SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Which TWO capabilities are part of Microsoft Entra ID Protection? (Choose two.)
⚠ Common exam trap
Many candidates confuse the risk-based policies in Entra ID Protection with general Conditional Access policies, but only risk-based policies are part of Entra ID Protection, while device compliance and other conditions belong to the broader Conditional Access service.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk-based conditional access policies
Risk-based conditional access policies (B) are a core capability of Microsoft Entra ID Protection, allowing organizations to automatically enforce access controls based on detected risk levels from user and sign-in activities. Reports on risky users and sign-ins (D) provide the foundational telemetry that Entra ID Protection uses to identify and investigate potential identity compromises, making both integral to the service.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Passwordless authentication
Why it's wrong here
Passwordless authentication, while enhancing security by eliminating passwords and reducing the attack surface for credential theft, is fundamentally an authentication method provided by Microsoft Entra ID. It allows users to sign in using methods like Windows Hello for Business, Microsoft Authenticator, or FIDO2 security keys. Microsoft Entra ID Protection, however, focuses on detecting, reporting, and automatically remediating identity-based risks, rather than offering specific authentication mechanisms.
- ✓
Risk-based conditional access policies
Why this is correct
Microsoft Entra ID Protection is a critical signal source for Conditional Access, enabling the creation of policies that automatically respond to detected risks. These policies can enforce actions like requiring multi-factor authentication, password change, or blocking access entirely when a user or sign-in is deemed risky by ID Protection's machine learning algorithms. This capability allows organizations to dynamically protect resources based on real-time threat intelligence.
- ✗
Just-in-time privileged access
Why it's wrong here
Just-in-time (JIT) privileged access is a core capability of Microsoft Entra Privileged Identity Management (PIM), designed to minimize the exposure time of privileged roles. PIM allows eligible users to activate administrative roles for a limited, predefined period, reducing the window for potential abuse or compromise. Microsoft Entra ID Protection, conversely, focuses on detecting identity-based risks and vulnerabilities, not on managing the temporary elevation of privileges.
- ✓
Reports on risky users and sign-ins
Why this is correct
Microsoft Entra ID Protection provides comprehensive reports that offer deep insights into detected identity-based risks within an organization. These reports highlight risky users, risky sign-ins, and identified vulnerabilities, detailing the specific risk detections that contributed to the risk level. This visibility enables security administrators to investigate potential threats, understand attack patterns, and take informed remediation actions to secure identities.
- ✗
Conditional access policies for device compliance
Why it's wrong here
Conditional Access policies for device compliance ensure that only devices meeting specific security standards, often managed by Microsoft Intune, can access corporate resources. This capability is a fundamental aspect of Microsoft Entra Conditional Access itself, leveraging device state as a condition. While crucial for overall security, it operates independently of Microsoft Entra ID Protection's primary function, which is to detect and respond to identity-based risks like compromised credentials or unusual sign-in patterns.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.