SC-900 Describe the capabilities of Microsoft Entra Practice Question
A company uses Microsoft Entra ID and wants to automatically detect potential security risks such as leaked credentials and suspicious sign-in patterns. They also need the ability to investigate these risks and configure automated responses based on risk levels. Which Microsoft Entra capability should they use?
⚠ Common exam trap
Many exam-takers confuse Identity Protection (which handles user and sign-in risk detection and automated response) with Privileged Identity Management (PIM), which only manages privileged role activation and does not detect leaked credentials or suspicious sign-in patterns.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra Identity Protection
Microsoft Entra Identity Protection is the correct service because it automatically detects potential security risks such as leaked credentials and suspicious sign-in patterns, provides investigation tools (e.g., risk reports and detailed risk event logs), and enables automated responses like conditional access policies that block or require MFA based on risk levels. This directly matches the scenario's requirements for detection, investigation, and automated remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra ID Governance
Why it's wrong here
Microsoft Entra ID Governance is designed for managing and auditing identity lifecycles, access entitlements, and access reviews across an organization. It ensures that the right people have the right access to the right resources at the right time, and that access is regularly certified. However, its primary function is not real-time detection of identity-based risks like suspicious sign-ins or leaked credentials, nor does it automate responses to such threats.
- ✓
Microsoft Entra Identity Protection
Why this is correct
Microsoft Entra Identity Protection is specifically engineered to detect identity-based risks in real-time, such as impossible travel, sign-ins from infected devices, or leaked credentials. It leverages machine learning and heuristics to identify suspicious activities and calculate a risk level for each sign-in and user. Based on these risk levels, administrators can configure automated policies to enforce actions like requiring multi-factor authentication, forcing a password change, or blocking access entirely, thereby providing automated responses to mitigate threats.
- ✗
Microsoft Entra Privileged Identity Management (PIM)
Why it's wrong here
Microsoft Entra Privileged Identity Management (PIM) focuses on securing and managing access to privileged roles within Microsoft Entra ID and Azure resources. It enables just-in-time (JIT) access, requiring users to activate roles for a limited time, and provides approval workflows and auditing for these activations. While PIM enhances security for high-privilege accounts, it does not detect general identity risks like unusual sign-in patterns or compromised user credentials for non-privileged accounts across the entire tenant.
- ✗
Microsoft Entra Domain Services
Why it's wrong here
Microsoft Entra Domain Services provides managed domain services, such as domain join, group policy, LDAP, and Kerberos/NTLM authentication, for Azure virtual machines and applications. It allows organizations to lift-and-shift traditional on-premises applications to Azure without deploying and managing their own domain controllers. This service is an infrastructure component for legacy application compatibility and does not offer capabilities for detecting identity risks or automating security responses based on user behavior or sign-in anomalies.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Event
An event is any identifiable occurrence or action in a computer system, network, or application that can be logged, monitored, or analyzed for security or operational purposes.
Key term
Identity
Identity is the unique set of attributes that defines a user, device, or service in a computer system, determining what they can access and do.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.