nerdexam
Microsoft

SC-900 · Question #185

Hotspot Question For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Answer: Which three forms of…

The correct answer is B. the Microsoft Authenticator app C. SMS messages E. Windows Hello for Business. Microsoft Entra MFA Verification Methods Correct Answers: B, C, E --- A - Security Questions → NO Security questions are not a supported MFA method in Microsoft Entra. They are exclusively a Self-Service Password Reset (SSPR) mechanism. Microsoft explicitly excludes them from…

Submitted by layla.eg· Apr 18, 2026Describe the capabilities of Microsoft Entra ID

Question

Hotspot Question For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Answer:

Which three forms of verification can be used with Microsoft Entra Multi-Factor Authentication (MFA)? Each correct answer presents a complete solution. NOTE: Each correct answer is worth one point.

Exhibits

SC-900 question #185 exhibit 1
SC-900 question #185 exhibit 2

Options

  • Asecurity questions
  • Bthe Microsoft Authenticator app
  • CSMS messages
  • Da smart card
  • EWindows Hello for Business

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    86% (25)
  • D
    10% (3)

Explanation

Microsoft Entra MFA Verification Methods

Correct Answers: B, C, E


A - Security Questions → NO

Security questions are not a supported MFA method in Microsoft Entra. They are exclusively a Self-Service Password Reset (SSPR) mechanism. Microsoft explicitly excludes them from MFA because they are considered too weak (answers can be guessed or socially engineered).


B - Microsoft Authenticator App → YES

This is the primary recommended MFA method. It supports:

  • Push notifications (approve/deny)
  • Passwordless phone sign-in
  • OATH time-based one-time passwords (TOTP)

C - SMS Messages → YES

SMS-based one-time codes are a supported Entra MFA factor. The user receives a 6-digit code via text. It's considered weaker than the Authenticator app (SIM-swapping risk) but is still an officially supported method.


D - Smart Card → NO

Smart cards use certificate-based authentication (CBA), which functions as a primary authentication method, not a standard MFA second factor in the Entra MFA framework. While CBA can satisfy MFA requirements in advanced configurations, it is not listed as one of the core MFA verification options.


E - Windows Hello for Business → YES

Windows Hello for Business uses biometrics or a device-bound PIN and is a fully supported Entra MFA method. It satisfies MFA because it combines something you have (the registered device) with something you are/know (biometric/PIN).


Memory Tip

"MFA = something you HAVE or ARE - not something you KNOW from memory"

  • Security questions = pure knowledge = SSPR only, not MFA
  • Smart card = primary auth, not a second factor
  • Authenticator app, SMS, Windows Hello = all involve a device or biometric you physically possess or embody → valid MFA

Topics

#Multi-Factor Authentication#Microsoft Entra ID#Authentication methods

Community Discussion

No community discussion yet for this question.

Full SC-900 Practice