SC-100 · Question #289
You have a Microsoft 365 E5 subscription and an Azure subscription. You need to recommend a solution to enforce the Zero Trust principle of explicit verification for the subscriptions. The solution…
The correct answer is A. Conditional Access. The correct answer is A: Conditional Access. The Microsoft Cybersecurity Reference Architectures (MCRA) explicitly maps Conditional Access to the Zero Trust principle of 'Verify Explicitly.' This principle requires that every access request be authenticated and authorized using…
Question
You have a Microsoft 365 E5 subscription and an Azure subscription. You need to recommend a solution to enforce the Zero Trust principle of explicit verification for the subscriptions. The solution must be based on Zero Trust guidance in the Microsoft Cybersecurity Reference Architectures (MCRA). What should you include in the recommendation?
Options
- AConditional Access
- BMicrosoft Defender for Identity
- CMicrosoft Defender for Cloud
- DMicrosoft Entra ID Identity Governance
How the community answered
(29 responses)- A72% (21)
- B17% (5)
- C3% (1)
- D7% (2)
Explanation
The correct answer is A: Conditional Access. The Microsoft Cybersecurity Reference Architectures (MCRA) explicitly maps Conditional Access to the Zero Trust principle of 'Verify Explicitly.' This principle requires that every access request be authenticated and authorized using all available signals-identity, device compliance, location, application, data sensitivity, and anomaly detection-before granting access. Conditional Access is the policy engine that evaluates these signals in real time and enforces access controls for both M365 and Azure resources. Defender for Identity (B) focuses on detecting identity-based attacks, not enforcing access policy. Defender for Cloud (C) handles cloud workload security posture. Entra ID Governance (D) addresses identity lifecycle management, which maps to the Zero Trust 'Use Least Privilege Access' principle, not 'Verify Explicitly.'
Topics
Community Discussion
No community discussion yet for this question.