AZ-305 Practice Question: Design identity, governance, and monitoring solutions
Which TWO features of Microsoft Entra ID help protect against credential compromise? (Choose two.)
⚠ Common exam trap
It's easy for candidates to confuse detection/remediation features (Identity Protection) or policy enforcement (Conditional Access) with direct credential protection mechanisms, leading them to select options that manage risk after compromise rather than preventing weak passwords or brute-force attacks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra Password Protection
Microsoft Entra Password Protection automatically blocks weak passwords and common password variations (e.g., 'Password123!') by comparing them against a global banned password list and an optional custom banned password list. This directly prevents users from setting easily guessable credentials, reducing the risk of credential compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra Conditional Access
Why it's wrong here
Conditional Access is a policy engine that evaluates sign-in signals (user risk, device compliance, location, and application) to enforce access controls such as requiring MFA or blocking access entirely. However, it operates after authentication begins and does nothing to prevent the initial compromise of a password; it only limits what an attacker can do with stolen credentials. Therefore it is not a feature that directly protects the password itself.
- ✗
Microsoft Entra Identity Protection
Why it's wrong here
Identity Protection is a detection and remediation service that identifies risky sign-in behaviors (e.g., anonymous IP addresses, leaked credentials, unfamiliar properties) and can automatically trigger Conditional Access policies to require additional verification. It is fundamentally reactive: it spots attacks that are already underway or that have used compromised data, but it does not harden the password or prevent brute-force guessing. Hence it does not directly protect credentials from being compromised.
- ✓
Microsoft Entra Password Protection
Why this is correct
Microsoft Entra Password Protection actively blocks users from selecting weak or easily guessed passwords by maintaining a global banned password list (e.g., 'Password123', 'P@ssw0rd') and allowing tenant administrators to add custom banned words and patterns. It is applied at the point of password creation or change, preventing the credential from ever being set to a vulnerable value. This directly hardens the password against dictionary and guessing attacks, making it a correct answer.
- ✓
Microsoft Entra Smart Lockout
Why this is correct
Microsoft Entra Smart Lockout automatically locks an account after a configurable number of failed sign-in attempts, using an advanced algorithm that considers the user's sign-in history, IP address, and prior lockout events to avoid locking out legitimate users while effectively stopping brute-force attacks. It throttles repeated password guessing in real time, making it infeasible for attackers to iterate through many passwords. Because it directly prevents credential brute-forcing, it is a correct answer.
- ✗
Microsoft Entra access reviews
Why it's wrong here
Microsoft Entra access reviews are a governance feature used to periodically certify and revoke user assignment to applications, groups, and roles, enforcing least privilege and removing stale accounts. They address authorization and lifecycle management, not authentication or credential strength, and have no effect on password policies or brute-force resistance. Therefore they are unrelated to the specific goal of protecting against password compromise.
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.