Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

A company uses Microsoft Entra ID. They need to monitor sign-in logs for anomalous activity (e.g., sign-ins from unfamiliar locations) and automatically take action such as requiring MFA or blocking sign-in. Which Microsoft Entra ID feature should they configure?

⚠ Common exam trap

Many candidates confuse Conditional Access as the detection mechanism, but it is only the enforcement layer; Identity Protection is the service that performs the actual anomaly detection and risk assessment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identity Protection

Identity Protection is the correct feature because it is specifically designed to detect anomalous sign-in activities, such as sign-ins from unfamiliar locations or anonymous IP addresses, and can automatically trigger risk-based remediation actions like requiring MFA or blocking sign-ins. It leverages machine learning models and real-time risk detections to assess sign-in risks and apply policies accordingly, directly meeting the requirement for monitoring and automated response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Identity Protection

    Why this is correct

    Identity Protection is the correct choice because it continuously evaluates user sign-ins against dozens of risk signals—such as impossible travel, anonymous IP addresses, unfamiliar properties, and leaked credentials—using machine learning models that produce a per-sign-in risk level. It not only flags anomalous activity in real time but also exposes risk history in Entra ID reports, and it can natively trigger automated remediation when paired with a Conditional Access policy (e.g., block sign-in or require MFA). Its purpose is precisely to detect and respond to risky sign-ins rather than to enforce static policies or manage permissions.

  • ✗

    Conditional Access

    Why it's wrong here

    Conditional Access is the enforcement layer, not the detection layer. It evaluates conditions like user, group, device compliance, IP location, and sign-in risk, and then applies controls such as requiring MFA, blocking access, or forcing a password change. Although a Conditional Access policy can reference 'sign-in risk' as a condition, that risk value is computed upstream by Identity Protection—Conditional Access never independently inspects or detects anomalous behavior. Thus, while it can react to risk if configured, it cannot itself monitor sign-ins for anomalies, which is why it is not the correct answer.

  • ✗

    Access Reviews

    Why it's wrong here

    Access Reviews are a governance and identity-lifecycle feature that provides periodic recertification of access rights—for example, confirming whether users still need their group memberships, application assignments, or Entra ID role assignments. These reviews run on a schedule and produce attestation reports, but they do not inspect sign-in events, evaluate risk signals, or provide real-time monitoring. They answer 'should this user still have access?' rather than 'is this sign-in risky?', making them irrelevant to detecting anomalous sign-in activity.

  • ✗

    Privileged Identity Management

    Why it's wrong here

    Privileged Identity Management (PIM) is focused on managing time-based and approval-based activation of elevated Entra ID roles and Azure roles, including features like multi-factor authentication at activation time and just-in-time access. It does not analyze sign-in logs or calculate risk scores for normal (non-elevated) sign-in attempts; its protection applies only to the moment of role activation, not to everyday authentication events. Since the requirement is to monitor sign-in risk broadly across the user population, PIM's narrow scope of privileged role lifecycle management is not a sign-in monitoring solution.

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.