Objective core.infrastructure-securitySC-900

Describe core infrastructure security services in Azure

Objective core.infrastructure-security sits in Describe capabilities of Microsoft security solutions, which carries 38% of the SCI Fundamentals exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Describe capabilities of Microsoft security solutionsModerate

A financial services company wants to require multifactor authentication only when administrators sign in to the Azure portal, without blocking normal user access to other apps. Which Microsoft Entra capability should they configure?

Correct.

The concept

Conditional Access uses if-then statements that combine signals such as user role and target application to enforce access controls like requiring multifactor authentication.

Why this answer

A Conditional Access policy scoped to administrative roles and the Azure portal app enforces MFA only for that specific sign-in scenario, leaving other access unaffected.

  • Correct: this is exactly the if-then, role-plus-app scoping Conditional Access is designed for.
  • BInsider Risk Management detects risky user activity using logs, it does not enforce sign-in time authentication requirements.
  • CInformation Barriers restricts communication and collaboration between groups, it has no role in authentication enforcement.
  • DPrivileged Access Management provides just-in-time access to sensitive Exchange settings, not MFA enforcement for portal sign-in.
Read the sourceConditional Access overview
Verified against learn.microsoft.com · 2026-07-28
conditional-accesszero-trustentra-idmfa

Now you: objective core.infrastructure-security questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Describe capabilities of Microsoft security solutionsEasy

An identity administrator is reviewing how Microsoft Entra Conditional Access evaluates sign-in requests. Which statement correctly describes when Conditional Access policies take effect?

Sample question 2 of 3

Describe capabilities of Microsoft security solutionsHard

A tenant with Microsoft Entra ID P1 licensing configures a Conditional Access policy to block access when Microsoft Entra ID Protection reports high user risk. The policy never triggers even during confirmed risky sign-ins. What is the most likely cause?

Sample question 3 of 3

Describe capabilities of Microsoft security solutionsEasy

What is Conditional Access described as within Microsoft Entra ID?

Full SCI Fundamentals question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Describe capabilities of Microsoft security solutions