AZ-500 Secure identity and access Practice Question
Your company is implementing a zero-trust security model. You need to ensure that all access to cloud applications is continuously verified based on user identity, device health, and location. Which combination of Microsoft security solutions should you use?
⚠ Common exam trap
The trap here is that candidates often pick Option B (Identity Protection + PIM) because they associate identity protection with zero trust, but they miss the critical need for device health verification (Intune) and continuous session monitoring (Defender for Cloud Apps) that are explicitly required by the question.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID Conditional Access, Microsoft Intune, and Microsoft Defender for Cloud Apps
The zero-trust requirement for continuous verification of user identity, device health, and location is met by combining Microsoft Entra ID Conditional Access (enforces policies based on user, device, and location signals), Microsoft Intune (manages device compliance and health), and Microsoft Defender for Cloud Apps (provides continuous session-level monitoring and control of cloud app access). This trio delivers the real-time, policy-driven access checks that zero trust demands.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Sentinel and Azure Policy
Why it's wrong here
Sentinel is a cloud-native SIEM that aggregates logs for threat hunting and automated response, while Azure Policy enforces compliance by auditing or remediating resource configuration. Although these tools generate powerful visibility into security events, they do not participate in the authentication or authorization path for individual app requests, so they cannot block or conditionally grant a user's session based on live identity, device, or risk signals. They address governance and detection after the fact, not the continuous verification of every access attempt that zero trust requires.
- ✗
Microsoft Entra ID Protection and Privileged Identity Management
Why it's wrong here
Entra ID Protection analyzes identity risk indicators such as leaked credentials and impossible travel, and PIM limits privileged access through just-in-time activation and approvals. This combination is purpose-built for detecting compromised identities and securing highly privileged roles, but it leaves out device trust, app-level session restrictions, and data protection policies across SaaS applications. It cannot verify a standard user's access to non-privileged cloud apps or monitor and constrain user activity inside an app session, making it a partial identity risk solution rather than a complete zero trust access control.
- ✗
Microsoft Entra Domain Services and Azure Firewall
Why it's wrong here
Microsoft Entra Domain Services provides managed domain services such as LDAP, Kerberos, and NTLM for legacy workloads, and Azure Firewall filters network traffic with threat intelligence and application rules. These are foundational infrastructure controls that secure east-west traffic and legacy authentication, but they operate at the network/domain tier, not at the application access tier where zero trust decisions like user location, device compliance, and risk are evaluated. Neither component can natively inspect a cloud app session to enforce a policy such as copy/paste disable or download block, so they fail to satisfy the cloud-app access verification requirement.
- ✓
Microsoft Entra ID Conditional Access, Microsoft Intune, and Microsoft Defender for Cloud Apps
Why this is correct
Conditional Access acts as the policy enforcement engine that combines user, device, location, and risk signals to require MFA or block sign-in, while Intune supplies the device compliance and configuration evidence that Conditional Access consumes. Defender for Cloud Apps extends enforcement beyond sign-in by applying session controls to discovered SaaS apps, so a flagged user can be allowed in read-only mode or prevented from uploading sensitive files. This identity-device-app trio verifies trust before access, during a session, and on the data plane, which is exactly the continuous verification model zero trust demands.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.