AZ-500 Secure identity and access Practice Question
Your organization uses Microsoft Entra ID for identity management. You need to implement a solution that automatically detects and remediates identity risks such as leaked credentials and impossible travel. The solution must use built-in Microsoft Entra capabilities without additional licensing beyond Microsoft Entra ID P2. What should you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure Identity Protection policies for sign-in risk and user risk.
Configure Identity Protection policies for sign-in risk and user risk. Microsoft Entra ID Protection is the built-in P2 capability that detects identity risks such as leaked credentials (user risk) and impossible travel (sign-in risk), and it can automatically remediate them by requiring MFA or password change through risk-based Conditional Access policies. PIM (A) governs just-in-time privileged role activation and does not detect leaked credentials or impossible travel. Conditional Access requiring MFA for all users (B) enforces a static control and does not perform risk detection or risk-based remediation. Access Reviews for guest users (C) handle periodic attestation of guest access, not identity risk detection or remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Privileged Identity Management (PIM) for role activation.
Why it's wrong here
Privileged Identity Management (PIM) in Microsoft Entra ID provides just-in-time role activation, time-bound assignments, and approval workflows for elevated roles. However, PIM is an access governance control; it does not analyze sign-in telemetry for threats such as leaked credentials, impossible travel, or anomalous user behavior. Enabling PIM would let admins activate roles securely but would never surface the identity-risk detections needed to remediate compromised accounts.
- ✗
Create Conditional Access policies requiring MFA for all users.
Why it's wrong here
Conditional Access policies that require MFA for all users enforce a strong authentication gate during sign-in, but they do not perform risk detection. Conditional Access conditions—like device compliance or location—are evaluated after a sign-in attempt, and they lack machine-learning risk scoring of activities. While MFA can block some attacks, indiscriminate MFA does not identify or automatically remediate accounts that are already compromised or at risk, which is the core requirement here.
- ✗
Set up Access Reviews for guest users.
Why it's wrong here
Access Reviews for guest users are an entitlement-management tool that periodically recertifies whether guests still need access to groups and applications. They rely on reviewers' decisions and do not incorporate risk signals or threat intelligence. Running access reviews can reduce standing privileges but cannot detect identity risks such as password spray attacks or suspicious sign-in patterns, making this option irrelevant for the stated detection/remediation requirement.
- ✓
Configure Identity Protection policies for sign-in risk and user risk.
Why this is correct
Identity Protection in Microsoft Entra ID aggregates machine-learning-based risk detections, including leaked credentials, impossible travel, anonymous IP addresses, and unfamiliar sign-in properties, into user-risk and sign-in-risk levels. You can configure risk-based Conditional Access policies to automatically require MFA or a secure password reset when risk thresholds are exceeded, providing both detection and auto-remediation. This is the service designed specifically to identify and act on identity risks.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.