Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Which TWO capabilities are part of Microsoft Entra ID Protection? (Choose two.)

⚠ Common exam trap

Many candidates confuse the risk-based policies in Entra ID Protection with general Conditional Access policies, but only risk-based policies are part of Entra ID Protection, while device compliance and other conditions belong to the broader Conditional Access service.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Risk-based conditional access policies

Risk-based conditional access policies (B) are a core capability of Microsoft Entra ID Protection, allowing organizations to automatically enforce access controls based on detected risk levels from user and sign-in activities. Reports on risky users and sign-ins (D) provide the foundational telemetry that Entra ID Protection uses to identify and investigate potential identity compromises, making both integral to the service.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Passwordless authentication

    Why it's wrong here

    Passwordless authentication, while enhancing security by eliminating passwords and reducing the attack surface for credential theft, is fundamentally an authentication method provided by Microsoft Entra ID. It allows users to sign in using methods like Windows Hello for Business, Microsoft Authenticator, or FIDO2 security keys. Microsoft Entra ID Protection, however, focuses on detecting, reporting, and automatically remediating identity-based risks, rather than offering specific authentication mechanisms.

  • Risk-based conditional access policies

    Why this is correct

    Microsoft Entra ID Protection is a critical signal source for Conditional Access, enabling the creation of policies that automatically respond to detected risks. These policies can enforce actions like requiring multi-factor authentication, password change, or blocking access entirely when a user or sign-in is deemed risky by ID Protection's machine learning algorithms. This capability allows organizations to dynamically protect resources based on real-time threat intelligence.

  • Just-in-time privileged access

    Why it's wrong here

    Just-in-time (JIT) privileged access is a core capability of Microsoft Entra Privileged Identity Management (PIM), designed to minimize the exposure time of privileged roles. PIM allows eligible users to activate administrative roles for a limited, predefined period, reducing the window for potential abuse or compromise. Microsoft Entra ID Protection, conversely, focuses on detecting identity-based risks and vulnerabilities, not on managing the temporary elevation of privileges.

  • Reports on risky users and sign-ins

    Why this is correct

    Microsoft Entra ID Protection provides comprehensive reports that offer deep insights into detected identity-based risks within an organization. These reports highlight risky users, risky sign-ins, and identified vulnerabilities, detailing the specific risk detections that contributed to the risk level. This visibility enables security administrators to investigate potential threats, understand attack patterns, and take informed remediation actions to secure identities.

  • Conditional access policies for device compliance

    Why it's wrong here

    Conditional Access policies for device compliance ensure that only devices meeting specific security standards, often managed by Microsoft Intune, can access corporate resources. This capability is a fundamental aspect of Microsoft Entra Conditional Access itself, leveraging device state as a condition. While crucial for overall security, it operates independently of Microsoft Entra ID Protection's primary function, which is to detect and respond to identity-based risks like compromised credentials or unusual sign-in patterns.

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.