Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

Which of the following is a primary purpose of Microsoft Entra ID Identity Protection?

⚠ Common exam trap

SC-900 often tests the distinction between Identity Protection (risk detection and remediation) and PIM (privileged role management), tricking candidates who confuse identity risk with privileged access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Detect and remediate identity risks

Microsoft Entra ID Identity Protection is designed to detect, investigate, and remediate identity-based risks. It uses signals like leaked credentials, atypical sign-in behavior, and risky users to generate risk detections and risk levels, which can be used in Conditional Access policies to block or require remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Detect and remediate identity risks

    Why this is correct

    Microsoft Entra ID Identity Protection evaluates sign-in and user risk signals, then triggers automated remediation such as requiring password reset or blocking access. Its core function is detecting and remediating identity risks, covering compromised credentials and risky sign-in behaviour.

  • ✗

    Manage privileged roles

    Why it's wrong here

    Privileged role management is handled by Microsoft Entra Privileged Identity Management, which provides just-in-time activation and approval workflows. Identity Protection instead focuses on detecting and remediating risky users and sign-ins using signals such as leaked credentials and anomalous behaviour.

  • ✗

    Classify and protect sensitive data

    Why it's wrong here

    Identity Protection detects and remediates risky sign-ins and compromised identities; classifying and protecting sensitive data is Microsoft Purview's role, so it cannot satisfy this scenario. It tempts because both are security services, but data classification would be the correct choice when the requirement is labelling and protecting information rather than identity risk.

  • ✗

    Manage device compliance policies

    Why it's wrong here

    Device compliance policies belong to Intune and Conditional Access enforcement, not Identity Protection. Identity Protection detects and remediates identity-based risks such as leaked credentials, risky sign-ins and compromised accounts, which is the capability the question targets.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.