MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
You are a security administrator. You need to configure a policy that automatically blocks sign-ins from anonymous IP addresses for all users in your Microsoft 365 tenant. Which policy should you configure in Microsoft Entra ID?
⚠ Common exam trap
MS-102 often tests the distinction between sign-in risk (real-time authentication signals like anonymous IP) and user risk (compromised credential indicators), causing candidates to pick the wrong condition.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access policy with sign-in risk condition
Anonymous IP address sign-ins are a sign-in risk detection in Microsoft Entra ID Protection. To automatically block them for all users, you configure a Conditional Access policy that targets All users and uses the sign-in risk condition set to High (or the specific 'Anonymous IP address' risk), with the access control set to Block. Sign-in risk evaluates the authentication attempt itself, which is exactly what anonymous IP represents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Password protection policy
Why it's wrong here
Password protection policies enforce banned-password lists and custom lockout settings; they do not evaluate sign-in origin. It is tempting because it is a tenant-wide Microsoft Entra ID security control, but it would be correct for preventing weak or banned passwords, not for blocking anonymous IP addresses.
- ✗
Conditional Access policy with user risk condition
Why it's wrong here
A Conditional Access policy with a user risk condition triggers on signals such as leaked credentials, not on the network origin of a sign-in. It is tempting because Conditional Access is the correct policy family, but anonymous IP blocking requires the sign-in risk condition or a named location condition instead.
- ✓
Conditional Access policy with sign-in risk condition
Why this is correct
A Conditional Access policy with the sign-in risk condition evaluates Microsoft Entra ID Protection signals and blocks sign-ins assessed as risky, including anonymous IP usage. Applying it to all users satisfies the requirement to automatically block anonymous-IP sign-ins tenant-wide.
- ✗
Identity Protection user risk policy
Why it's wrong here
An Identity Protection user risk policy responds to compromised-credential indicators, remediating or blocking based on user risk level, not anonymous IP origin. It is tempting because it is an automated Microsoft Entra ID sign-in control, but it would be correct for leaked-credential scenarios rather than anonymous proxy sign-ins.
Go deeper
Related to this question
Learn chapter
Hybrid Modern Authentication
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.