Microsoft Azure Security Engineer Associate AZ-500 Practice Question
Your Azure tenant has two Conditional Access policies: PolicyA: grant access only if the user completes multi-factor authentication. PolicyB: block access when the sign-in risk level is High. Both policies are enabled and target all cloud apps and all users. A user whose sign-in is assessed as High risk successfully completes MFA and tries to open the Azure portal.
What will happen?
The sign-in is allowed because Conditional Access evaluates grant policies before block policies when policies have equal priority.
The sign-in is blocked because a block decision overrides any grant decision when multiple Conditional Access policies apply.
The sign-in is allowed because completing MFA satisfies the requirements of PolicyA and mitigates the high-risk sign-in.
The sign-in is allowed only if the device is compliant; otherwise, it is blocked.
Conditional Access evaluates all enabled policies that apply to the sign-in. If any applicable policy is configured to block access, the sign-in is denied, even when another policy would grant access after MFA. Because PolicyB blocks high-risk sign-ins and applies to the user, the block decision overrides the grant decision from PolicyA. Therefore, the user is prevented from accessing the Azure portal. Completing MFA does not lower the risk score or bypass the block. The other answer choices are incorrect because MFA satisfaction does not supersede a block, evaluation order does not privilege grant controls, and device compliance is irrelevant to the described policies.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Conditional Access in Microsoft Azure?
Open an interactive chat with Bash
How does Conditional Access evaluate multiple policies?
Open an interactive chat with Bash
What is the sign-in risk level and how is it determined?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure identity and access
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .