nerdexam
Microsoft

SC-100 · Question #154

You have an on-premises network and a Microsoft 365 subscription. You are designing a Zero Trust security strategy. Which two security controls should you include as part of the Zero Trust solution?…

The correct answer is C. Block sign-in attempts from unknown locations. D. Block sign-in attempts from noncompliant devices. Zero Trust operates on 'never trust, always verify' - every access request must be validated regardless of its origin. Blocking sign-ins from unknown locations (C) enforces location-based conditional access, rejecting unrecognized or risky network origins. Blocking sign-ins…

Design security operations, identity, and compliance capabilities

Question

You have an on-premises network and a Microsoft 365 subscription. You are designing a Zero Trust security strategy. Which two security controls should you include as part of the Zero Trust solution? Each correct answer presents part of the solution. NOTE: Each correct answer is worth one point.

Options

  • AAlways allow connections from the on-premises network.
  • BDisable passwordless sign-in for sensitive accounts.
  • CBlock sign-in attempts from unknown locations.
  • DBlock sign-in attempts from noncompliant devices.

How the community answered

(31 responses)
  • A
    13% (4)
  • B
    3% (1)
  • C
    84% (26)

Explanation

Zero Trust operates on 'never trust, always verify' - every access request must be validated regardless of its origin. Blocking sign-ins from unknown locations (C) enforces location-based conditional access, rejecting unrecognized or risky network origins. Blocking sign-ins from noncompliant devices (D) enforces device health compliance before granting access. Always allowing on-premises connections (A) directly violates Zero Trust by implicitly trusting an entire network segment. Disabling passwordless sign-in (B) reduces security rather than improving it, contradicting Zero Trust's strong authentication pillar.

Topics

#Zero Trust#Conditional Access#Identity Protection#Device Compliance

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice