Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

A company wants to automatically detect sign-in attempts from anonymous IP addresses and sign-ins from unfamiliar locations. When such a risk is detected, they want to require multi-factor authentication (MFA) or block the sign-in in real time. Additionally, they need a dashboard that shows risk events and allows generating weekly risk reports. Which Microsoft Entra ID feature should they use?

⚠ Common exam trap

Candidates often confuse Conditional Access as the detection mechanism, but it is only the enforcement layer; Identity Protection is the service that actually detects the risks and provides the risk signals that Conditional Access uses.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra ID Identity Protection

Microsoft Entra ID Identity Protection is the correct feature because it specifically detects sign-in risks such as anonymous IP addresses and unfamiliar locations, and it can automatically enforce conditional access policies like requiring MFA or blocking sign-ins in real time. It also provides a dashboard for risk events and supports generating weekly risk reports, directly matching all stated requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Entra ID Identity Protection

    Why this is correct

    Microsoft Entra ID Identity Protection is the dedicated detection engine that evaluates each sign-in against a set of risk signals, including the anonymous IP address signal, which flags sign-ins originating from Tor, virtual private networks (VPNs), and other IP-anonymizing services. It applies machine-learning models and heuristics to produce a risk score (Low/Medium/High) and generates a risky sign-in report, which can then trigger automated remediation such as requiring multifactor authentication (MFA) or blocking the sign-in. This is the component responsible for the underlying detection, not Conditional Access.

  • ✗

    Microsoft Entra ID Conditional Access

    Why it's wrong here

    Conditional Access is a policy enforcement platform that can consume risk signals, but it does not itself inspect the source IP to determine whether it is anonymous. It supports a condition called 'Risk based policy' (e.g., User risk or Sign-in risk), which relies on the risk assessment already produced by Identity Protection. Therefore, while Conditional Access can block or challenge a sign-in from an anonymous IP, it must first receive the risk signal from Identity Protection; it does not perform the detection autonomously.

  • ✗

    Microsoft Entra ID Privileged Identity Management

    Why it's wrong here

    Privileged Identity Management (PIM) is focused exclusively on time-bound, just-in-time activation of privileged roles such as Global Administrator or Application Administrator, and it provides approval workflows and auditing for role assignments. It has no visibility into the network properties of a sign-in request and does not evaluate sign-in risk signals like anonymous IP addresses. Its purpose is to minimize standing privileges, not to monitor authentication events for suspicious source characteristics.

  • ✗

    Microsoft Entra ID Identity Governance

    Why it's wrong here

    Entra ID Identity Governance is an administrative framework for access lifecycle operations, including access reviews, entitlement management, and identity lifecycle workflows. It is fundamentally a governance and compliance tool, not a real-time security detection mechanism, so it does not analyze sign-in requests for anonymous IP addresses or other risk signals. While it can help clean up overprivileged accounts over time, it cannot trigger an automated response to an anonymously sourced sign-in at the moment it occurs.

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.