Courseiva
Describe the capabilities of Microsoft EntrahardMultiple SelectObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

Which THREE of the following are capabilities provided by Microsoft Entra ID Protection? (Select three.)

⚠ Common exam trap

Many exam-takers confuse the broader set of Microsoft Entra ID features (like passwordless authentication or device compliance) with the specific risk detection and response capabilities of Entra ID Protection, which is narrowly focused on identity risk management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Automated investigation and remediation of identity risks

Microsoft Entra ID Protection includes automated investigation and remediation capabilities that respond to detected identity risks. When a risk is identified, such as a compromised user account, the service can automatically trigger actions like requiring a password reset or blocking sign-in attempts, reducing the need for manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Automated investigation and remediation of identity risks

    Why this is correct

    Microsoft Entra ID Protection provides automated responses to detected identity risks, such as suspicious sign-ins or compromised credentials. It can automatically block access, require multi-factor authentication, or prompt for a password change based on predefined policies and the assessed risk level. This capability significantly reduces the manual effort required to mitigate identity-related threats and enhances overall security posture by enforcing real-time remediation.

  • Passwordless authentication options

    Why it's wrong here

    Passwordless authentication options, such as FIDO2 security keys, Windows Hello for Business, or the Microsoft Authenticator app, are core authentication methods provided by the broader Microsoft Entra ID platform. While Microsoft Entra ID Protection consumes authentication data to assess risk, it does not directly provide or manage these authentication methods. Its role is to detect and respond to risks associated with how users authenticate, regardless of the specific method used.

  • Device compliance assessment

    Why it's wrong here

    Device compliance assessment is a primary capability of Microsoft Intune, which evaluates whether devices meet organizational security standards and configurations. Intune determines if a device is compliant based on policies regarding OS versions, encryption, antivirus status, and other settings. While Microsoft Entra Conditional Access can leverage Intune's compliance status, Microsoft Entra ID Protection focuses exclusively on user and sign-in risk, not the health or compliance of the devices themselves.

  • Detection of compromised credentials and risky sign-ins

    Why this is correct

    Microsoft Entra ID Protection excels at identifying various identity-based threats, including the detection of compromised credentials found on the dark web and anomalous sign-in patterns. It uses machine learning to identify risky behaviors such as impossible travel, sign-ins from unfamiliar locations, or attempts from infected devices. This proactive detection is crucial for identifying and alerting administrators to potential breaches before they escalate.

  • Risk-based conditional access policies

    Why this is correct

    Microsoft Entra ID Protection calculates user and sign-in risk levels, which can be directly integrated into Microsoft Entra Conditional Access policies. This allows organizations to create dynamic access rules that enforce specific controls, such as requiring multi-factor authentication or blocking access entirely, only when a user's sign-in or overall user risk reaches a defined threshold. This enables adaptive security that balances user experience with necessary protection based on real-time risk assessments.

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.