Courseiva

SC-100 Microsoft Entra ID Protection Practice Question

You are a security architect for a global financial services company that uses Microsoft 365 E5 and Azure. The company has 50,000 users across 10 regions. The security team needs to detect and respond to identity-based threats in real-time, automate remediation for compromised accounts, and meet regulatory requirements for audit logging. The following requirements must be met: (1) Detect risky sign-ins and user anomalies, (2) Automatically block sign-ins when risk level is high, (3) Provide a centralized dashboard for security analysts to investigate incidents, (4) Retain logs for at least one year for compliance, (5) Minimize false positives by using machine learning. You have the following services available: Microsoft Entra ID P2, Microsoft Sentinel, Microsoft Defender for Identity, Microsoft Purview, and Microsoft Intune. Which combination of services should you use to meet all requirements?

⚠ Common exam trap

Candidates often confuse Microsoft Defender for Identity (on-premises AD) with Entra ID Protection (cloud identity). The question specifies a cloud-only environment with Microsoft 365 and Azure, so Defender for Identity is not suitable.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra ID Protection (P2) and Microsoft Sentinel

Microsoft Entra ID Protection (P2) provides the risk-based sign-in and user risk detections powered by machine learning, and its Conditional Access integration can automatically block sign-ins when risk is high, satisfying requirements 1, 2, and 5. Microsoft Sentinel supplies the centralized SIEM dashboard for analysts to investigate incidents and supports long-term log retention (including one-year retention via the data lake or workspace retention settings), covering requirements 3 and 4. Together, option B meets all five requirements. Option A is wrong because Intune handles device management and Defender for Cloud covers cloud workload protection, not identity risk detection or SIEM. Option C is wrong because Defender for Identity monitors on-premises Active Directory signals and Purview handles data governance/compliance, not real-time sign-in risk blocking. Option D is wrong because Purview does not perform identity risk detection or automated sign-in remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Intune and Microsoft Defender for Cloud

    Why it's wrong here

    Intune is a cloud-based endpoint management service that enforces device compliance and configuration policies, while Microsoft Defender for Cloud protects multi-cloud workloads through posture management and workload-specific security. Neither service generates or consumes identity risk signals for user sign-ins, such as impossible travel or leaked credentials. Therefore, they cannot detect identity-based attacks against Entra ID accounts, which is the core requirement of this scenario.

  • ✓

    Microsoft Entra ID Protection (P2) and Microsoft Sentinel

    Why this is correct

    Entra ID Protection (P2) uses machine learning to continuously evaluate sign-in and user risk, assigning risk levels and enabling Conditional Access to require MFA or block high-risk attempts. Sentinel then ingests these risk detections, along with other identity logs, into a central SIEM that provides long-term retention, advanced hunting through KQL, and analyst workflow for investigation. Together they deliver both the real-time detection and the centralized visibility needed by a global financial services security team.

  • ✗

    Microsoft Defender for Identity and Microsoft Purview

    Why it's wrong here

    Defender for Identity is purpose-built to detect attacks on on-premises Active Directory using domain controller traffic and Kerberos protocol analysis, not cloud-based Entra ID authentication activity. Purview is a data governance and compliance solution that classifies and tracks sensitive data, and it has no role in identity threat detection. As a result, this pairing leaves cloud identity risks undetected and fails to address the required sign-in and user risk monitoring.

  • ✗

    Microsoft Purview and Microsoft Sentinel

    Why it's wrong here

    Purview specializes in data governance, eDiscovery, and information protection, but it does not generate any identity risk detections or possess user risk analytics. Sentinel is a powerful SIEM, but it is an aggregator and correlation engine without an embedded identity risk scoring engine like Entra ID Protection; it must rely on an external detector to supply risk incidents. Therefore, this combination would have no primary identity threat detection source, leaving high-risk sign-ins and compromised accounts virtually invisible until later secondary detection.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.