Drag steps to the numbered slots on the right, or tap a step then tap a slot.
SC-900 Describe the capabilities of Microsoft Entra Practice Question
Arrange the steps to investigate a user compromise using Azure AD Identity Protection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Access the Azure AD Identity Protection portal, then review the risky users report, then select a specific user, then analyze the risk events for that user, then take remediation action.
Identity Protection investigation involves accessing the portal, reviewing risks, selecting a user, analyzing events, and taking action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Access the Azure AD Identity Protection portal, then review the risky users report, then select a specific user, then analyze the risk events for that user, then take remediation action.
Why this is correct
This is the correct order because you must first access the portal to see the reports, then review risky users to identify a compromised account, select the user to drill down, analyze the specific risk events to understand the compromise, and finally take action to remediate.
- ✗
Access the Azure AD Identity Protection portal, then select a specific user, then analyze the risk events for that user, then review the risky users report, then take remediation action.
Why it's wrong here
This sequence is incorrect because the logical flow for investigating a user compromise requires identifying risky users before attempting to select one for detailed analysis. After accessing the Azure AD Identity Protection portal, the 'risky users report' serves as the primary dashboard to identify and prioritize accounts exhibiting suspicious activity. Attempting to select a specific user and analyze their risk events without first reviewing this aggregated report would be inefficient and lack a clear investigative target, as you wouldn't know which user warrants immediate attention.
- ✗
Access the Azure AD Identity Protection portal, then review the risky users report, then take remediation action, then select a specific user, then analyze the risk events.
Why it's wrong here
This order is incorrect because taking remediation action prematurely, immediately after reviewing the risky users report but before selecting a specific user and analyzing their individual risk events, is not a best practice. While the report identifies potential compromises, effective remediation requires understanding the specific nature and severity of the risk events associated with a particular user. Without this detailed analysis, any action taken might be inappropriate, insufficient, or overly disruptive, as the specific context of the compromise would be unknown.
- ✗
Access the Azure AD Identity Protection portal, then analyze the risk events, then review the risky users report, then select a specific user, then take remediation action.
Why it's wrong here
This is incorrect because analyzing risk events without first selecting a user is not possible; you must select a user to view their specific risk events. The logical order is to review the list, then select a user, then analyze.
Go deeper
Related to this question
Learn chapter
Identity Concepts
Key term
Identity protection
Identity protection is the set of policies, technologies, and practices used to secure digital identities and prevent unauthorized access to systems and data.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.