nerdexam
Microsoft

SC-100 · Question #34

Your company is developing an invoicing application that will use Azure Active Directory (Azure AD) B2C. The application will be deployed as an App Service web app. You need to recommend a solution…

The correct answer is A. Azure AD Conditional Access integration with user flows and custom policies E. smart account lockout in Azure AD B2C. To protect an Azure AD B2C application from identity-related attacks, two controls are appropriate. Conditional Access integration with user flows and custom policies (A) enables enforcement of access controls such as requiring MFA, blocking risky sign-ins, and restricting…

Design security operations, identity, and compliance capabilities

Question

Your company is developing an invoicing application that will use Azure Active Directory (Azure AD) B2C. The application will be deployed as an App Service web app. You need to recommend a solution to the application development team to secure the application from identity related attacks. Which two configurations should you recommend? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Options

  • AAzure AD Conditional Access integration with user flows and custom policies
  • BAzure AD workbooks to monitor risk detections
  • Ccustom resource owner password credentials (ROPC) flows in Azure AD B2C
  • Daccess packages in Identity Governance
  • Esmart account lockout in Azure AD B2C

How the community answered

(35 responses)
  • A
    71% (25)
  • B
    3% (1)
  • C
    9% (3)
  • D
    17% (6)

Explanation

To protect an Azure AD B2C application from identity-related attacks, two controls are appropriate. Conditional Access integration with user flows and custom policies (A) enables enforcement of access controls such as requiring MFA, blocking risky sign-ins, and restricting access based on location or device compliance - directly mitigating identity-based attacks. Smart account lockout in Azure AD B2C (E) automatically locks accounts after a configurable number of failed sign-in attempts, preventing brute-force and password spray attacks. Azure AD workbooks (B) are monitoring/detective tools, not preventative. Custom ROPC flows (C) are considered insecure and are discouraged in production because they expose credentials directly. Access packages in Identity Governance (D) are designed for enterprise entitlement management, not B2C consumer identity security.

Topics

#Azure AD B2C#Conditional Access#Identity Protection#Application Security

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice