SC-900 Describe the capabilities of Microsoft Entra Practice Question
Which TWO Microsoft Entra features can be used together to enforce risk-based conditional access?
⚠ Common exam trap
Candidates often confuse Privileged Identity Management (PIM) with risk-based access, but PIM controls role activation, not risk evaluation, while Identity Protection is the dedicated risk detection service.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conditional Access
Conditional Access (B) is correct because it is the policy engine that enforces access decisions based on signals, including risk levels. Identity Protection (C) is correct because it detects and calculates user and sign-in risk in real time using machine learning. Together, Identity Protection provides the risk assessment, and Conditional Access enforces the policy (e.g., block or require MFA) based on that risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Entra Verified ID
Why it's wrong here
Microsoft Entra Verified ID enables organizations to issue and verify digital verifiable credentials, allowing individuals to prove their identity or attributes in a privacy-preserving manner. While it enhances trust in identity verification, it does not directly provide risk detection or policy enforcement capabilities based on user or sign-in risk levels. Its primary function is credential management and verification, not dynamic risk-based access control.
- ✓
Conditional Access
Why this is correct
Microsoft Entra Conditional Access is a policy engine that evaluates conditions, including user and sign-in risk levels detected by Identity Protection, to enforce specific access controls. It allows administrators to define "if-then" statements, such as "if a user is signing in from a risky location, then block access or require multi-factor authentication." This direct integration makes it crucial for implementing risk-based access policies.
- ✓
Identity Protection
Why this is correct
Microsoft Entra Identity Protection continuously monitors user and sign-in behavior to detect various types of identity-based risks, such as leaked credentials, impossible travel, or unfamiliar sign-in properties. It assigns a risk score to users and sign-in attempts based on these detections. This risk information is then fed into Conditional Access policies, enabling automated responses to protect organizational resources.
- ✗
Self-Service Password Reset
Why it's wrong here
Microsoft Entra Self-Service Password Reset (SSPR) allows users to reset their forgotten or locked passwords without administrator intervention, typically by verifying their identity through pre-registered authentication methods. While it improves user productivity and reduces helpdesk calls, SSPR is a specific feature for password management and does not contribute to detecting identity risks or enforcing access policies based on those risks.
- ✗
Privileged Identity Management
Why it's wrong here
Microsoft Entra Privileged Identity Management (PIM) enables organizations to manage, control, and monitor access to important resources by providing just-in-time and just-enough access to privileged roles. It helps reduce the exposure time of privileges, but its core function is privilege governance and auditing, not the real-time detection of user or sign-in risk to dynamically adjust access policies.
Go deeper
Related to this question
Learn chapter
Identity Concepts
Key term
Identity protection
Identity protection is the set of policies, technologies, and practices used to secure digital identities and prevent unauthorized access to systems and data.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.