AZ-305 Practice Question: Design identity, governance, and monitoring solutions
Which TWO of the following are true about Microsoft Entra ID Governance features?
⚠ Common exam trap
It's easy for candidates to confuse security features (Conditional Access, Identity Protection) with governance features (Access Reviews, Entitlement Management), leading candidates to select options that enforce access rather than manage its lifecycle.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Access reviews allow administrators to periodically review and attest to access rights.
Microsoft Entra ID Access Reviews enable administrators to periodically review and attest to the access rights of users, groups, or applications, ensuring that only authorized users retain access. This is a core governance feature that helps organizations meet compliance and security requirements by automating the certification process.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conditional Access policies govern access based on location and device.
Why it's wrong here
Conditional Access is an access-control engine that evaluates many signals—user risk, sign-in risk, application, and session context—and can enforce MFA or block access, but it doesn't manage the periodic attestation or automated request lifecycle that define identity governance. Its location and device conditions are only two of many possible conditions, so describing it as 'based on location and device' mischaracterizes its scope and misses its role as a real-time policy layer rather than a governance process.
- ✓
Access reviews allow administrators to periodically review and attest to access rights.
Why this is correct
Access reviews in Microsoft Entra ID are a governance control that enables administrators, or delegated reviewers, to conduct recurring certifications of group memberships, application assignments, and privileged roles. These reviews generate attestation evidence for compliance audits, and, based on the reviewer's decision, automatically remove stale or inappropriate access when configured with auto-apply. That periodic, human-in-the-loop attestation is exactly the access-lifecycle governance the question is asking about.
- ✗
Privileged Identity Management (PIM) provides just-in-time access for all users.
Why it's wrong here
Privileged Identity Management provides just-in-time, time-bound activation for Azure AD roles, Azure resource roles, and other Microsoft services — but only for privileged roles, not all users or all access scenarios. It also adds approval workflows, MFA requirements, and audit history for elevation, so it's a security tool for privileged access management (PAM), not a general governance feature for every user's access. Therefore, saying it applies to 'all users' is false, because non-privileged users' ongoing access is managed by other tools like access reviews and entitlement management.
- ✗
Identity Protection automatically blocks all risky sign-ins.
Why it's wrong here
Identity Protection is a risk-detection service that identifies suspicious behaviors such as impossible travel, atypical sign-ins, and leaked credentials, then surfaces risk levels and lets you build risk-based Conditional Access policies to remediate or block sign-ins. It does not automatically block all risky sign-ins; instead, it offers a range of actions like requiring MFA, resetting passwords, or simply logging risk, and the actual enforcement is delegated to Conditional Access policies you configure. So the assertion of automatic blocking overstates the product's behavior and ignores its advisory and policy-driven nature.
- ✓
Entitlement management enables automation of access request workflows.
Why this is correct
Entitlement management is Microsoft Entra ID's identity-governance feature for automating end-to-end access request workflows, including customized approvals, assignments with expiration, and periodic re-certification. It creates access packages that bundle roles and permissions, letting managers or resource owners grant time-limited access without manual IT intervention, and it can automatically remove access when the assignment expires. This automation of access requests is core to governance because it enforces lifecycle policies consistently and reduces the risk of stale permissions.
Go deeper
Related to this question
About these practice questions
One of 212 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.