AZ-305 Practice Question: Design identity, governance, and monitoring solutions
A company uses Microsoft Entra ID (Microsoft Entra ID). They want to automatically detect and respond to high-risk sign-in events, such as sign-ins from malware-linked IP addresses or leaked credentials. When such risks are detected, they want to require multi-factor authentication (MFA) or block the sign-in. They also need a dashboard to review risk events and generate reports. Which Microsoft Entra ID feature should they configure?
⚠ Common exam trap
It's easy for candidates to confuse Conditional Access with Identity Protection, not realizing that Conditional Access is the enforcement mechanism while Identity Protection is the detection and risk-scoring engine that provides the necessary risk signals.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID Identity Protection
Microsoft Entra ID Identity Protection is the correct feature because it is specifically designed to automatically detect and respond to high-risk sign-in events, such as sign-ins from malware-linked IP addresses or leaked credentials. It provides risk-based conditional access policies that can require MFA or block sign-ins, and it includes a dashboard for reviewing risk events and generating reports. This aligns directly with the scenario's requirements for detection, automated response, and reporting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra ID Privileged Identity Management (PIM)
Why it's wrong here
PIM is wrong because it is solely an access management feature that handles just-in-time activation, approvals, and expiration of elevated Entra ID roles like Global Administrator. It never inspects authentication attempts or sign-in indicators such as leaked credentials, anonymous IPs, or impossible travel, so it cannot serve as a risk detection or risk reporting service. PIM's purpose is to control who can perform privileged tasks, not to correlate or analyze sign-in threat signals.
- ✓
Microsoft Entra ID Identity Protection
Why this is correct
Identity Protection is the correct answer because it is Entra ID's risk detection engine, using signals like leaked credentials, anonymous IP addresses, impossible travel, malware-linked IPs, and unfamiliar sign-in properties to compute per-user and per-risk assignments. It provides an interactive risk dashboard, programmatic risk detection APIs, and supports risk-based Conditional Access policies, such as requiring MFA or blocking access when risk levels exceed a threshold, and can auto-remediate via self-service password reset for confirmed compromised users.
- ✗
Microsoft Entra ID Conditional Access
Why it's wrong here
Conditional Access is wrong because it is an enforcement layer that consumes risk signals but does not generate them. Policies evaluate identity signals, including the risk level produced by Identity Protection, to allow, block, or require additional verification like MFA or a compliant device. Without Identity Protection feeding risk scores, Conditional Access has no risk data to evaluate, and it also provides no risk detection dashboard or risk event reporting of its own.
- ✗
Microsoft Entra ID Identity Governance
Why it's wrong here
Identity Governance is wrong because it focuses on the lifecycle and management of identity access—entitlements, access reviews, role assignments, and certification workflows—rather than on real-time authentication risk detection. While a compromised account could trigger a governance action after the fact, Identity Governance lacks the analytical pipelines necessary to continuously assess sign-in risk, detect leaked credential usage, or provide a threat-focused risk dashboard.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 212 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.