Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

Your organization uses Microsoft Entra ID and has enabled Microsoft Entra ID Protection. You notice that the number of 'Leaked Credentials' detections is high. What action should you take to automatically remediate this risk?

⚠ Common exam trap

Many exam-takers confuse 'automatic password reset' (which is not supported) with 'requiring a password change' (which is supported via a user risk policy), leading them to select Option A instead of C.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a user risk policy in Microsoft Entra ID Protection to require a password change for high-risk users

A user risk policy in Microsoft Entra ID Protection can be configured to automatically trigger a password change when a user is detected as high risk, such as when leaked credentials are identified. This policy directly remediates the risk by forcing the user to update their compromised credentials, effectively invalidating the leaked password. The other options either do not address the root cause or require manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Microsoft Entra ID Protection to automatically reset passwords for all users with leaked credentials

    Why it's wrong here

    Microsoft Entra ID Protection does not offer a built-in action to automatically reset passwords for all users with leaked credentials. It detects leaked credentials and assigns a user risk level, but remediation still requires a user risk policy that is configured with 'Require password change' as the targeted access control. Without such a policy, no password reset occurs, and the leaked credentials remain valid for continued use.

  • ✗

    Configure a conditional access policy to block access for users with high user risk

    Why it's wrong here

    Configuring a Conditional Access policy to block high-user-risk users is an acceptable risk-based response, but it does not remediate the underlying leaked credentials. The user's password remains compromised, so the risk is only suppressed while the block is in force; an attacker who has the password still possesses valid authentication material. Conditional Access can gate access based on user risk, but remediation requires a separate user risk policy action such as forcing a password change.

  • ✓

    Configure a user risk policy in Microsoft Entra ID Protection to require a password change for high-risk users

    Why this is correct

    The correct remediation is to configure a user risk policy in Microsoft Entra ID Protection that assigns 'Require password change' as the access control for high-risk users. When a user is flagged for leaked credentials, this policy forces the user to complete a password change the next time they sign in, which revokes the compromised password and automatically lowers the user's risk back to normal. This is the only built-in, automatically enforced way to remediate leaked credentials in Entra ID.

  • ✗

    Enable Microsoft Entra ID Multifactor Authentication for all users

    Why it's wrong here

    Enabling Microsoft Entra ID Multifactor Authentication for all users does not remediate leaked credentials because the compromised password itself is never changed. MFA only requires an additional verification factor, so it may block a simple password replay, but an attacker with the leaked password and possession of the account still has the original credential material. MFA is a valuable security control, but the leaked credential must be invalidated through a forced password reset to truly resolve the risk.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.