Identity Management Flashcards
7 cards from real SC-100 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Identity Management flashcards as text
A company uses Azure AD and wants to enforce that any application requesting access to Microsoft Graph must be pre-approved by an administrator rather than consented to by users. How should this be configured?
Answer: Disable user consent for all applications and require admin consent workflow
Disabling user consent and enabling the admin consent workflow ensures all OAuth permission grants are reviewed and approved by administrators before users can access applications.
An architect is evaluating whether to use Azure AD Password Hash Synchronization (PHS) or Pass-through Authentication (PTA). Which statement correctly represents a security trade-off?
Answer: PHS enables cloud-based Identity Protection risk detections including leaked credential checks
PHS sends hashed password data to Azure AD, enabling cloud-side features like leaked credential detection in Identity Protection, which PTA cannot support without cloud hashes.
During an SC-100 design review, an architect proposes using Azure AD groups to control access to sensitive financial applications. Which additional control should be recommended to meet least-privilege requirements?
Answer: Implement Azure AD Access Reviews to periodically validate group memberships
Access Reviews periodically validate whether users still need their group memberships, removing stale access that accumulates over time and violates least privilege.
Which Azure AD feature allows an organization to verify the authenticity of credentials presented by external partners using decentralized identity standards?
Answer: Microsoft Entra Verified ID
Microsoft Entra Verified ID implements W3C Verifiable Credentials standards, allowing organizations to issue and verify tamper-proof credential claims from partners.
An organization needs to ensure that Azure AD service principals used in CI/CD pipelines authenticate to Azure without using secrets or certificates. Which modern approach should be recommended?
Answer: Use workload identity federation with federated credentials
Workload identity federation lets CI/CD systems (GitHub Actions, GitLab, etc.) authenticate to Azure AD using tokens from their own OIDC provider without any Azure-side secrets.
A security architect must recommend controls to reduce the impact of a compromised global administrator account in Azure AD. Which combination is most effective?
Answer: Require MFA and use Privileged Access Workstations (PAWs) for admin tasks
Combining MFA with dedicated Privileged Access Workstations reduces attack surface by requiring a second factor and isolating admin activities to hardened devices.
What is the key security benefit of implementing Azure AD Conditional Access in report-only mode before enforcing policies?
Answer: It allows architects to evaluate policy impact and identify users who would be blocked before enforcement
Report-only mode evaluates Conditional Access policies against real sign-ins and logs what would happen without actually enforcing the policy, allowing safe impact assessment.