Microsoft Security, Compliance, and Identity Fundamentals Microsoft Entra Authentication Methods Flashcards
7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Microsoft Security, Compliance, and Identity Fundamentals Microsoft Entra Authentication Methods flashcards as text
Which Microsoft Entra authentication method sends a push notification to a smartphone requiring user approval?
Answer: Microsoft Authenticator push notification
Microsoft Authenticator push notifications send an approval request to the user's registered phone, which they must accept to complete authentication.
A user's phone is lost. Which action should an admin perform in Microsoft Entra ID to prevent unauthorized access via the lost phone's authenticator app?
Answer: Revoke all refresh tokens and remove the registered MFA device
The admin should revoke the user's refresh tokens (to invalidate active sessions) and remove the lost phone as a registered MFA device from the user's authentication methods.
Which of the following best describes Certificate-Based Authentication (CBA) in Microsoft Entra ID?
Answer: Using a digital certificate on a smart card or device to authenticate without a password
CBA in Microsoft Entra ID allows users to authenticate using X.509 digital certificates stored on smart cards or devices, replacing passwords entirely.
What does the Microsoft Entra ID Authentication Methods policy control?
Answer: Which authentication methods are enabled and for which users or groups
The Authentication Methods policy lets admins configure which methods (e.g., FIDO2, Microsoft Authenticator, SMS) are enabled and which users or groups can use them.
Which scenario correctly describes where Windows Hello for Business stores its private key?
Answer: In a Trusted Platform Module (TPM) on the user's device
Windows Hello for Business stores the private key in the device's TPM chip, ensuring it never leaves the hardware and cannot be extracted remotely.
In Microsoft Entra ID, what is 'MFA fatigue' and how does number matching address it?
Answer: Attackers spamming push notifications hoping users accidentally approve; number matching requires entering a specific number shown at sign-in
MFA fatigue involves attackers sending repeated push notifications until a tired user approves one; number matching defeats this by requiring the user to enter a code visible only during the legitimate sign-in.
Which Microsoft Entra authentication method is best suited for frontline workers who share devices and do not have personal smartphones?
Answer: FIDO2 security keys
FIDO2 security keys are portable hardware tokens that workers can carry personally and use on any shared device without requiring a personal smartphone.