Courseiva

SC-100 Design security solutions for infrastructure Practice Question

Your company uses Microsoft Entra ID for identity management. You need to implement a solution to automatically detect and remediate risky sign-ins using machine learning. What should you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure Microsoft Entra ID Protection and enable risk-based policies.

Microsoft Entra ID Protection is the correct choice (Option C) because it uses machine learning to detect risky sign-ins and user risk events, and it lets you enable risk-based Conditional Access policies that automatically remediate those risks (for example, requiring MFA or blocking access). It is purpose-built for identity risk detection and automated remediation, matching the scenario's requirement exactly. Option A, Entra Connect, only synchronizes on-premises identities to Entra ID and does not perform risk detection. Option B, Conditional Access with session controls, enforces access and session restrictions but does not itself provide the machine-learning risk detection engine. Option D, PIM, manages just-in-time privileged role activation and approvals, not risky sign-in detection or remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure Microsoft Entra Connect to sync on-premises identities.

    Why it's wrong here

    Microsoft Entra Connect performs directory synchronization, replicating on-premises Active Directory objects (users, groups, and hashed credentials) to Entra ID. It does not analyze sign-in patterns, user behavior, or risk signals; its role is identity provisioning, not security monitoring. Enabling this alone will not flag a compromised account or a suspicious sign-in, so it cannot satisfy a requirement for automated risk detection and remediation.

  • ✗

    Configure Conditional Access policies with session controls.

    Why it's wrong here

    Conditional Access policies with session controls (e.g., sign-in frequency, app restrictions, or Conditional Access app control) enforce access decisions based on conditions like location, device, or application. However, these controls are reactive and depend on a risk signal being supplied externally; Conditional Access itself does not compute or detect risk. Without Microsoft Entra ID Protection to generate and assign risk levels, session controls have no risk-related condition to act upon, so they cannot autonomously detect or remediate compromised identities.

  • ✓

    Configure Microsoft Entra ID Protection and enable risk-based policies.

    Why this is correct

    Microsoft Entra ID Protection actively monitors user and sign-in risk using machine learning, heuristic analysis, and Microsoft's threat intelligence feeds. Enabling risk-based policies (which are a type of Conditional Access policy using risk as a condition) allows automatic remediation, such as requiring MFA, blocking the sign-in, or forcing a secure password change. This directly addresses the need to detect risky identities and respond without manual intervention, making it the correct choice for identity-based threat detection and auto-remediation.

  • ✗

    Configure Privileged Identity Management (PIM) for admin roles.

    Why it's wrong here

    Privileged Identity Management (PIM) provides just-in-time and time-bound admin role activation, approval workflows, and access reviews to reduce standing privileged access. It governs role eligibility and elevation but does not evaluate user or sign-in risk; a user with no PIM role could still be compromised and pose risk. PIM complements but does not replace risk detection, so it cannot detect or automatically remediate risky sign-ins or compromised accounts in the broader user population.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.