Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

Your company has a Microsoft 365 E5 tenant with Microsoft Entra ID P2. You are the security administrator. You need to implement a solution that automatically detects and remediates identity risks. Requirements: - Risky sign-ins (e.g., from anonymous IP addresses) should be automatically blocked. - Users with confirmed compromised credentials should be forced to reset their password at next sign-in. - You need to receive alerts when high-risk events occur. - The solution must minimize false positives.

Which Microsoft Entra ID features should you combine?

⚠ Common exam trap

MS-102 often tests the difference between Identity Protection and other security features like Defender for Cloud Apps or Conditional Access alone, and candidates may incorrectly choose a solution that does not include risk-based policies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Microsoft Entra Identity Protection, configure a sign-in risk policy to block high-risk sign-ins, and a user risk policy to require password reset for high-risk users. Set up alerts for risk events.

The correct combination is Microsoft Entra Identity Protection with a sign-in risk policy to block high-risk sign-ins and a user risk policy to require password reset for high-risk users, plus alerts for risk events. Identity Protection uses machine learning to detect risky sign-ins and compromised credentials, and the risk policies automatically remediate based on risk level. This minimizes false positives by using risk-based conditional access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set up Microsoft Entra Identity Governance access reviews and enable self-service password reset.

    Why it's wrong here

    Access reviews and self-service password reset address access governance and user self-service, but they do not generate or consume real-time risk signals. Identity Protection's risk detections—such as leaked credentials or atypical travel—are the basis for automated remediation. Without those risk events, the organization cannot conditionally block or challenge genuinely compromised accounts.

  • ✗

    Configure Conditional Access policies to block sign-ins from anonymous IP addresses and require password reset for all users.

    Why it's wrong here

    Blocking sign-ins from anonymous IP addresses is a static Conditional Access condition that ignores other risk factors, and forcing a password reset for every user creates unacceptable friction and false positives. Adaptive risk policies rely on Identity Protection's per-user and per-sign-in risk scores, not a fixed location list. Thus this approach is too broad and not responsive to actual compromise indicators.

  • ✓

    Enable Microsoft Entra Identity Protection, configure a sign-in risk policy to block high-risk sign-ins, and a user risk policy to require password reset for high-risk users. Set up alerts for risk events.

    Why this is correct

    Microsoft Entra Identity Protection continuously evaluates sign-in and user risk using detections like leaked credentials, impossible travel, and unfamiliar properties. A sign-in risk policy can block high-risk sign-ins, and a user risk policy can require a secure password reset for high-risk users. Configuring alerts for risk events enables investigation. This provides the adaptive, real-time protection the company needs.

  • ✗

    Deploy Microsoft Defender for Cloud Apps to detect risky sign-ins and configure session policies.

    Why it's wrong here

    Defender for Cloud Apps is a CASB focused on discovering cloud apps, assessing their compliance, and applying session-level controls such as download blocking. While it can consume or contribute to risk signals, it does not provide the core risk detections and risk-based user remediation that Identity Protection offers. Using it as the primary mechanism would miss sign-in risk policies and user risk enforcement.

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.