SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A security administrator receives an alert about a suspicious sign-in from an unfamiliar location. The user verified the sign-in as legitimate. Which Microsoft Entra ID feature should be used to reduce false positives for this user?
⚠ Common exam trap
It's easy for candidates to confuse Conditional Access policies (which can block or challenge sign-ins based on risk) with Identity Protection's manual risk remediation actions like 'Confirm user safe', but Conditional Access does not provide a way to retroactively dismiss a false positive alert.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identity Protection confirm user safe
Microsoft Entra ID Identity Protection's 'Confirm user safe' feature allows administrators to manually override a risk detection when a user confirms a suspicious sign-in was legitimate. This reduces false positives by telling Identity Protection to ignore that specific risk event for that user, preventing future alerts based on the same detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Passwordless authentication
Why it's wrong here
Passwordless authentication methods, such as Windows Hello for Business or FIDO2 security keys, improve user sign-in security by eliminating passwords, thereby reducing the attack surface for credential theft. However, implementing passwordless authentication does not directly interact with or suppress existing risk detections or alerts generated by Microsoft Entra Identity Protection. Its primary function is to provide a more secure sign-in experience, not to manage the lifecycle of detected identity risks.
- ✗
Privileged Identity Management
Why it's wrong here
Microsoft Entra Privileged Identity Management (PIM) is designed to manage, control, and monitor access to important resources within an organization by providing just-in-time access to privileged roles. While PIM is crucial for securing administrative accounts, it does not directly detect or remediate suspicious sign-in activities or user behaviors that trigger risk alerts. Its function is focused on role lifecycle and access governance, not real-time identity threat detection and response.
- ✓
Identity Protection confirm user safe
Why this is correct
The "Confirm user safe" action within Microsoft Entra Identity Protection is specifically designed to address false-positive risk detections. When a security administrator confirms a user is safe, it signals to the Identity Protection risk engine that the detected activity was legitimate and not a compromise. This action effectively dismisses the current risk event and helps refine the machine learning model, preventing similar future legitimate activities from generating new alerts for that specific user.
- ✗
Conditional Access policies
Why it's wrong here
Conditional Access policies in Microsoft Entra ID are powerful tools used to enforce specific access controls based on various conditions, including user risk levels detected by Identity Protection. While these policies can block access, require multi-factor authentication, or force a password change in response to a risk, they do not inherently dismiss or resolve the underlying risk detection itself. Conditional Access acts as an enforcement mechanism, not a risk management or suppression tool.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Identity
Identity is the unique set of attributes that defines a user, device, or service in a computer system, determining what they can access and do.
Key term
Identity protection
Identity protection is the set of policies, technologies, and practices used to secure digital identities and prevent unauthorized access to systems and data.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.