Microsoft Certified Security Compliance And Identity Fundamentals · Free Practice Question Easy
Question 45
Scenario: Mercs for Money is a collection of mercenaries gathered together by Wade Wilson who organized the group and is now a successful Professional Services enterprise. Looking to improve the operations of the organization, Wade has contracted you to assist with several IT projects.
The IT team is planning to apply conditional access policies which can trigger multi-factor authentication if a user attempts to access a specific application.
Is this feasible?
-
A
No
-
B
Yes
Reveal correct answer
Correct answer: B
Explanation
Yes – Is this feasible to apply conditional access policies which can trigger multi-factor authentication if a user attempts to access a specific application.
Conditional Access
The modern security perimeter now extends beyond an organization's network to include user and device identity. Organizations can utilize these identity signals as part of their access control decisions.

https://www.microsoft.com/en-us/videoplayer/embed/RE4MwZs
Conditional Access is the tool used by Azure Active Directory to bring signals together, to make decisions, and enforce organizational policies. Conditional Access is at the heart of the new identity driven control plane.

Conditional Access policies at their simplest are if-then statements, if a user wants to access a resource, then they must complete an action. Example: A payroll manager wants to access the payroll application and is required to perform multi-factor authentication to access it.
Administrators are faced with two primary goals:
• Empower users to be productive wherever and whenever
• Protect the organization's assets
By using Conditional Access policies, you can apply the right access controls when needed to keep your organization secure and stay out of your user's way when not needed.

Important: Conditional Access policies are enforced after first-factor authentication is completed. Conditional Access isn't intended to be an organization's first line of defence for scenarios like denial-of-service (DoS) attacks, but it can use signals from these events to determine access.
Conditional Access policies are enforced after first-factor authentication is completed. Conditional Access isn't intended to be an organization's first line of defence for scenarios like denial-of-service (DoS) attacks, but it can use signals from these events to determine access.
https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/overview
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
