Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

A security administrator needs to review all sign-in attempts and identify suspicious login patterns for the past 30 days. Which Microsoft 365 portal should they use to access this information?

⚠ Common exam trap

It's easy for candidates to confuse the Microsoft 365 admin center (which shows basic sign-in activity under 'Health' > 'Sign-in logs') with the full-featured Microsoft Entra ID sign-in logs, but the admin center only provides a limited view and lacks the detailed filtering, risk analysis, and 30-day retention needed for security investigations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra ID sign-in logs

Microsoft Entra ID sign-in logs provide a detailed record of all sign-in attempts, including successful and failed logins, IP addresses, applications used, and risk detections. This data can be filtered and analyzed to identify suspicious patterns such as multiple failed attempts or sign-ins from unusual locations over the past 30 days, making it the correct choice for a security administrator.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Purview compliance portal

    Why it's wrong here

    The Microsoft Purview compliance portal is centered on regulatory and compliance workflows such as eDiscovery, data classification, and audit log search. Its audit log records changes captured by unified audit, but it does not present the full interactive and non-interactive sign-in event schema with fields like conditional access results, MFA outcomes, or risk indicators. For investigating potentially malicious sign-in attempts, an identity-focused log is required, not a compliance-oriented tool.

  • ✗

    Microsoft 365 admin center

    Why it's wrong here

    The Microsoft 365 admin center offers a management view of users, groups, and tenant health, and it shows only a limited summary of user sign-in activity on user detail pages. Detailed sign-in data—including filtering by date, application, or status, plus export capabilities and risk assessment—is available only from Microsoft Entra ID's Sign-in logs. Because the admin center is a management console, it is not the authoritative source for comprehensive sign-in investigation.

  • ✓

    Microsoft Entra ID sign-in logs

    Why this is correct

    Microsoft Entra ID sign-in logs are the authoritative record of every authentication attempt against your Microsoft 365 tenant, captured by the identity provider that issued the token. Each entry includes timestamps, user principal name, application, client IP, device details, conditional access policies applied, MFA requirements, and sign-in error codes—sufficient for correlating suspicious patterns. Investigators can access these logs in the Entra admin center, Azure portal, or via Microsoft Graph APIs, making them the primary tool for this review.

  • ✗

    Microsoft Defender for Cloud Apps

    Why it's wrong here

    Microsoft Defender for Cloud Apps is a CASB that provides usage analytics, anomaly detection, and app-to-app access controls across multiple cloud providers. It consumes and enriches underlying sign-in data from Microsoft Entra ID to generate risk-based alerts, but it does not produce or store the original sign-in log entries. When the requirement is to 'review all sign-in attempts' at the directory level, the source of record remains Entra ID's Sign-in logs rather than Defender's aggregated view.

About these practice questions

This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.