SC-900 Describe the capabilities of Microsoft Entra Practice Question
Which THREE components are part of Microsoft Entra Permissions Management (CIEM)?
⚠ Common exam trap
It's easy for candidates to confuse the CIEM components (Activity trail, Audit trail, Permissions Analytics Report) with broader Microsoft Entra features like Identity Protection or Access reviews, which serve different governance and security functions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Activity trail
Activity trail (A) is correct because Microsoft Entra Permissions Management (CIEM) captures a detailed log of all user actions and resource access events across multi-cloud environments (AWS, Azure, GCP). This trail is essential for forensic analysis and identifying anomalous behavior, directly supporting the CIEM goal of providing visibility into permissions usage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Activity trail
Why this is correct
Within Microsoft Entra Permissions Management, the Activity trail component meticulously records all user and resource actions performed across connected cloud environments, including AWS, Azure, and GCP. This comprehensive log details who accessed what resource, when, and how, providing critical visibility into the actual usage of granted permissions. It is essential for detecting anomalous behavior, identifying potential misuse of entitlements, and understanding the real-world impact of permission policies.
- ✓
Audit trail
Why this is correct
The Audit trail in Microsoft Entra Permissions Management specifically logs all configuration changes made within the Permissions Management platform itself. This includes modifications to permission policies, role assignments, user onboarding, and any administrative actions that alter the system's setup or monitoring scope. It provides an immutable record of "who changed what" in the management of cloud entitlements, crucial for compliance, accountability, and tracking administrative actions within the CIEM solution.
- ✗
Identity Protection
Why it's wrong here
Identity Protection is a distinct feature of Microsoft Entra ID (formerly Azure AD) focused on detecting and remediating identity-based risks for user accounts within the Entra ID tenant. It identifies threats such as impossible travel, leaked credentials, and anomalous sign-in activities to protect user identities. While critical for overall security, it is not a direct component of Microsoft Entra Permissions Management, which is a Cloud Infrastructure Entitlement Management (CIEM) solution for managing permissions across multi-cloud infrastructure.
- ✗
Access reviews
Why it's wrong here
Access reviews are a core capability within Microsoft Entra ID Governance, designed to periodically evaluate and certify user access to groups, applications, and roles within an organization's Entra ID tenant. They ensure that users only retain access necessary for their current roles, helping to enforce the principle of least privilege over time. However, access reviews are a feature of Entra ID Governance, not an integral component of Microsoft Entra Permissions Management, which specializes in discovering, remediating, and monitoring permissions across multi-cloud infrastructure.
- ✓
Permissions Analytics Report
Why this is correct
The Permissions Analytics Report is a crucial component of Microsoft Entra Permissions Management that provides deep insights into effective permissions across multi-cloud environments. It leverages machine learning to analyze permission usage patterns, calculate a Permission Creep Index (PCI), and identify identities with excessive or unused permissions. This report is instrumental in pinpointing overprivileged identities and recommending precise least-privilege adjustments, enabling organizations to proactively right-size entitlements based on actual activity.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.