Courseiva

SC-900 Describe the capabilities of Microsoft Entra Practice Question

Which THREE capabilities are provided by Microsoft Entra Identity Protection? (Choose three.)

⚠ Common exam trap

Many candidates confuse the risk-based Conditional Access integration (which is part of Identity Protection) with the password reset and JIT access features that belong to separate Microsoft Entra services like SSPR and PIM.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Detect leaked credentials

Microsoft Entra Identity Protection includes leaked credential detection (A), which scans for compromised credentials exposed in breaches or dark web dumps and surfaces them as user risk detections. It also enables risk-based Conditional Access policies (B), allowing sign-in and user risk levels to drive access decisions such as requiring MFA or password change. Its risk investigation reports (E) give administrators visibility into risky users, risky sign-ins, and detections for triage and remediation. Self-service password reset (C) is a separate Microsoft Entra ID feature, and just-in-time privileged access (D) is provided by Privileged Identity Management, not Identity Protection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Detect leaked credentials

    Why this is correct

    Microsoft Entra ID Protection actively monitors public and dark web sources for compromised user credentials associated with your tenant. When a username and password pair is found to be leaked, ID Protection flags the affected user as having a "leaked credentials" risk, enabling administrators to force password resets or block sign-ins to prevent unauthorized access. This proactive monitoring is a critical defense against credential stuffing attacks.

  • ✓

    Enable risk-based conditional access policies

    Why this is correct

    Microsoft Entra ID Protection continuously evaluates sign-in and user behavior for suspicious activities, generating real-time risk scores. These dynamic risk signals are then fed directly into Microsoft Entra Conditional Access policies, allowing organizations to automatically enforce adaptive controls such as multi-factor authentication, password changes, or blocking access entirely based on the detected risk level of a specific sign-in attempt or user.

  • ✗

    Allow users to reset their own passwords

    Why it's wrong here

    While a crucial identity management feature, allowing users to reset their own passwords is provided by Microsoft Entra Self-Service Password Reset (SSPR), not Microsoft Entra ID Protection. SSPR enables users to securely reset forgotten passwords without administrator intervention, whereas ID Protection focuses on detecting and remediating identity-based risks like compromised accounts or suspicious sign-ins.

  • ✗

    Provide just-in-time privileged access

    Why it's wrong here

    Just-in-time (JIT) privileged access, which grants temporary, time-bound permissions for specific administrative tasks, is a core capability of Microsoft Entra Privileged Identity Management (PIM). Microsoft Entra ID Protection, conversely, is focused on identifying and mitigating identity-based risks associated with user accounts and sign-ins, rather than managing the lifecycle of privileged roles.

  • ✓

    Provide a risk investigation report

    Why this is correct

    Microsoft Entra ID Protection offers comprehensive reports that detail detected risks, including risky users, risky sign-ins, and detected vulnerabilities. These reports provide administrators with actionable insights into potential threats, allowing them to investigate specific risk events, understand attack patterns, and prioritize remediation efforts to enhance the overall security posture of their organization.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.