SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Which TWO features are included in Microsoft Entra ID Identity Protection? (Choose two.)
⚠ Common exam trap
Many candidates confuse Identity Protection's risk detection capabilities with other Microsoft 365 security features like Privileged Identity Management (PIM) or Defender for Cloud Apps, leading them to select just-in-time access or cloud app discovery as correct answers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sign-in risk detection
Microsoft Entra ID Identity Protection is built around two risk signal types: sign-in risk detection (Option B) and user risk detection (Option E). Sign-in risk detection evaluates each authentication attempt in real time using signals such as anonymous IP address, atypical travel, malware-linked IP address, and unfamiliar sign-in properties, and it can trigger Conditional Access policies requiring MFA or blocking access. User risk detection identifies accounts whose credentials are likely compromised, for example through leaked credentials found on the dark web or by detecting anomalous user activity, and it drives remediation such as forced password reset. Option A (just-in-time privileged access) belongs to Microsoft Entra Privileged Identity Management, not Identity Protection. Option C (Cloud app discovery) is a Microsoft Defender for Cloud Apps capability used to discover and assess shadow IT SaaS usage. Option D (multi-factor authentication registration campaign) is an authentication methods policy setting in Microsoft Entra ID that nudges users to register for MFA; it is not one of the risk detections provided by Identity Protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Just-in-time privileged access
Why it's wrong here
Just-in-time (JIT) privileged access is a core feature of Microsoft Entra Privileged Identity Management (PIM). PIM allows organizations to manage, control, and monitor access to important resources by providing time-bound and approval-based role activation. While PIM is an advanced capability within Microsoft Entra ID, it is distinct from the risk detection capabilities offered by Identity Protection, which focuses on identifying compromised identities and risky sign-ins.
- ✓
Sign-in risk detection
Why this is correct
Microsoft Entra ID Identity Protection actively monitors and analyzes various signals in real-time to detect suspicious sign-in attempts. These signals include unfamiliar locations, impossible travel, infected devices, and anonymous IP addresses, indicating a potential compromise of user credentials. By identifying these risky sign-ins, Identity Protection helps organizations prevent unauthorized access and enforce adaptive access policies, such as requiring multi-factor authentication or blocking access.
- ✗
Cloud app discovery
Why it's wrong here
Cloud app discovery is a primary feature of Microsoft Defender for Cloud Apps (MDCA), formerly known as Microsoft Cloud App Security (MCAS). This capability identifies all cloud applications being used across an organization's network, providing visibility into shadow IT and assessing associated risks. While MDCA integrates with Microsoft Entra ID for identity context, cloud app discovery itself is not a component of Microsoft Entra ID Identity Protection, which focuses on user and sign-in risk.
- ✗
Multi-factor authentication registration campaign
Why it's wrong here
Multi-factor authentication (MFA) registration campaigns are a feature configured within Microsoft Entra Conditional Access policies. These campaigns prompt users to register for MFA during their regular sign-in process, gradually rolling out MFA adoption across the organization. While MFA is a crucial security control often enforced based on Identity Protection's risk signals, the registration campaign functionality itself resides within Conditional Access, not directly within Identity Protection's risk detection engine.
- ✓
User risk detection
Why this is correct
Microsoft Entra ID Identity Protection continuously evaluates various indicators to identify users whose accounts may have been compromised. This includes detecting leaked credentials, sign-ins from malware-infected devices, or unusual user behavior patterns that deviate from established baselines. User risk detection assigns a risk level to individual user accounts, enabling administrators to implement proactive remediation actions like password resets or blocking access to protect organizational resources.
Go deeper
Related to this question
Learn chapter
Cloud App Governance and App Consent
Key term
Identity
Identity is the unique set of attributes that defines a user, device, or service in a computer system, determining what they can access and do.
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.