Answers and explanations
- A
Explanation: You need to set up a New Location and add the IP ranges for all of your organization's premises. This will ensure that Azure AD has your named/trusted locations established before you set up any policies that may reference them as inclusions or exclusions.
You should not create a new policy to require MFA for all users, but you should set the policy to apply to all locations and exclude all trusted locations. Doing so would not be effective until you have completed the required first step, which is adding the IP addresses that represent your named/trusted locations.
You should not create a new certificate under VPN Connectivity. This task is completely irrelevant to the defined requirement.
You should not set Baseline Policy: End user Protection to Enabled. Baseline policies are inflexible and can only be turned on or off. No granular settings can be modified. At the time of writing this book, baseline policies are scheduled to be deprecated...