SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Your organization uses Microsoft Entra ID. You need to enforce multi-factor authentication (MFA) for all users accessing the company's financial application. Which security feature should you use?
⚠ Common exam trap
It's easy for candidates to confuse Identity Protection's risk-based policies with direct MFA enforcement, but Identity Protection only provides risk signals and requires Conditional Access to act on them.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access
Conditional Access policies in Microsoft Entra ID allow you to enforce MFA specifically for the financial application by targeting the application in the policy. This provides granular control over authentication requirements based on conditions such as user, location, device state, and application, which is exactly what is needed to secure a specific app.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security defaults
Why it's wrong here
Microsoft Entra ID Security defaults provide a baseline level of security by enforcing multi-factor authentication (MFA) registration and usage for all users and administrative activities across the entire tenant. While effective for broad protection, they lack the granularity required to specifically target and enforce MFA for individual cloud applications. Therefore, Security defaults cannot fulfill the requirement of enforcing MFA per application, as their scope is tenant-wide.
- ✗
Privileged Identity Management
Why it's wrong here
Microsoft Entra Privileged Identity Management (PIM) is designed to manage, control, and monitor access to important resources within an organization. Its core functionality revolves around providing just-in-time (JIT) and just-enough-access for privileged roles, reducing the risk of excessive or standing administrative permissions. While PIM can integrate with Conditional Access to require MFA for role activation, its primary purpose is not to enforce MFA for general user access to specific cloud applications.
- ✗
Identity Protection
Why it's wrong here
Microsoft Entra ID Protection is a security module focused on detecting potential vulnerabilities affecting an organization's identities, including risky sign-ins and compromised credentials. It identifies various risk types and can trigger automated remediation actions, such as requiring password changes or blocking sign-ins. However, Identity Protection's primary function is risk detection and response, not the direct enforcement of multi-factor authentication for specific, non-risky access to individual cloud applications.
- ✓
Conditional Access
Why this is correct
Microsoft Entra Conditional Access is a powerful policy engine that allows organizations to enforce specific access requirements based on various conditions, including user identity, device state, location, and application being accessed. By configuring a Conditional Access policy, administrators can precisely target individual cloud applications and mandate multi-factor authentication as a grant control for access, thereby meeting the requirement to enforce MFA per application. This granular control ensures security without unnecessarily impacting all users or applications.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.