nerdexam
Microsoft

SC-300 · Question #103

factor authentication for all of your users. In preparation for this, you need to ensure that all users are properly registered for multi-factor Authentication. Of the choices below, which one can…

The correct answer is B. Security Question. Why Security Questions Cannot Be Used for MFA in Microsoft Entra ID (Azure AD) Security Questions (Option B) cannot be used as a multi-factor authentication method in Microsoft Entra ID because they are only supported for Self-Service Password Reset (SSPR), not as a second…

Submitted by jordan8· Mar 6, 2026Implement authentication and access management

Question

factor authentication for all of your users. In preparation for this, you need to ensure that all users are properly registered for multi-factor Authentication. Of the choices below, which one can NOT be used as an authentication method?

Options

  • AMicrosoft Authenticator App
  • BSecurity Question
  • CFIDO2 Security Key
  • DSMS
  • EVoice Call

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    87% (26)
  • C
    7% (2)
  • E
    3% (1)

Explanation

Why Security Questions Cannot Be Used for MFA in Microsoft Entra ID (Azure AD)

Security Questions (Option B) cannot be used as a multi-factor authentication method in Microsoft Entra ID because they are only supported for Self-Service Password Reset (SSPR), not as a second factor for MFA sign-in - they are considered too weak and easily guessable to serve as a true authentication factor.

The remaining options are all valid MFA methods: the Microsoft Authenticator App (A) provides push notifications and time-based codes, FIDO2 Security Keys (C) are physical hardware tokens offering phishing-resistant authentication, SMS (D) delivers one-time passcodes via text message, and Voice Call (E) reads a verification code or prompts a key press to confirm identity.

Memory Tip: Think of it this way - "Questions are for Reset, not for MFA." Security questions belong exclusively in the SSPR world. If an exam option sounds like something you'd answer rather than possess or generate, it's likely not a valid MFA method.

Topics

#Multi-factor Authentication#Authentication methods#Azure AD MFA

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice