SC-900 Describe the capabilities of Microsoft Entra Practice Question
Which THREE of the following are features of Microsoft Entra ID Protection?
⚠ Common exam trap
Test-takers frequently confuse Entra ID Protection with Entra ID Governance features (Access reviews and Entitlement management), which are separate capabilities focused on lifecycle and compliance rather than risk detection and remediation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
User risk detection (e.g., leaked credentials)
Option B is correct because Microsoft Entra ID Protection detects user risk, including leaked credentials found on the dark web or by Microsoft's threat intelligence, and flags the account as at risk. Option C is correct because ID Protection also detects sign-in risk, such as sign-ins from anonymous IP addresses (Tor browser or anonymizing VPNs), atypical travel, or unfamiliar locations. Option E is correct because ID Protection feeds its user and sign-in risk detections into Conditional Access, enabling risk-based policies that can require MFA or block access when risk is elevated. Options A and D are not features of ID Protection: access reviews and entitlement management are capabilities of Microsoft Entra ID Governance (part of Entra ID P2), used for reviewing access and managing the lifecycle of access packages, not for risk detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Access reviews
Why it's wrong here
Access reviews are a key feature of Microsoft Entra ID Governance, a distinct product within the broader Microsoft Entra family, rather than a standalone feature of Microsoft Entra itself. They enable organizations to periodically evaluate and certify who has access to various resources, such as groups, applications, and roles. This process helps ensure that users maintain only the necessary permissions, aligning with the principle of least privilege and fulfilling compliance requirements by removing stale or excessive access.
- ✓
User risk detection (e.g., leaked credentials)
Why this is correct
User risk detection is a fundamental capability of Microsoft Entra ID Protection, which is an advanced security component of Microsoft Entra. This feature continuously monitors for potential compromises related to user accounts, such as identifying leaked credentials found on the dark web or detecting suspicious activity patterns indicative of identity theft. It assigns a risk level to individual users, enabling organizations to implement proactive security measures like forcing a password reset or blocking access.
- ✓
Sign-in risk detection (e.g., anonymous IP addresses)
Why this is correct
Sign-in risk detection is a critical security function provided by Microsoft Entra ID Protection, a specialized service within the Microsoft Entra suite. It analyzes various signals during a user's sign-in attempt, including anomalies like sign-ins from anonymous IP addresses, impossible travel scenarios, or IP addresses associated with known malware. This real-time analysis helps identify and block suspicious sign-in attempts, preventing unauthorized access to resources and protecting organizational data.
- ✗
Entitlement management
Why it's wrong here
Entitlement management is a robust feature within Microsoft Entra ID Governance, a specific offering designed for managing identity and access lifecycle at scale, not a general feature of Microsoft Entra. It allows organizations to define access packages that bundle resources and policies, enabling users to request access and automating approval workflows and access expiration. This ensures appropriate access for employees, partners, and guests throughout their lifecycle, streamlining access provisioning and deprovisioning.
- ✓
Risk-based Conditional Access policies
Why this is correct
Risk-based Conditional Access policies are a powerful security control within Microsoft Entra, leveraging the sophisticated risk detections from Microsoft Entra ID Protection. These policies automatically enforce specific access requirements, such as mandating multi-factor authentication (MFA), requiring a password change, or blocking access entirely, when a user or sign-in is deemed risky. This dynamic approach significantly enhances security by adapting access controls to the real-time risk posture of an identity or sign-in event.
Go deeper
Related to this question
Learn chapter
Microsoft Entra Global Secure Access
Key term
Threat intelligence
Threat intelligence is evidence-based knowledge about existing or emerging cyber threats that helps organizations defend against attacks.
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.