SC-900 Practice Question: Describe the concepts of security, compliance, and identity
Fabrikam Inc. is a global manufacturing company that uses Microsoft Entra ID for identity management. They have recently experienced a security incident where an attacker compromised a user account and accessed sensitive intellectual property. The security team wants to implement identity protection measures to detect and respond to such attacks in the future. They need a solution that can automatically detect suspicious sign-in behavior, such as impossible travel and anomalous token issuance, and then take action to block the sign-in or require additional verification. Additionally, they want to integrate threat intelligence feeds to improve detection. Which Microsoft security solution should they use to meet these requirements?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID Protection
Microsoft Entra ID Protection uses machine learning to detect risks like impossible travel and anomalous token issuance, and can automatically enforce policies such as requiring MFA or blocking sign-ins. It also integrates with threat intelligence feeds. Option A is wrong because Microsoft Defender for Identity focuses on on-premises Active Directory, not cloud sign-ins. Option C is wrong because Microsoft Sentinel is a SIEM, not an automated response tool for sign-in risks. Option D is wrong because Microsoft Defender for Cloud Apps is for cloud app discovery and control, not primarily for sign-in risk detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Identity
Why it's wrong here
Microsoft Defender for Identity monitors on-premises Active Directory domain controller traffic for lateral movement and reconnaissance, so it cannot evaluate Entra ID sign-in risk or block cloud authentication. It is tempting because it detects identity-based attacks, which suits hybrid environments with on-premises AD rather than cloud-only Entra sign-in protection.
- ✓
Microsoft Entra ID Protection
Why this is correct
Microsoft Entra ID Protection uses machine learning to detect risks like impossible travel and anomalous token issuance, and can automatically enforce policies such as requiring MFA or blocking sign-ins. It also integrates with threat intelligence feeds.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a SIEM/SOAR platform that ingests logs and automates responses, but it does not natively evaluate Entra sign-in risk or enforce conditional access blocks. It is tempting because Sentinel correlates threat intelligence feeds and can trigger playbooks, which suits centralised detection and investigation rather than inline identity risk enforcement.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps provides CASB visibility and session controls over SaaS apps, but it does not compute Entra sign-in risk or enforce conditional access on authentication. It is tempting because it detects anomalous cloud activity, which suits governing sanctioned app usage rather than blocking risky sign-ins at the identity layer.
Go deeper
Related to this question
Learn chapter
Microsoft Defender for Cloud
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.