nerdexam
Microsoft

SC-100 · Question #167

You have a Microsoft 365 subscription. You are designing a user access solution that follows the Zero Trust principles of the Microsoft Cybersecurity Reference Architectures (MCRA). You need to…

The correct answer is A. continuous access evaluation E. Conditional Access. Continuous Access Evaluation (CAE) (A) enables Azure AD to push critical security events-account disabled/deleted, password changed/reset, refresh tokens revoked, MFA enabled-to CAE-capable services such as Exchange Online, SharePoint Online, and Teams in near-real-time (within…

Design security operations, identity, and compliance capabilities

Question

You have a Microsoft 365 subscription. You are designing a user access solution that follows the Zero Trust principles of the Microsoft Cybersecurity Reference Architectures (MCRA). You need to recommend a solution that automatically restricts access to Microsoft Exchange Online, SharePoint Online, and Teams in near-real-time (NRT) in response to the following Azure AD events:

  • A user account is disabled or deleted.
  • The password of a user is changed or reset.
  • All the refresh tokens for a user are revoked.
  • Multi-factor authentication (MFA) is enabled for a user.

Which two features should you include in the recommendation? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Options

  • Acontinuous access evaluation
  • BAzure AD Application Proxy
  • Ca sign-in risk policy
  • DAzure AD Privileged Identity Management (PIM)
  • EConditional Access

How the community answered

(32 responses)
  • A
    72% (23)
  • B
    9% (3)
  • C
    16% (5)
  • D
    3% (1)

Explanation

Continuous Access Evaluation (CAE) (A) enables Azure AD to push critical security events-account disabled/deleted, password changed/reset, refresh tokens revoked, MFA enabled-to CAE-capable services such as Exchange Online, SharePoint Online, and Teams in near-real-time (within minutes rather than waiting for token expiry). The service immediately rejects existing sessions upon receiving these events. Conditional Access (E) provides the policy framework that CAE operates within; CAE policies are Conditional Access policies, and the enforcement is triggered through that integration. Azure AD Application Proxy (B) publishes on-premises apps and is unrelated to NRT session revocation for M365 services. A sign-in risk policy (C) evaluates risk at sign-in time but does not revoke active sessions in response to post-sign-in account events. Azure AD PIM (D) manages privileged role activation windows but does not automatically restrict ongoing M365 sessions in near-real-time based on the listed account events.

Topics

#Continuous Access Evaluation#Conditional Access#Zero Trust#Identity and Access Management

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice