Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

Your organization uses Microsoft Entra ID with P2 licenses. You need to identify and remediate users who are at risk due to leaked credentials or anomalous sign-in activity. You want to automate the response to high-risk users by requiring a password change. Which feature should you use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra Identity Protection

Microsoft Entra Identity Protection provides risk-based conditional access policies that can automatically require a password change for high-risk users. Option B is wrong because Microsoft Defender for Cloud Apps focuses on cloud application security, not identity risk. Option C is wrong because Microsoft Entra Identity Governance handles access reviews and entitlement management. Option D is wrong because Microsoft Entra Privileged Identity Management (PIM) manages privileged roles, not user risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Entra Identity Protection

    Why this is correct

    Identity Protection detects leaked credentials and anomalous sign-in behaviour via its risk detections, then applies risk-based Conditional Access policies. A policy requiring password change for high-risk users automates remediation, satisfying the P2-licensed requirement to identify and respond to risky users.

  • ✗

    Microsoft Defender for Cloud Apps

    Why it's wrong here

    Defender for Cloud Apps applies session and anomaly policies to SaaS traffic via Conditional Access App Control; it does not compute Entra ID risk detections or force a password reset. It tempts because it surfaces suspicious activity, but Microsoft Entra ID Protection is the engine that scores leaked-credential risk and triggers remediation.

  • ✗

    Microsoft Entra Identity Governance

    Why it's wrong here

    Identity Governance handles access packages, entitlement management and lifecycle workflows; it does not consume sign-in or leaked-credential risk detections or require password changes. It tempts because it is a P2 identity capability, yet Microsoft Entra ID Protection is what detects risk and applies the password-reset remediation automatically.

  • ✗

    Microsoft Entra Privileged Identity Management (PIM)

    Why it's wrong here

    PIM governs just-in-time activation of privileged directory roles and access reviews; it neither evaluates sign-in or credential-leak risk signals nor triggers a password reset. It tempts because it is a P2 identity feature, yet Microsoft Entra ID Protection is what detects risk and enforces the password-change remediation.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.