Courseiva

AZ-500 Secure identity and access Practice Question

Your company is implementing a zero-trust security model. You need to ensure that all access to cloud applications is continuously verified based on user identity, device health, and location. Which combination of Microsoft security solutions should you use?

⚠ Common exam trap

The trap here is that candidates often pick Option B (Identity Protection + PIM) because they associate identity protection with zero trust, but they miss the critical need for device health verification (Intune) and continuous session monitoring (Defender for Cloud Apps) that are explicitly required by the question.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra ID Conditional Access, Microsoft Intune, and Microsoft Defender for Cloud Apps

The zero-trust requirement for continuous verification of user identity, device health, and location is met by combining Microsoft Entra ID Conditional Access (enforces policies based on user, device, and location signals), Microsoft Intune (manages device compliance and health), and Microsoft Defender for Cloud Apps (provides continuous session-level monitoring and control of cloud app access). This trio delivers the real-time, policy-driven access checks that zero trust demands.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Sentinel and Azure Policy

    Why it's wrong here

    Sentinel is a cloud-native SIEM that aggregates logs for threat hunting and automated response, while Azure Policy enforces compliance by auditing or remediating resource configuration. Although these tools generate powerful visibility into security events, they do not participate in the authentication or authorization path for individual app requests, so they cannot block or conditionally grant a user's session based on live identity, device, or risk signals. They address governance and detection after the fact, not the continuous verification of every access attempt that zero trust requires.

  • ✗

    Microsoft Entra ID Protection and Privileged Identity Management

    Why it's wrong here

    Entra ID Protection analyzes identity risk indicators such as leaked credentials and impossible travel, and PIM limits privileged access through just-in-time activation and approvals. This combination is purpose-built for detecting compromised identities and securing highly privileged roles, but it leaves out device trust, app-level session restrictions, and data protection policies across SaaS applications. It cannot verify a standard user's access to non-privileged cloud apps or monitor and constrain user activity inside an app session, making it a partial identity risk solution rather than a complete zero trust access control.

  • ✗

    Microsoft Entra Domain Services and Azure Firewall

    Why it's wrong here

    Microsoft Entra Domain Services provides managed domain services such as LDAP, Kerberos, and NTLM for legacy workloads, and Azure Firewall filters network traffic with threat intelligence and application rules. These are foundational infrastructure controls that secure east-west traffic and legacy authentication, but they operate at the network/domain tier, not at the application access tier where zero trust decisions like user location, device compliance, and risk are evaluated. Neither component can natively inspect a cloud app session to enforce a policy such as copy/paste disable or download block, so they fail to satisfy the cloud-app access verification requirement.

  • ✓

    Microsoft Entra ID Conditional Access, Microsoft Intune, and Microsoft Defender for Cloud Apps

    Why this is correct

    Conditional Access acts as the policy enforcement engine that combines user, device, location, and risk signals to require MFA or block sign-in, while Intune supplies the device compliance and configuration evidence that Conditional Access consumes. Defender for Cloud Apps extends enforcement beyond sign-in by applying session controls to discovered SaaS apps, so a flagged user can be allowed in read-only mode or prevented from uploading sensitive files. This identity-device-app trio verifies trust before access, during a session, and on the data plane, which is exactly the continuous verification model zero trust demands.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.