# First official practice assessment: 82% (41/50), Conditional Access recognition missed twice

Taken 2026-08-05, after completing all 16 planned lessons. Scored 82% overall, below the 85%+ target in [[MISSION]]. Weakest section per the official breakdown: "Describe Azure architecture and services" (Domain 2).

**The repeat pattern:** two separate questions (device-compliance-gated access to an app; approved-client-app-only access to Microsoft 365) both called for **Conditional Access**, and the user picked MFA and RBAC respectively instead. Same root cause both times — recognizing a *condition being evaluated* (device, app, location, risk) as the Conditional Access signature, versus an extra identity proof (MFA) or a permission grant (RBAC). This is a scenario-recognition gap, not a definitional one — Lesson 9's definition of Conditional Access was answered correctly when tested directly back in that lesson.

**Genuine content gaps** (not recall failures — never taught): service endpoints (connecting a VNet to a PaaS resource like Azure SQL), Azure Files' supported protocols (SMB + NFS, not FTP), SaaS's subscription-based licensing model vs. IaaS/PaaS consumption-based pricing, and Azure Advisor vs. Azure Policy (recommends vs. enforces). All patched into [[0017-practice-assessment-gap-patch]].

**Implications:** retake the practice assessment (Day 19 on [[study-roadmap]]) as a fresh attempt, not a memorized repeat of the same 50 questions. Watch Conditional Access scenario questions specifically on the retake — a single explanation pass in Lesson 17 shouldn't be assumed to have fixed a pattern that showed up twice.
