Courseiva
Describe the capabilities of Microsoft EntrahardMultiple ChoiceObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

An organization uses Microsoft Entra ID Protection. A user's sign-in is flagged with a risk level of 'High' because of an anonymous IP address. The administrator wants to automatically block the sign-in while allowing the user to self-remediate. Which should be configured?

⚠ Common exam trap

Many exam-takers confuse sign-in risk policies (which block or challenge at the sign-in event) with user risk policies (which require password changes after a compromise), leading candidates to choose a user risk policy when the scenario explicitly describes a sign-in-level risk from an anonymous IP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A sign-in risk policy configured to block access

A sign-in risk policy in Microsoft Entra ID Protection can be configured to automatically block access when a sign-in is detected as high risk (e.g., from an anonymous IP address). This policy operates at the sign-in level, allowing the administrator to block the sign-in while still enabling the user to self-remediate (e.g., by signing in again after the risk is mitigated). Option C directly matches this requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A Conditional Access policy requiring MFA for high-risk sign-ins

    Why it's wrong here

    A Conditional Access policy configured to require MFA for high-risk sign-ins would indeed trigger an MFA challenge if a sign-in is deemed risky by Microsoft Entra ID Protection. However, this action does not *block* the sign-in outright; it merely adds an additional verification step. If the attacker possesses the MFA token or can bypass it, the sign-in could still proceed, failing to meet the requirement of automatically blocking the access attempt.

    When this WOULD be correct

    This would be correct if the question asked for a policy that requires additional verification (MFA) for high-risk sign-ins, without blocking access, and the user can self-remediate by completing MFA.

  • A user risk policy configured to require a password change

    Why it's wrong here

    A user risk policy in Microsoft Entra ID Protection focuses on the overall risk state of a user account, indicating potential compromise over time, rather than the risk of a single sign-in attempt. While requiring a password change is a valid remediation for a compromised user account, this policy typically triggers *after* a sign-in has occurred or as a subsequent remediation step, not as an immediate block to the *current* sign-in attempt itself.

    When this WOULD be correct

    A user risk policy requiring a password change would be correct if the question described a user risk (e.g., leaked credentials) and the goal was to force the user to self-remediate by changing their password after the risk is detected.

  • A sign-in risk policy configured to block access

    Why this is correct

    Microsoft Entra ID Protection's sign-in risk policy directly evaluates the risk associated with a specific sign-in attempt in real-time. When configured to block access for a detected risk level, such as 'High,' it prevents the user from completing the sign-in immediately. This directly addresses the requirement to automatically block a high-risk sign-in, ensuring immediate protection against potentially compromised credentials and unauthorized access.

  • An MFA registration policy for all users

    Why it's wrong here

    An MFA registration policy's primary function is to compel users to register for multi-factor authentication, typically during their next interactive sign-in. While crucial for overall security posture, this policy does not inherently evaluate or block sign-ins based on real-time risk detection. It merely ensures the prerequisite for MFA challenges is met, rather than actively preventing a suspicious sign-in attempt from proceeding.

    When this WOULD be correct

    This option would be correct if the question asked: 'An organization wants to ensure all users are registered for MFA before accessing cloud apps. Which policy should be configured?' In that case, an MFA registration policy would enforce registration.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

A sign-in risk policy configured to block accessCorrect answer

Why this is correct

Microsoft Entra ID Protection's sign-in risk policy directly evaluates the risk associated with a specific sign-in attempt in real-time. When configured to block access for a detected risk level, such as 'High,' it prevents the user from completing the sign-in immediately. This directly addresses the requirement to automatically block a high-risk sign-in, ensuring immediate protection against potentially compromised credentials and unauthorized access.

A Conditional Access policy requiring MFA for high-risk sign-insWrong answer — click to see why

Why this is wrong here

This option requires MFA for high-risk sign-ins but does not block access, which contradicts the administrator's goal to automatically block the sign-in while allowing self-remediation.

★ When this WOULD be the correct answer

This would be correct if the question asked for a policy that requires additional verification (MFA) for high-risk sign-ins, without blocking access, and the user can self-remediate by completing MFA.

Why candidates choose this

Candidates may think requiring MFA is sufficient to mitigate risk, but they overlook the explicit requirement to block the sign-in, not just challenge it.

A user risk policy configured to require a password changeWrong answer — click to see why

Why this is wrong here

The question specifies a sign-in risk (anonymous IP address), not user risk. A user risk policy targets user account compromise, not sign-in events, and would not block the sign-in based on sign-in risk.

★ When this WOULD be the correct answer

A user risk policy requiring a password change would be correct if the question described a user risk (e.g., leaked credentials) and the goal was to force the user to self-remediate by changing their password after the risk is detected.

Why candidates choose this

Candidates may confuse user risk with sign-in risk, or think that requiring a password change is a common remediation for high-risk events, not realizing that sign-in risk policies handle sign-in blocking directly.

An MFA registration policy for all usersWrong answer — click to see why

Why this is wrong here

An MFA registration policy requires users to register for MFA but does not block sign-ins or allow self-remediation for high-risk sign-ins. The question specifically asks to block access and allow self-remediation, which is achieved by a sign-in risk policy configured to block access.

★ When this WOULD be the correct answer

This option would be correct if the question asked: 'An organization wants to ensure all users are registered for MFA before accessing cloud apps. Which policy should be configured?' In that case, an MFA registration policy would enforce registration.

Why candidates choose this

Candidates may confuse MFA registration with risk-based policies, thinking that requiring MFA for all users addresses high-risk sign-ins, but it does not block access or provide self-remediation for specific risk events.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.