SC-300 Practice Question 3431

Exam: SC-300
Domain: Implement authentication and access management
Difficulty: hard
You want to enforce a policy where privileged administrators can only authenticate using phishing-resistant credentials (FIDO2 security keys, Windows Hello, or Certificate-Based Authentication). Which Conditional Access control should you use?

Answer Options

A
Authentication Strengths specifying Phishing-resistant MFA
B
Basic password complexity rules
C
SMS text verification policies
D
Security Defaults toggle

Correct Answer

A: Authentication Strengths specifying Phishing-resistant MFA

Explanation

Conditional Access Authentication Strengths allow administrators to specify exact combinations of authentication methods, including the built-in "Phishing-resistant MFA" strength.