Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

A company wants to configure policies that detect risky sign-ins (e.g., from anonymous IPs or unfamiliar locations) and automatically require multi-factor authentication (MFA) when such risk is detected. Which Microsoft Entra ID feature should they use to create these policies?

⚠ Common exam trap

Test-takers frequently confuse Identity Protection (which detects risk) with Conditional Access (which enforces the policy), leading them to select Identity Protection as the answer when the question explicitly asks for the feature that 'creates policies' to require MFA.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra ID Conditional Access

Microsoft Entra ID Conditional Access is the correct feature because it allows administrators to create policies that evaluate sign-in risk signals (such as anonymous IP addresses or unfamiliar locations) and enforce access controls like requiring multi-factor authentication (MFA). Conditional Access policies can integrate with Identity Protection risk detections, but the policy itself is defined and managed within the Conditional Access blade, making it the direct tool for this requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Entra ID Conditional Access

    Why this is correct

    Conditional Access is the actual enforcement layer in Microsoft Entra ID that consumes risk signals, including sign-in risk scores generated by Identity Protection, and applies real-time policies. With conditions such as user risk or sign-in risk, it can require MFA, block access from anonymous IP addresses, or force password change. This policy-based action is exactly what is needed to 'configure policies that detect risky sign-ins' from anonymous sources.

  • ✗

    Microsoft Entra ID Identity Protection

    Why it's wrong here

    Identity Protection is a detection and reporting service that identifies risky sign-ins by analyzing signals like anonymous IP addresses, impossible travel, and leaked credentials, assigning risk levels. However, it does not natively enforce controls; instead, it exposes those risk scores to Conditional Access as conditions. Without Conditional Access, Identity Protection merely alerts on risk but cannot automatically block or require MFA.

  • ✗

    Microsoft Entra ID Privileged Identity Management

    Why it's wrong here

    Privileged Identity Management (PIM) focuses on just-in-time administrative role activation, providing approval workflows and time-bound assignments for Microsoft Entra ID roles and Azure resources. It does not analyze sign-in risk for ordinary end users, nor does it consider anonymous IP addresses as a risk factor for general sign-in policies. Therefore, it is unrelated to configuring policies for risky sign-ins from anonymous sources.

  • ✗

    Microsoft Entra ID Audit Logs

    Why it's wrong here

    Audit Logs in Microsoft Entra ID record sign-in events and directory changes for compliance and forensics, but they are purely a log sink without any policy engine. They cannot evaluate risk levels at runtime or trigger responses like blocking access or requiring MFA. To act on risk, you need a separate policy mechanism such as Conditional Access, which reads those signals and enforces controls.

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.