SC-900 Describe the capabilities of Microsoft Entra Practice Question
A company uses Microsoft Entra ID. The security team wants to automatically block sign-ins from IP addresses that are known to be associated with malicious activity. They also want to receive alerts when users with leaked credentials attempt to sign in. Which Microsoft Entra feature should they use?
⚠ Common exam trap
Candidates often confuse ID Protection, which detects and responds to identity risks, with Conditional Access, which enforces policy based on signals but does not generate them.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID Protection
Microsoft Entra ID Protection detects risk events, including sign-ins from malicious IP addresses and users with leaked credentials. It can be configured with risk policies to automatically block sign-ins or require password changes, and it provides alerts and reports. This makes it the correct feature to both block malicious IP sign-ins and alert on leaked credentials.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra Conditional Access
Why it's wrong here
Conditional Access enforces access controls based on conditions like user, device, location, and risk. While it can use sign-in risk as a condition, it does not itself detect malicious IPs or leaked credentials; it relies on signals from ID Protection. Without ID Protection, Conditional Access lacks the risk detection to block based on malicious IPs or leaked credentials.
- ✗
Microsoft Entra Privileged Identity Management (PIM)
Why it's wrong here
PIM manages just-in-time privileged role assignments and provides approval and MFA for role activation. It does not detect malicious IP addresses or leaked credentials, nor does it block sign-ins based on such risks. Its focus is on governing privileged access, not on identity risk detection and remediation.
- ✗
Microsoft Entra Password Protection
Why it's wrong here
Password Protection prevents users from setting weak or banned passwords. It does not detect malicious IP addresses or leaked credentials, and it does not block sign-ins. While it improves password strength, it does not provide the risk detection and automated response required in this scenario.
- ✓
Microsoft Entra ID Protection
Why this is correct
ID Protection detects risk events such as sign-ins from malicious IP addresses and leaked credentials. It can be configured with risk policies to automatically block sign-ins or require password changes. It also generates alerts and reports. This directly matches the requirement to block malicious IP sign-ins and alert on leaked credentials.
Go deeper
Related to this question
Learn chapter
Self-Service Password Reset (SSPR)
Key term
Alert
An alert is a notification that something unusual or potentially harmful has happened in a computer system or network.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.