Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

Your company has a hybrid identity environment with 10,000 on-premises users synchronized to Microsoft Entra ID using Microsoft Entra Connect. You plan to implement a modern access control strategy for all cloud applications. The requirements are: enforce multifactor authentication (MFA) for all users when accessing sensitive applications, allow users to self-remediate risky sign-ins via a mobile app, and minimize infrastructure complexity. You need to design the identity and governance solution. What should you do?

⚠ Common exam trap

Test-takers frequently confuse Microsoft Defender for Identity or Microsoft Entra Domain Services with identity protection and access control solutions, overlooking that Entra ID Protection and Conditional Access are the correct cloud-native services for risk-based MFA enforcement and self-remediation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure Microsoft Entra ID Protection to detect risky sign-ins and create a conditional access policy that requires MFA for sensitive apps. Enable the risky user policy to require password change, and use Microsoft Authenticator for self-remediation.

It uses Microsoft Entra ID Protection to detect risky sign-ins and a Conditional Access policy to require MFA for sensitive applications, meeting the MFA enforcement requirement. The risky user policy requiring a password change combined with Microsoft Authenticator for self-remediation allows users to resolve their own risk without admin intervention, satisfying the self-remediation requirement. This approach minimizes infrastructure complexity by relying entirely on cloud-native services rather than on-premises components.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy Microsoft Entra Domain Services and configure Kerberos authentication for cloud apps. Use Azure MFA Server on-premises for MFA enforcement.

    Why it's wrong here

    Microsoft Entra Domain Services supplies a managed domain for legacy workloads that require Kerberos/NTLM/LDAP authentication, but modern cloud apps already authenticate via Microsoft Entra ID, so adding a domain controller does not improve sign-in security. Azure MFA Server is deprecated and should not be used for new deployments; it also cannot consume Entra ID Protection risk signals or enforce Conditional Access policies that trigger self-remediation. Therefore this architecture adds unnecessary infrastructure and fails to address the required risk detection and user self-service recovery.

  • ✓

    Configure Microsoft Entra ID Protection to detect risky sign-ins and create a conditional access policy that requires MFA for sensitive apps. Enable the risky user policy to require password change, and use Microsoft Authenticator for self-remediation.

    Why this is correct

    Microsoft Entra ID Protection continuously evaluates user and sign-in risk signals (e.g., impossible travel, leaked credentials, anonymous IP) and makes them available to Conditional Access policies. A policy can require Microsoft Entra MFA only when a user is classified as risky for sensitive applications, while the user-risk policy can force an authenticated password change to remediate a compromised account. Microsoft Authenticator enables self-remediation by providing number matching and push notifications so a user can approve MFA and then complete a password reset without a helpdesk call.

  • ✗

    Implement Microsoft Defender for Identity to monitor on-premises AD and require MFA via on-premises NPS extension.

    Why it's wrong here

    Microsoft Defender for Identity uses on-premises Active Directory signals and entity behavior analytics with domain controllers or Active Directory Federation Services to detect advanced attacks like Golden Ticket, DCSync, and lateral movement; it does not enforce or require MFA for cloud sign-ins. The NPS extension is specifically designed for VPN or RADIUS scenarios and cannot evaluate the sign-in context of a cloud app or initiate self-service remediation. This combination therefore provides threat detection and limited MFA coverage for remote access, but does not deliver risk-based conditional access or user-driven password recovery as requested.

  • ✗

    Use Microsoft Entra Permissions Management to enforce MFA policies and manage user permissions.

    Why it's wrong here

    Microsoft Entra Permissions Management is a cloud infrastructure entitlement management (CIEM) tool that discovers and remediates excessive privileges across Azure, AWS, and Google Cloud, such as over-privileged service principals and unused roles. It does not process interactive user sign-in risk, configure Conditional Access, or enforce Microsoft Entra MFA challenges, because those responsibilities belong to Microsoft Entra ID Protection and Conditional Access. Managing cross-cloud permissions is unrelated to requiring a self-service password change for genuinely risky identities.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.