Courseiva

SC-100 Practice Question: Design security solutions for applications and data

Exhibit

{
  "alert": {
    "id": "8564c5c0-7c8a-4c3a-8f0c-5a9b6e7f8a0b",
    "provider": "Microsoft Entra ID Identity Protection",
    "riskEventTypes": ["unfamiliarFeatures", "atypicalTravel"],
    "riskLevel": "medium",
    "userPrincipalName": "jdoe@contoso.com",
    "additionalData": {
      "userRiskLevel": "high",
      "signInRiskLevel": "medium"
    }
  }
}

Refer to the exhibit. This is a risk alert from Microsoft Entra ID Identity Protection for user jdoe@contoso.com. You are designing an automated response using Microsoft Sentinel. Which condition should you use to trigger a high-severity incident?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

If the user risk level is 'high'

The correct condition is A: trigger the high-severity incident when the user risk level is 'high'. In Microsoft Entra ID Identity Protection, user risk represents the probability that a given identity has been compromised, and a 'high' user risk is the strongest aggregate signal for an account-level compromise, making it the appropriate trigger for a high-severity Microsoft Sentinel incident. Option B is not the best fit because sign-in risk is scoped to a single authentication attempt rather than the overall user account. Option C is too narrow, since 'leakedCredentials' is only one risk detection type and does not by itself indicate the highest severity. Option D is incorrect because 'medium' user risk is a lower severity than 'high' and would not justify a high-severity incident.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    If the user risk level is 'high'

    Why this is correct

    In Microsoft Entra ID Protection, the user risk level is an aggregated probability that an account has been compromised, calculated from multiple risk detections over time. When the user risk level is rated 'high', the service raises a user risk alert, which is exactly what this exhibit displays. The alert metadata shows the user risk as 'high', so the condition that triggered this alert is the high user risk classification, not any other factor like sign-in risk or a specific leaked credential event.

  • ✗

    If the sign-in risk level is 'high'

    Why it's wrong here

    This alert is a user risk safety alert, not a sign-in risk alert, and the two are independent. A 'high' sign-in risk level would produce a separate sign-in risk detection for that specific sign-in attempt, such as impossible travel or anonymous IP. The exhibit explicitly shows the sign-in risk as 'medium', so a high sign-in risk cannot be the trigger because that value is not present. Even if it were high, it would not change the user risk alert's condition since the alert is based on user risk.

  • ✗

    If the risk event types include 'leakedCredentials'

    Why it's wrong here

    The 'leakedCredentials' risk event type is a single detection indicating that the account's credentials were found exposed on the internet, and it can contribute to user risk. However, the exhibit's alert does not include 'leakedCredentials' among its risk event types, so it cannot be the condition that raised this alert. This alert is the result of an aggregated user risk calculation that may incorporate various detections, but no single event type such as leaked credentials is mandatory for a high user risk verdict.

  • ✗

    If the user risk level is 'medium'

    Why it's wrong here

    If the user risk level were 'medium', the alert would not show a 'high' user risk in its details, and the system would classify the account as at moderate risk, not critically compromised. The exhibit clearly labels the user risk level as 'high', so proposing a threshold of 'medium' contradicts the evidence. A medium user risk might generate a 'Medium' risk alert or no alert, depending on the configured conditional access policy, but it cannot be the trigger for this specific high-risk alert.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.