SC-900 Describe the capabilities of Microsoft Entra Practice Question
Which THREE of the following are capabilities provided by Microsoft Entra ID Protection? (Select three.)
⚠ Common exam trap
Many exam-takers confuse the broader set of Microsoft Entra ID features (like passwordless authentication or device compliance) with the specific risk detection and response capabilities of Entra ID Protection, which is narrowly focused on identity risk management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automated investigation and remediation of identity risks
Microsoft Entra ID Protection includes automated investigation and remediation capabilities that respond to detected identity risks. When a risk is identified, such as a compromised user account, the service can automatically trigger actions like requiring a password reset or blocking sign-in attempts, reducing the need for manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Automated investigation and remediation of identity risks
Why this is correct
Microsoft Entra ID Protection provides automated responses to detected identity risks, such as suspicious sign-ins or compromised credentials. It can automatically block access, require multi-factor authentication, or prompt for a password change based on predefined policies and the assessed risk level. This capability significantly reduces the manual effort required to mitigate identity-related threats and enhances overall security posture by enforcing real-time remediation.
- ✗
Passwordless authentication options
Why it's wrong here
Passwordless authentication options, such as FIDO2 security keys, Windows Hello for Business, or the Microsoft Authenticator app, are core authentication methods provided by the broader Microsoft Entra ID platform. While Microsoft Entra ID Protection consumes authentication data to assess risk, it does not directly provide or manage these authentication methods. Its role is to detect and respond to risks associated with how users authenticate, regardless of the specific method used.
- ✗
Device compliance assessment
Why it's wrong here
Device compliance assessment is a primary capability of Microsoft Intune, which evaluates whether devices meet organizational security standards and configurations. Intune determines if a device is compliant based on policies regarding OS versions, encryption, antivirus status, and other settings. While Microsoft Entra Conditional Access can leverage Intune's compliance status, Microsoft Entra ID Protection focuses exclusively on user and sign-in risk, not the health or compliance of the devices themselves.
- ✓
Detection of compromised credentials and risky sign-ins
Why this is correct
Microsoft Entra ID Protection excels at identifying various identity-based threats, including the detection of compromised credentials found on the dark web and anomalous sign-in patterns. It uses machine learning to identify risky behaviors such as impossible travel, sign-ins from unfamiliar locations, or attempts from infected devices. This proactive detection is crucial for identifying and alerting administrators to potential breaches before they escalate.
- ✓
Risk-based conditional access policies
Why this is correct
Microsoft Entra ID Protection calculates user and sign-in risk levels, which can be directly integrated into Microsoft Entra Conditional Access policies. This allows organizations to create dynamic access rules that enforce specific controls, such as requiring multi-factor authentication or blocking access entirely, only when a user's sign-in or overall user risk reaches a defined threshold. This enables adaptive security that balances user experience with necessary protection based on real-time risk assessments.
Go deeper
Related to this question
Learn chapter
Identity Concepts
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
User account
A user account is a digital identity that allows a person to access a computer system, network, or application with specific permissions and settings.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.