AZ-305 Practice Question: Design identity, governance, and monitoring solutions
Your organization uses Microsoft Entra ID with P2 licensing. You need to implement a strategy to automatically detect and remediate risky sign-ins without requiring user interaction for low-risk events. What should you configure?
⚠ Common exam trap
Many candidates confuse sign-in risk policies (which evaluate individual sign-in events) with user risk policies (which evaluate overall user compromise), leading candidates to select Option C, which addresses user risk rather than the sign-in risk requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identity Protection sign-in risk policy set to allow access and log for low risk, and require MFA for medium and above
The Identity Protection sign-in risk policy allows you to automatically respond to sign-in risk levels. By configuring it to 'allow access' and 'log' for low risk, you meet the requirement of no user interaction for low-risk events, while requiring MFA for medium and above ensures remediation for higher-risk sign-ins without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Identity Protection sign-in risk policy set to allow access and log for low risk, and require MFA for medium and above
Why this is correct
The Identity Protection sign-in risk policy evaluates real-time risk signals for each authentication event, such as anonymous IP addresses, impossible travel, or atypical directory access. Configuring it to allow access and log for low risk automatically remediates low-risk sign-ins by letting them proceed while generating an audit log for later review, while setting the medium-and-above action to require MFA forces stronger authentication only when risk warrants it. This precisely matches a risk-based remediation approach without disrupting ordinary sign-ins.
- ✗
Conditional Access policy with session control requiring MFA for all sign-ins
Why it's wrong here
A Conditional Access policy with a session control requiring MFA for all sign-ins is incorrect because it applies MFA unconditionally to every authentication attempt, regardless of the detected sign-in risk, which directly contradicts the requirement to automatically remediate low risk and require MFA only for medium or higher risk. Additionally, MFA in Conditional Access is enforced through a grant control, not a session control, so this option even misidentifies the mechanism. The result is unnecessary user friction and no risk-aware differentiation.
- ✗
Identity Protection user risk policy set to block high risk
Why it's wrong here
Identity Protection's user risk policy operates on the user account rather than on individual sign-in events; it uses signals like leaked credentials or password spray detection to assess the likelihood of account compromise. Blocking high-risk users does nothing to address a low-risk sign-in that the requirement wants to allow and log, and it does not require MFA for medium sign-in risk because user risk and sign-in risk are independent assessments. Thus this option fails to meet the stated sign-in-focused remediation.
- ✗
Identity Protection sign-in risk policy set to allow access with MFA for medium and above
Why it's wrong here
Configuring the Identity Protection sign-in risk policy to require MFA only for medium and above leaves the low-risk sign-in level completely unhandled, because the policy must explicitly define a control for each risk level you intend to manage. With low risk omitted, low-risk authentication attempts are neither explicitly allowed nor logged, so they are not automatically remediated as the requirement specifies. The missing 'allow with logging' branch for low risk makes this option incomplete even though the medium-and-above action is correct.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.