Courseiva

SC-100 Design security solutions for infrastructure Practice Question

A multinational corporation uses Microsoft Entra ID with hybrid identities. They need to design a solution that automatically remediates risky sign-ins without user intervention. Which feature should you enable?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identity Protection with Conditional Access policies

The correct option is D: Identity Protection with Conditional Access policies, because Entra ID Identity Protection detects risky sign-ins and risk detections, and Conditional Access can automatically enforce remediation actions such as requiring MFA, blocking access, or forcing password reset without user intervention. This directly addresses the requirement for automatic remediation of risky sign-ins in a hybrid identity environment. Option A, Entra ID Governance Access Reviews, is for periodic attestation of access rights, not sign-in risk remediation. Option B, Privileged Identity Management, manages just-in-time privileged role activation and approvals, not risky sign-in response. Option C, Microsoft Defender for Identity, detects identity threats on-premises but does not itself automatically remediate Entra ID sign-in risk through Conditional Access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Entra ID Governance (Access Reviews)

    Why it's wrong here

    Entra ID Governance (Access Reviews) is an attestation capability that periodically asks owners to review and confirm group memberships, application assignments, and role eligibility. These reviews run on a scheduled cadence (e.g., monthly or quarterly) and are not real-time; they are designed to remove stale access over time, not to react to a suspicious sign-in event. Therefore, it cannot automatically remediate a risky sign-in as it lacks event-driven risk evaluation.

  • ✗

    Privileged Identity Management (PIM)

    Why it's wrong here

    Privileged Identity Management (PIM) provides just-in-time, time-bound, and approval-based activation of privileged roles in Microsoft Entra ID, such as Global Administrator. While it limits standing privilege and requires approval for role activation, it does not examine user sign-in risk signals or evaluate the security of a user's session. PIM governs who can become an admin and when, not whether a current sign-in is risky or should be blocked.

  • ✗

    Microsoft Defender for Identity

    Why it's wrong here

    Microsoft Defender for Identity monitors on-premises Active Directory traffic, including domain controller and authentication events, to detect advanced attacks such as lateral movement, kerberoasting, and pass-the-hash. While it can provide alerts about suspicious on-prem behavior, those alerts require manual investigation by a security analyst and do not automatically enforce Conditional Access policies or block cloud SaaS sign-ins. It also does not natively calculate Microsoft Entra ID sign-in risk from cloud-based signals like leaked credentials or unfamiliar locations.

  • ✓

    Identity Protection with Conditional Access policies

    Why this is correct

    Identity Protection continuously evaluates sign-in and user risk using signals like impossible travel, leaked credentials, and anonymous IP addresses, assigning a risk level (low, medium, high). Conditional Access policies consume that risk score and automatically enforce actions such as blocking the sign-in, requiring MFA, or forcing a password reset in real time. This is a native, automatic remediation mechanism for risky sign-ins.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.