Soru

Zorluk: OrtaMicrosoft Entra ID Authentication and Conditional Access

NexaHealth is designing an identity and security strategy using Microsoft Entra ID. You need to match each technical requirement to the most appropriate Microsoft Entra ID or Conditional Access feature. Drag the appropriate feature from the column on the right to the matching requirement on the left.

  • Enforce multi-factor authentication (MFA) for administrative roles only when their sign-in attempt is classified as a medium or high risk level.Conditional Access sign-in risk condition
  • Enforce a maximum inactive session lifetime of one hour for web-based access to sensitive clinical portals.Conditional Access session controls
  • Block the use of organization-specific and healthcare-specific terms within user passwords during password creation or reset.Microsoft Entra Password Protection custom list
  • Enable external guest users to authenticate using their existing Google or Facebook accounts without provisioning new credentials.Microsoft Entra External ID identity providers

Cevap

The correct pairings are: Requirement 1 matches 'Conditional Access sign-in risk condition', Requirement 2 matches 'Conditional Access session controls', Requirement 3 matches 'Microsoft Entra Password Protection custom list', and Requirement 4 matches 'Microsoft Entra External ID identity providers'.
Each security and authentication requirement maps to a dedicated feature in Microsoft Entra: sign-in risk policies evaluate session context, session controls manage idle session lifetimes, custom password protection lists prevent insecure industry terms, and external identity provider configuration allows direct federation with third-party accounts.

Adım Adım Çözüm

1
Analyze the requirement to enforce MFA dynamically based on anomalous access patterns.
Identify that the sign-in risk condition assesses the probability of a compromised request in real-time.
This allows targeting MFA prompts specifically to risky authentication attempts rather than every administrative login.
2
Analyze the requirement to limit the duration of inactive web portal sessions.
Determine that session controls within Conditional Access policies manage browser session persistence and sign-in frequency.
These controls enforce a re-authentication prompt once the specified threshold is crossed.
3
Analyze the requirement to restrict the use of industry-specific terms in user passwords.
Determine that Microsoft Entra Password Protection allows uploading a custom list of banned terms.
This list is evaluated alongside the global banned password list to secure password validation.
4
Analyze the requirement to authenticate guest users via existing consumer identity accounts.
Identify that Microsoft Entra External ID identity providers support external federation with identity providers like Google and Facebook.
This avoids provisioning internal credentials for external partners, simplifying governance.

Anahtar Kavram

Selecting the correct Microsoft Entra identity, authentication, and Conditional Access features to satisfy specific security and business compliance requirements.
Tahmini Süre:2m 0s
Bu soruyu puanla