SC-900 Practice Question: Describe the concepts of security, compliance, and identity
Which of the following is a primary purpose of Microsoft Entra ID Identity Protection?
⚠ Common exam trap
SC-900 often tests the distinction between Identity Protection (risk detection and remediation) and PIM (privileged role management), tricking candidates who confuse identity risk with privileged access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Detect and remediate identity risks
Microsoft Entra ID Identity Protection is designed to detect, investigate, and remediate identity-based risks. It uses signals like leaked credentials, atypical sign-in behavior, and risky users to generate risk detections and risk levels, which can be used in Conditional Access policies to block or require remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Detect and remediate identity risks
Why this is correct
Microsoft Entra ID Identity Protection evaluates sign-in and user risk signals, then triggers automated remediation such as requiring password reset or blocking access. Its core function is detecting and remediating identity risks, covering compromised credentials and risky sign-in behaviour.
- ✗
Manage privileged roles
Why it's wrong here
Privileged role management is handled by Microsoft Entra Privileged Identity Management, which provides just-in-time activation and approval workflows. Identity Protection instead focuses on detecting and remediating risky users and sign-ins using signals such as leaked credentials and anomalous behaviour.
- ✗
Classify and protect sensitive data
Why it's wrong here
Identity Protection detects and remediates risky sign-ins and compromised identities; classifying and protecting sensitive data is Microsoft Purview's role, so it cannot satisfy this scenario. It tempts because both are security services, but data classification would be the correct choice when the requirement is labelling and protecting information rather than identity risk.
- ✗
Manage device compliance policies
Why it's wrong here
Device compliance policies belong to Intune and Conditional Access enforcement, not Identity Protection. Identity Protection detects and remediates identity-based risks such as leaked credentials, risky sign-ins and compromised accounts, which is the capability the question targets.
Go deeper
Related to this question
Learn chapter
Privileged Identity Management (PIM)
Key term
Identity
Identity is the unique set of attributes that defines a user, device, or service in a computer system, determining what they can access and do.
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.