Which TWO scenarios are addressed by Microsoft Entra ID Protection? (Choose two.)
ID Protection monitors for credential leaks.
Why this answer
Microsoft Entra ID Protection uses machine learning and heuristic algorithms to detect leaked credentials by monitoring known credential dumps on the dark web. When a user's credentials appear in a breach, ID Protection can automatically force a password reset or block sign-ins. Additionally, ID Protection can block sign-ins from anonymous IP addresses (e.g., Tor or anonymous VPNs) as part of its risk-based conditional access policies.
These two capabilities—detecting leaked credentials and blocking sign-ins from anonymous IP addresses—are core risk detection and remediation features of Identity Protection.
Exam trap
The trap here is confusing Identity Protection's risk detection and remediation capabilities with other Microsoft Entra features like SSPR, access reviews, or device compliance, leading candidates to select options that are not part of the Identity Protection service.