Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

A company uses Microsoft Entra ID (Microsoft Entra ID). They want to automatically detect and respond to high-risk sign-in events, such as sign-ins from malware-linked IP addresses or leaked credentials. When such risks are detected, they want to require multi-factor authentication (MFA) or block the sign-in. They also need a dashboard to review risk events and generate reports. Which Microsoft Entra ID feature should they configure?

⚠ Common exam trap

It's easy for candidates to confuse Conditional Access with Identity Protection, not realizing that Conditional Access is the enforcement mechanism while Identity Protection is the detection and risk-scoring engine that provides the necessary risk signals.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Entra ID Identity Protection

Microsoft Entra ID Identity Protection is the correct feature because it is specifically designed to automatically detect and respond to high-risk sign-in events, such as sign-ins from malware-linked IP addresses or leaked credentials. It provides risk-based conditional access policies that can require MFA or block sign-ins, and it includes a dashboard for reviewing risk events and generating reports. This aligns directly with the scenario's requirements for detection, automated response, and reporting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Entra ID Privileged Identity Management (PIM)

    Why it's wrong here

    PIM is wrong because it is solely an access management feature that handles just-in-time activation, approvals, and expiration of elevated Entra ID roles like Global Administrator. It never inspects authentication attempts or sign-in indicators such as leaked credentials, anonymous IPs, or impossible travel, so it cannot serve as a risk detection or risk reporting service. PIM's purpose is to control who can perform privileged tasks, not to correlate or analyze sign-in threat signals.

  • Microsoft Entra ID Identity Protection

    Why this is correct

    Identity Protection is the correct answer because it is Entra ID's risk detection engine, using signals like leaked credentials, anonymous IP addresses, impossible travel, malware-linked IPs, and unfamiliar sign-in properties to compute per-user and per-risk assignments. It provides an interactive risk dashboard, programmatic risk detection APIs, and supports risk-based Conditional Access policies, such as requiring MFA or blocking access when risk levels exceed a threshold, and can auto-remediate via self-service password reset for confirmed compromised users.

  • Microsoft Entra ID Conditional Access

    Why it's wrong here

    Conditional Access is wrong because it is an enforcement layer that consumes risk signals but does not generate them. Policies evaluate identity signals, including the risk level produced by Identity Protection, to allow, block, or require additional verification like MFA or a compliant device. Without Identity Protection feeding risk scores, Conditional Access has no risk data to evaluate, and it also provides no risk detection dashboard or risk event reporting of its own.

  • Microsoft Entra ID Identity Governance

    Why it's wrong here

    Identity Governance is wrong because it focuses on the lifecycle and management of identity access—entitlements, access reviews, role assignments, and certification workflows—rather than on real-time authentication risk detection. While a compromised account could trigger a governance action after the fact, Identity Governance lacks the analytical pipelines necessary to continuously assess sign-in risk, detect leaked credential usage, or provide a threat-focused risk dashboard.

About these practice questions

Courseiva writes every AZ-305 question from scratch — 212 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.