Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Which TWO features are included in Microsoft Entra ID Identity Protection? (Choose two.)

⚠ Common exam trap

Many candidates confuse Identity Protection's risk detection capabilities with other Microsoft 365 security features like Privileged Identity Management (PIM) or Defender for Cloud Apps, leading them to select just-in-time access or cloud app discovery as correct answers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Sign-in risk detection

Microsoft Entra ID Identity Protection is built around two risk signal types: sign-in risk detection (Option B) and user risk detection (Option E). Sign-in risk detection evaluates each authentication attempt in real time using signals such as anonymous IP address, atypical travel, malware-linked IP address, and unfamiliar sign-in properties, and it can trigger Conditional Access policies requiring MFA or blocking access. User risk detection identifies accounts whose credentials are likely compromised, for example through leaked credentials found on the dark web or by detecting anomalous user activity, and it drives remediation such as forced password reset. Option A (just-in-time privileged access) belongs to Microsoft Entra Privileged Identity Management, not Identity Protection. Option C (Cloud app discovery) is a Microsoft Defender for Cloud Apps capability used to discover and assess shadow IT SaaS usage. Option D (multi-factor authentication registration campaign) is an authentication methods policy setting in Microsoft Entra ID that nudges users to register for MFA; it is not one of the risk detections provided by Identity Protection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Just-in-time privileged access

    Why it's wrong here

    Just-in-time (JIT) privileged access is a core feature of Microsoft Entra Privileged Identity Management (PIM). PIM allows organizations to manage, control, and monitor access to important resources by providing time-bound and approval-based role activation. While PIM is an advanced capability within Microsoft Entra ID, it is distinct from the risk detection capabilities offered by Identity Protection, which focuses on identifying compromised identities and risky sign-ins.

  • ✓

    Sign-in risk detection

    Why this is correct

    Microsoft Entra ID Identity Protection actively monitors and analyzes various signals in real-time to detect suspicious sign-in attempts. These signals include unfamiliar locations, impossible travel, infected devices, and anonymous IP addresses, indicating a potential compromise of user credentials. By identifying these risky sign-ins, Identity Protection helps organizations prevent unauthorized access and enforce adaptive access policies, such as requiring multi-factor authentication or blocking access.

  • ✗

    Cloud app discovery

    Why it's wrong here

    Cloud app discovery is a primary feature of Microsoft Defender for Cloud Apps (MDCA), formerly known as Microsoft Cloud App Security (MCAS). This capability identifies all cloud applications being used across an organization's network, providing visibility into shadow IT and assessing associated risks. While MDCA integrates with Microsoft Entra ID for identity context, cloud app discovery itself is not a component of Microsoft Entra ID Identity Protection, which focuses on user and sign-in risk.

  • ✗

    Multi-factor authentication registration campaign

    Why it's wrong here

    Multi-factor authentication (MFA) registration campaigns are a feature configured within Microsoft Entra Conditional Access policies. These campaigns prompt users to register for MFA during their regular sign-in process, gradually rolling out MFA adoption across the organization. While MFA is a crucial security control often enforced based on Identity Protection's risk signals, the registration campaign functionality itself resides within Conditional Access, not directly within Identity Protection's risk detection engine.

  • ✓

    User risk detection

    Why this is correct

    Microsoft Entra ID Identity Protection continuously evaluates various indicators to identify users whose accounts may have been compromised. This includes detecting leaked credentials, sign-ins from malware-infected devices, or unusual user behavior patterns that deviate from established baselines. User risk detection assigns a risk level to individual user accounts, enabling administrators to implement proactive remediation actions like password resets or blocking access to protect organizational resources.

About these practice questions

One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.