MS-102 Practice Question: Implement and manage Microsoft Entra identity and access
Your company uses Microsoft Entra ID and wants to use Microsoft's recommendation to protect against password spray attacks. Which feature should you enable?
⚠ Common exam trap
Many exam-takers confuse Identity Protection (which detects risky sign-ins) with the direct mitigation feature Smart Lockout, or they assume MFA alone is sufficient to stop password spray attacks, when in fact Smart Lockout is the specific Microsoft-recommended control for this attack vector.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Smart Lockout
Smart Lockout is Microsoft's recommended feature to protect against password spray attacks because it intelligently locks out bad actors after a threshold of failed attempts while allowing legitimate users to continue. It uses adaptive logic to distinguish between real users and attackers by considering the sign-in pattern and IP address, making it the correct choice for this specific threat.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Smart Lockout
Why this is correct
Smart Lockout in Microsoft Entra ID uses adaptive machine learning to detect and block password spray and brute-force attacks by locking an account after a defined number of failed sign-in attempts. It learns the user's normal sign-in patterns, such as frequently used IP addresses and devices, and adjusts lockout thresholds accordingly, so legitimate users are less likely to be locked out while attackers are effectively denied access. This is precisely the account lockout capability the company needs to prevent attackers from cycling through passwords.
- ✗
Identity Protection
Why it's wrong here
Identity Protection is a risk-based detection service that evaluates sign-in risk and user risk using signals such as anonymous IP addresses, impossible travel, and leaked credentials. While it can trigger Conditional Access policies to require MFA or block risky sign-ins, it does not enforce a lockout after repeated failed attempts; its purpose is to assess and respond to risk, not to throttle authentication attempts. Therefore, Identity Protection alone will not provide the lockout behavior the company wants.
- ✗
Password Hash Synchronization
Why it's wrong here
Password Hash Synchronization is an authentication option that synchronizes a hash of each user's on-premises password to Microsoft Entra ID so that cloud authentication can validate passwords without retaining plaintext credentials. It does not include any account lockout logic; lockout policies are enforced by the on-premises Active Directory or by the cloud authentication settings, but PHS itself is purely a sync mechanism and plays no role in locking accounts after failed sign-in attempts.
- ✗
Multifactor Authentication
Why it's wrong here
Multifactor Authentication requires an additional verification factor, such as a phone code or biometric, to authenticate after the password is correctly entered. This reduces the likelihood of an attacker using a stolen password, but it does not prevent password spray attacks because each attempt still gets a full MFA challenge; MFA is a control for verifying identity, not a throttle or lockout that stops multiple failed attempts. Thus, MFA complements but does not replace the account lockout capability described in the scenario.
Go deeper
Related to this question
Learn chapter
Entra ID Administration
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.