โ† All SC-900 Flashcard Decks

Microsoft Security, Compliance, and Identity Fundamentals Microsoft Entra Authentication Methods Flashcards

7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Microsoft Security, Compliance, and Identity Fundamentals Microsoft Entra Authentication Methods flashcards as text
  1. Which Microsoft Entra authentication method is considered most resistant to phishing attacks?

    Answer: FIDO2 security keys

    FIDO2 security keys are phishing-resistant because they use public key cryptography bound to the specific site's origin, so credentials cannot be intercepted and replayed on fake sites.

  2. A company wants to allow employees to sign in to Microsoft Entra ID using their fingerprint on a corporate laptop. Which technology enables this?

    Answer: Windows Hello for Business

    Windows Hello for Business uses biometrics (fingerprint, face) or PIN stored locally on the device to authenticate users to Microsoft Entra ID.

  3. What type of cryptography underpins FIDO2 and Windows Hello for Business?

    Answer: Public key (asymmetric) cryptography

    Both FIDO2 and Windows Hello for Business use asymmetric cryptography, where a private key stays on the device and the public key is registered with the identity provider.

  4. Which statement about SMS as an authentication method is accurate in the context of Microsoft Entra security guidance?

    Answer: SMS is less secure than app-based methods due to SIM-swapping risks

    SMS is vulnerable to SIM-swapping attacks where an attacker takes over a phone number, making it less secure than authenticator apps or FIDO2 keys.

  5. In Microsoft Entra ID, what is the purpose of the 'Temporary Access Pass' (TAP)?

    Answer: A time-limited passcode to bootstrap passwordless credential registration

    A Temporary Access Pass is a time-limited, admin-issued passcode that lets users sign in once to register passwordless methods like FIDO2 keys or Microsoft Authenticator.

  6. Which Microsoft Entra feature uses risk signals to require step-up authentication when a user's sign-in appears risky?

    Answer: Identity Protection with risk-based Conditional Access

    Microsoft Entra Identity Protection detects risk signals and integrates with Conditional Access to enforce MFA or block sign-ins when risk is elevated.

  7. What is the minimum number of authentication methods an organization should require users to register for SSPR to ensure resilience?

    Answer: 2

    Microsoft recommends requiring users to register at least 2 authentication methods so they have a backup if one method is unavailable during password reset.