MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
A security administrator needs to review all sign-in attempts and identify suspicious login patterns for the past 30 days. Which Microsoft 365 portal should they use to access this information?
⚠ Common exam trap
It's easy for candidates to confuse the Microsoft 365 admin center (which shows basic sign-in activity under 'Health' > 'Sign-in logs') with the full-featured Microsoft Entra ID sign-in logs, but the admin center only provides a limited view and lacks the detailed filtering, risk analysis, and 30-day retention needed for security investigations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID sign-in logs
Microsoft Entra ID sign-in logs provide a detailed record of all sign-in attempts, including successful and failed logins, IP addresses, applications used, and risk detections. This data can be filtered and analyzed to identify suspicious patterns such as multiple failed attempts or sign-ins from unusual locations over the past 30 days, making it the correct choice for a security administrator.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Purview compliance portal
Why it's wrong here
The Microsoft Purview compliance portal is centered on regulatory and compliance workflows such as eDiscovery, data classification, and audit log search. Its audit log records changes captured by unified audit, but it does not present the full interactive and non-interactive sign-in event schema with fields like conditional access results, MFA outcomes, or risk indicators. For investigating potentially malicious sign-in attempts, an identity-focused log is required, not a compliance-oriented tool.
- ✗
Microsoft 365 admin center
Why it's wrong here
The Microsoft 365 admin center offers a management view of users, groups, and tenant health, and it shows only a limited summary of user sign-in activity on user detail pages. Detailed sign-in data—including filtering by date, application, or status, plus export capabilities and risk assessment—is available only from Microsoft Entra ID's Sign-in logs. Because the admin center is a management console, it is not the authoritative source for comprehensive sign-in investigation.
- ✓
Microsoft Entra ID sign-in logs
Why this is correct
Microsoft Entra ID sign-in logs are the authoritative record of every authentication attempt against your Microsoft 365 tenant, captured by the identity provider that issued the token. Each entry includes timestamps, user principal name, application, client IP, device details, conditional access policies applied, MFA requirements, and sign-in error codes—sufficient for correlating suspicious patterns. Investigators can access these logs in the Entra admin center, Azure portal, or via Microsoft Graph APIs, making them the primary tool for this review.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps is a CASB that provides usage analytics, anomaly detection, and app-to-app access controls across multiple cloud providers. It consumes and enriches underlying sign-in data from Microsoft Entra ID to generate risk-based alerts, but it does not produce or store the original sign-in log entries. When the requirement is to 'review all sign-in attempts' at the directory level, the source of record remains Entra ID's Sign-in logs rather than Defender's aggregated view.
Go deeper
Related to this question
Learn chapter
Azure Information Protection (AIP) Labels
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
About these practice questions
This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.