SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your organization is implementing Microsoft Entra ID governance. Which THREE capabilities should you include to manage the identity lifecycle and access reviews?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra Access Reviews.
Microsoft Entra Access Reviews (B) is correct because it lets reviewers periodically attest to users' group memberships, application assignments, and role assignments, which is the core mechanism for recertifying access in an identity governance program. Microsoft Entra Entitlement Management (C) is correct because access packages, catalogs, and connected organizations automate the request, approval, and assignment of resource bundles, including external user lifecycle, which is central to governing access at scale. Microsoft Entra Lifecycle Workflows (D) is correct because it automates joiner, mover, and leaver tasks such as generating Temporary Access Passes, assigning licenses, and disabling accounts based on HR events, directly addressing identity lifecycle management. Microsoft Entra Identity Protection (A) is not included because it detects and remediates identity-based risks like risky sign-ins and compromised credentials rather than managing lifecycle or access reviews. Privileged Identity Management (E) is not included because it focuses on just-in-time privileged role activation and approval, which is privileged access management rather than the lifecycle and review capabilities the scenario asks for.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra Identity Protection.
Why it's wrong here
Identity Protection uses machine learning and heuristics to detect risky sign-ins and user behaviors, such as anonymous IP addresses, leaked credentials, or impossible travel, and it can enforce conditional access policies to challenge or block those sessions. It is focused on security risk remediation, not on reviewing the ongoing necessity of user access assignments or group memberships for governance. Consequently, it does not address a requirement to periodically recertify access entitlements.
- ✓
Microsoft Entra Access Reviews.
Why this is correct
Access Reviews allow an administrator to create recurring review scopes covering group memberships, application assignments, and role assignments, where designated reviewers attest whether each user's access remains necessary. Once a cycle completes, the reviewer's decisions can be applied automatically to remove access that was denied, and the entire history is stored to demonstrate compliance with internal and regulatory standards. This is the purpose-built mechanism for periodic access certification.
- ✓
Microsoft Entra Entitlement Management.
Why this is correct
Entitlement management enables building access packages that bundle resources like groups, apps, and SharePoint sites, and it automates the request-approval-issuance process, including assigning expiration dates for time-limited access. However, its core function is to grant and revoke access based on user requests and business approval workflows, not to systematically re-attest existing entitlements that were already granted. A recurring attestation of current access is performed by Access Reviews, which can be linked to access packages but is a separate feature.
- ✓
Microsoft Entra Lifecycle Workflows.
Why this is correct
Lifecycle Workflows automate joiner, mover, and leaver scenarios by automatically creating, updating, and disabling user accounts and assigning employee attributes based on triggers from HR sources such as Microsoft Entra Connect Sync or Viva HR. These workflows govern the user's identity and account status across their employment lifecycle, but they do not inspect or certify the individual application permissions and group memberships that remain valid for an existing employee. Therefore, they are not the correct service for periodic access recertification.
- ✗
Privileged Identity Management (PIM).
Why it's wrong here
PIM delivers just-in-time privileged access to Microsoft Entra ID roles, Azure resources, and Microsoft 365 roles, allowing activation for a limited time, optionally with approval and multi-factor authentication, and maintains logs for privileged assignments. Its scope is deliberately limited to high-privilege roles that represent security risk, rather than the broad range of ordinary user access that must be reviewed as part of identity governance. General access certifications are therefore outside PIM's purpose.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.