exam questions

Exam MS-900 All Questions

View all questions & answers for the MS-900 exam

Exam MS-900 topic 1 question 417 discussion

Actual exam question from Microsoft's MS-900
Question #: 417
Topic #: 1
[All MS-900 Questions]

A company subscribes to Microsoft 365 and uses Azure Active Directory. Users are required to use a corporate computer and the Microsoft Authenticator app.

The company wants to protect employee device when the employees are out of the country/region.

You need to identify the conditional access signals the company should use.

Which two signals should you identify? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

  • A. cloud apps
  • B. user risk
  • C. group membership
  • D. named location
Show Suggested Answer Hide Answer
Suggested Answer: BD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Jeff261290
Highly Voted 11 months, 3 weeks ago
Selected Answer: BD
Provided answers are correct: Named location can be used to block access from countries/regions where the organization knows traffic shouldn’t come from. This can help to prevent unauthorized access to resources and reduce the risk of data breaches. User risk can be used to detect and respond to risky sign-in behavior. This can include sign-ins from unfamiliar locations or devices, sign-ins from anonymous IP addresses, or sign-ins from infected devices. By detecting and responding to risky sign-in behavior, organizations can help to prevent unauthorized access to resources and protect sensitive data
upvoted 9 times
...
Gajen03
Most Recent 1 year, 1 month ago
he company should use the following two conditional access signals: User or Group Membership: Policies can be targeted to specific users and groups, giving administrators fine-grained control over access1. In this case, the company can target the policies to the employees who are traveling out of the country/region1. IP Location Information: Organizations can create trusted IP address ranges that can be used when making policy decisions1. Administrators can specify entire countries/regions IP ranges to block or allow traffic from1. In this scenario, the company can set up policies to protect employee devices when they are out of the country/region1. These signals, combined with the requirement for employees to use a corporate computer and the Microsoft Authenticator app, will help ensure that the company’s data remains secure even when employees are traveling1.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...