Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

Which TWO features of Microsoft Entra ID help protect against credential compromise? (Choose two.)

⚠ Common exam trap

It's easy for candidates to confuse detection/remediation features (Identity Protection) or policy enforcement (Conditional Access) with direct credential protection mechanisms, leading them to select options that manage risk after compromise rather than preventing weak passwords or brute-force attacks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra Password Protection

Microsoft Entra Password Protection automatically blocks weak passwords and common password variations (e.g., 'Password123!') by comparing them against a global banned password list and an optional custom banned password list. This directly prevents users from setting easily guessable credentials, reducing the risk of credential compromise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Entra Conditional Access

    Why it's wrong here

    Conditional Access is a policy engine that evaluates sign-in signals (user risk, device compliance, location, and application) to enforce access controls such as requiring MFA or blocking access entirely. However, it operates after authentication begins and does nothing to prevent the initial compromise of a password; it only limits what an attacker can do with stolen credentials. Therefore it is not a feature that directly protects the password itself.

  • ✗

    Microsoft Entra Identity Protection

    Why it's wrong here

    Identity Protection is a detection and remediation service that identifies risky sign-in behaviors (e.g., anonymous IP addresses, leaked credentials, unfamiliar properties) and can automatically trigger Conditional Access policies to require additional verification. It is fundamentally reactive: it spots attacks that are already underway or that have used compromised data, but it does not harden the password or prevent brute-force guessing. Hence it does not directly protect credentials from being compromised.

  • ✓

    Microsoft Entra Password Protection

    Why this is correct

    Microsoft Entra Password Protection actively blocks users from selecting weak or easily guessed passwords by maintaining a global banned password list (e.g., 'Password123', 'P@ssw0rd') and allowing tenant administrators to add custom banned words and patterns. It is applied at the point of password creation or change, preventing the credential from ever being set to a vulnerable value. This directly hardens the password against dictionary and guessing attacks, making it a correct answer.

  • ✓

    Microsoft Entra Smart Lockout

    Why this is correct

    Microsoft Entra Smart Lockout automatically locks an account after a configurable number of failed sign-in attempts, using an advanced algorithm that considers the user's sign-in history, IP address, and prior lockout events to avoid locking out legitimate users while effectively stopping brute-force attacks. It throttles repeated password guessing in real time, making it infeasible for attackers to iterate through many passwords. Because it directly prevents credential brute-forcing, it is a correct answer.

  • ✗

    Microsoft Entra access reviews

    Why it's wrong here

    Microsoft Entra access reviews are a governance feature used to periodically certify and revoke user assignment to applications, groups, and roles, enforcing least privilege and removing stale accounts. They address authorization and lifecycle management, not authentication or credential strength, and have no effect on password policies or brute-force resistance. Therefore they are unrelated to the specific goal of protecting against password compromise.

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.