Courseiva

SC-900 Describe the capabilities of Microsoft Entra Practice Question

Match each identity term to its correct meaning.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

An entity that can be authenticated

Proving you are who you claim to be

Determining what an authenticated user can do

Trust relationship between identity providers

Creating and managing user accounts and access

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Identity: An entity that can be authenticated (e.g., user, device, service).

Identity is the entity (user, device, service) being authenticated. Authentication verifies who you are (e.g., passwords, MFA). Authorization determines what you can access (e.g., permissions). Directory stores identity information (e.g., Azure AD). Common confusion: mixing authentication and authorization definitions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Identity: An entity that can be authenticated (e.g., user, device, service).

    Why this is correct

    Identity, in the context of security, refers to any entity that can be uniquely identified and authenticated within a system. This encompasses a broad range of digital personas or objects, including human users, automated service accounts, applications, and even physical devices like laptops or IoT sensors. It represents the 'who' or 'what' that needs to be recognized and verified before any access decisions can be made.

  • Authentication: The process of verifying the identity of a user or service.

    Why this is correct

    Authentication is the foundational security process of verifying the claimed identity of a user, device, or service. This critical step involves validating credentials provided by the entity, such as passwords, multi-factor authentication codes, or digital certificates, against a trusted source. Successful authentication confirms that the entity is indeed who or what it purports to be, establishing a level of trust within the system.

  • Authorization: The process of granting or denying access to resources based on identity and permissions.

    Why this is correct

    Authorization is the subsequent security process that determines what an authenticated identity is permitted to do within a system. Occurring after successful authentication, it involves evaluating the identity's assigned roles, group memberships, or explicit permissions against the requested action or resource. This ensures that even a verified identity can only access specific data, applications, or functionalities for which they have been explicitly granted access rights.

  • Directory: A service that stores and manages identity information (e.g., Azure AD).

    Why this is correct

    A directory service is a specialized information system designed to store, organize, and manage digital identity information and related resources in a centralized manner. It acts as a comprehensive repository for user accounts, groups, devices, and their associated attributes, providing the underlying infrastructure for authentication and authorization. Examples like Azure Active Directory offer scalable, cloud-based solutions for managing identities across an enterprise.

  • Identity: The process of verifying credentials.

    Why it's wrong here

    This definition incorrectly describes 'Identity' as a process. Identity refers to the *entity* itself—the user, device, or service—that exists within a digital environment and possesses attributes. The *process* of verifying credentials, such as a username and password, to confirm the authenticity of that entity's claim is precisely what authentication entails, making this a misattribution of terms.

  • Authentication: The process of granting access rights.

    Why it's wrong here

    This definition mistakenly attributes the function of 'Authorization' to 'Authentication.' Authentication is solely concerned with proving *who* an entity is, verifying their claimed identity through credentials. The distinct and subsequent step of determining *what* that authenticated entity is allowed to do, by granting or denying specific access rights to resources, is the core role of authorization.

Go deeper

Related to this question

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.