Courseiva

AZ-500 Secure identity and access Practice Question

You are a security administrator for a financial institution. You need to implement a solution that allows users to authenticate using biometrics and prevents password-based attacks. Which Microsoft Entra ID feature should you enable?

⚠ Common exam trap

A common mix-up: candidates confuse Azure MFA (which still requires a password) with passwordless methods, mistakenly thinking MFA alone eliminates password-based attacks, when in fact it only adds a second layer after the password is entered.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Passwordless authentication (FIDO2 or Windows Hello for Business)

Passwordless authentication methods like FIDO2 and Windows Hello for Business eliminate the use of passwords entirely, thereby preventing password-based attacks such as brute force, phishing, and credential stuffing. Biometric verification (e.g., fingerprint or facial recognition) is a core component of these methods, meeting the requirement for biometric authentication. This aligns with the Zero Trust principle of reducing the attack surface by removing shared secrets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Entra ID Protection

    Why it's wrong here

    Microsoft Entra ID Protection is a risk-based detection and remediation service, not an authentication method. It analyzes signals such as leaked credentials, impossible travel, and anonymous IP addresses to assign a risk score and trigger conditional access policies, but it still relies on the user presenting a password as the primary factor. While it can force a password reset or require MFA, it does nothing to remove passwords from the authentication flow, so it fails the goal of eliminating password-based attacks.

  • ✓

    Passwordless authentication (FIDO2 or Windows Hello for Business)

    Why this is correct

    Passwordless authentication using FIDO2 security keys or Windows Hello for Business replaces the password entirely with public/private key cryptography. The private key never leaves the device and is unlocked by a biometric gesture (fingerprint or face) or a PIN, while the public key is registered with Microsoft Entra ID. Because no shared secret is transmitted over the network, these methods are phishing-resistant and eliminate the most common attack vectors like password spraying and credential theft, making this the only option that truly removes passwords.

  • ✗

    Password hash synchronization

    Why it's wrong here

    Password hash synchronization is a directory synchronization feature that copies the SHA-256 hash of a user's on-premises Active Directory password to Microsoft Entra ID so that cloud sign-ins can be validated. It does not eliminate passwords; in fact, it makes the password hash a high-value target because an attacker who obtains a hash can use pass-the-hash or offline cracking techniques. This option simply migrates the password problem to the cloud rather than removing the password as an authentication factor.

  • ✗

    Azure Multi-Factor Authentication

    Why it's wrong here

    Azure Multi-Factor Authentication (MFA) adds a second verification step, such as a phone call, authenticator app, or SMS, but it still requires the user's password as the first factor. MFA reduces the likelihood of successful credential theft because an attacker needs both factors, but passwords remain vulnerable to phishing, keylogging, and brute-force attacks. MFA is an essential security control, but it is not passwordless and does not prevent password-based attacks at the source.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.