MS-102 Practice Question: Implement and manage Microsoft Entra identity and access
Your company is implementing a Zero Trust security model. You need to ensure that all user access requests to corporate resources are verified continuously, not just at the initial sign-in. Which Microsoft Entra ID feature should you use?
⚠ Common exam trap
Test-takers frequently confuse Identity Protection's risk-based conditional access policies with continuous enforcement, but Identity Protection only triggers a block at sign-in or via a conditional access policy check, not mid-session for every subsequent request.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Continuous Access Evaluation (CAE)
Continuous Access Evaluation (CAE) is the correct choice because it enforces real-time token validation and policy enforcement for every access request, not just at initial authentication. CAE works by having critical events (e.g., user disablement, IP address change, or risk elevation) trigger a revocation message to the resource provider, which then immediately blocks access—even if the token is still valid. This aligns directly with the Zero Trust principle of 'verify explicitly and continuously' rather than relying on a one-time sign-in.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Continuous Access Evaluation (CAE)
Why this is correct
Continuous Access Evaluation (CAE) is the feature that enforces zero trust continuous verification by allowing Entra ID and resource providers to respond in real time to critical events. When a user is disabled, a password is changed, or a conditional access policy is updated, CAE revokes access within seconds—even if the token itself is still technically valid. It does this through a shared token validation mechanism: resource providers like Exchange Online and SharePoint Online consult a revocation table and reject tokens for sessions that have been terminated, instead of waiting for token expiration. This gives administrators immediate, policy-driven access revocation that aligns exactly with the scenario described.
- ✗
Microsoft Entra Identity Protection
Why it's wrong here
Microsoft Entra Identity Protection is incorrect because it detects risky sign-ins using signals such as impossible travel, leaked credentials, and anomalous behavior, but it does not continuously enforce access verification after a session is established. Risk detections are evaluated at sign-in time, and risk-based policies may prompt MFA or block access, yet they do not revoke an already-accepted token when a condition changes mid-session. Identity Protection augments the conditional access workflow with a risk score, but it lacks the real-time token validation that CAE provides—making its enforcement point a one-time check rather than a continuous loop.
- ✗
Microsoft Entra Privileged Identity Management (PIM)
Why it's wrong here
Microsoft Entra Privileged Identity Management (PIM) is wrong because its purpose is to govern administrative roles, not to evaluate every access request from every user. PIM provides just-in-time activation of privileged roles by requiring justifications or approvals, and it can require MFA before activation; however, once the activation window is granted, the user holds that elevated role for the configured duration without per-request, real-time token revocation. This question asks about continuous verification for all users and resources, whereas PIM is narrowly scoped to time-bound elevation of privileged identities and does not continuously reassess the validity of an authenticated session.
- ✗
Microsoft Entra Verified ID
Why it's wrong here
Microsoft Entra Verified ID is not the answer because it is a decentralized identity solution that issues and verifies verifiable credentials, such as proof of employment or certification, rather than performing session-level access evaluation. With Verified ID, an app can cryptographically verify a claim presented by a user's wallet, but this verification happens at issuance or presentation time, not continuously on every resource access attempt. It does not revoke or mutate existing access tokens based on real-time signals, and its technology stack (W3C VC/VP) is wholly different from the token validation pipeline used by CAE. Therefore, Verified ID does not satisfy the requirement for continuous access enforcement.
Go deeper
Related to this question
Learn chapter
Privileged Access Management in M365
Key term
Security model
A security model is a formal framework that defines how subjects (users, processes) can access objects (files, resources) based on rules, ensuring confidentiality, integrity, and availability.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.