Courseiva

Microsoft Entra ID Identity Risk Detection and Remediation: Identity Protection and Conditional Access

Which TWO Microsoft Entra ID capabilities help detect and remediate identity risks? (Select two.)

Quick Answer

The answer is Conditional Access and Identity Protection. Identity Protection is the detection engine that analyzes signals like leaked credentials, anonymous IP addresses, and atypical travel to assign a risk level to each user or sign-in, while Conditional Access acts as the remediation engine by enforcing automated policies—such as requiring multi-factor authentication or blocking access—when a risk threshold is met. On the SC-900 exam, this pairing tests your understanding of how Microsoft Entra ID identity risk detection and remediation work together as a closed-loop system; a common trap is confusing Privileged Identity Management (PIM), which controls just-in-time admin roles, with risk remediation. Remember the mnemonic “Detect with Protection, Remediate with Access” to keep the two distinct.

⚠ Common exam trap

Many exam-takers confuse Privileged Identity Management (PIM) with risk remediation, but PIM only manages privileged role activation and does not detect or automatically remediate identity risks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identity Protection

Microsoft Entra ID Protection (option A) is correct because it uses Microsoft's threat intelligence and machine learning to detect identity risks such as leaked credentials, anonymous IP usage, and atypical sign-in behavior, generating risk detections and risk levels (low/medium/high) for users and sign-ins that can trigger automated remediation. Conditional Access (option E) is correct because it enforces access controls based on signals including user risk and sign-in risk reported by Identity Protection, allowing remediation actions such as requiring multi-factor authentication, forcing a secure password change, or blocking access when risk is elevated. Together, Identity Protection detects the risk and Conditional Access remediates it, which is exactly the detect-and-remediate identity risk scenario described. Identity Governance (option B) focuses on access reviews, entitlement management, and lifecycle workflows rather than risk detection. Password protection (option C) enforces banned-password lists and on-premises password policies but does not detect or remediate identity risk signals. Privileged Identity Management (option D) provides just-in-time privileged role activation, approval, and access reviews for admin roles, not risk-based detection or remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Identity Protection

    Why this is correct

    Identity Protection detects risky users and sign-ins through Microsoft's threat intelligence and feeds those detections into risk-based Conditional Access, enabling automatic remediation such as requiring MFA or blocking access. This satisfies the requirement for detecting and remediating identity risks.

  • ✗

    Identity Governance

    Why it's wrong here

    Identity Governance handles access reviews, entitlement management and lifecycle workflows, which enforce policy rather than detect anomalous sign-ins. It fits periodic attestation of who holds access; detecting and remediating identity risk is the function of Identity Protection.

  • ✗

    Password protection

    Why it's wrong here

    Password protection blocks weak or banned passwords at set and change time, a preventive control against credential guessing. It suits enforcing password policy, but it neither scores sign-in risk nor remediates compromised identities, which Identity Protection does.

  • ✗

    Privileged Identity Management

    Why it's wrong here

    Privileged Identity Management governs just-in-time activation and approval of privileged roles; it does not analyse sign-in or user behaviour to flag compromised accounts. It is the right control for standing-access risk, whereas risk detection and remediation require Identity Protection.

  • ✓

    Conditional Access

    Why this is correct

    Conditional Access enforces real-time access decisions based on signals such as user risk and sign-in risk reported by Microsoft Entra ID Protection, so a risky session can be blocked or forced through MFA. This satisfies the detect-and-remediate requirement by acting on identity risk rather than merely reporting it.

About these practice questions

One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO are capabilities of Microsoft Entra ID Protection?

easy
  • ✓ A.Risk-based conditional access policies
  • B.Device enrollment policies
  • C.Self-service password reset
  • D.Privileged role activation
  • ✓ E.Detection of leaked credentials

Why A: Microsoft Entra ID Protection uses risk-based conditional access policies to automatically respond to detected risks, such as blocking access or requiring multi-factor authentication, based on real-time risk levels. Option E is correct because Entra ID Protection continuously monitors for leaked credentials by analyzing known credential breaches and flagging accounts whose credentials have been exposed, enabling proactive remediation.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.