from all locations
Why it's wrong here
This statement is incorrect for two primary reasons. Firstly, the `grantControls` in the policy JSON would specify an `operator` of `OR` if either MFA *or* a compliant device is sufficient, not an implicit "AND" as suggested. Secondly, the policy's `locations` condition would likely exclude specific trusted locations, meaning it does not apply uniformly to "all locations" without distinction, but rather to a subset.
- ✗
Users from trusted locations must complete MFA and use a compliant device
Why it's wrong here
This statement is incorrect because Conditional Access policies often use the `exclude` clause within the `locations` condition to explicitly bypass requirements for users originating from "Trusted locations." If trusted locations are excluded, the policy's grant controls, such as requiring MFA and a compliant device, would not be enforced for users accessing resources from those specific, pre-defined trusted IP ranges.
Go deeper
Related to this question
Learn chapter
Azure Policy and Initiatives
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.