Courseiva

SC-900 Describe the capabilities of Microsoft Entra Practice Question

Which TWO Microsoft Entra ID features can be used to protect against credential theft? (Choose two.)

⚠ Common exam trap

Candidates often confuse SSPR (a recovery mechanism) with a preventive control, or mistakenly think Entra ID Connect or Domain Services offer security features they do not, when the question specifically asks for features that protect against credential theft.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Passwordless authentication

Passwordless authentication (A) is correct because it removes the password from the sign-in process entirely, using methods such as Windows Hello for Business, FIDO2 security keys, or the Microsoft Authenticator app, so there is no password credential for attackers to phish, replay, or steal. Conditional Access policies that require MFA (E) are correct because they enforce a second verification factor at sign-in, so even if a password is compromised through phishing or breach, the stolen credential alone is insufficient to authenticate. SSPR (B) only lets users reset forgotten passwords and does not itself prevent credential theft. Microsoft Entra ID Domain Services (C) provides managed domain services such as LDAP and domain join for legacy workloads, and Microsoft Entra ID Connect (D) synchronizes on-premises identities to Entra ID; neither feature directly protects credentials from theft.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Passwordless authentication

    Why this is correct

    Passwordless authentication significantly enhances security by eliminating the primary target for many credential theft attacks: the password itself. By replacing passwords with more secure methods like FIDO2 security keys, Windows Hello for Business, or the Microsoft Authenticator app, organizations remove the risk of passwords being phished, brute-forced, or stolen through credential stuffing. This approach fundamentally reduces the attack surface for identity-based breaches.

  • ✗

    Self-Service Password Reset (SSPR)

    Why it's wrong here

    Self-Service Password Reset (SSPR) is designed as a recovery mechanism, enabling users to independently reset forgotten or expired passwords without IT intervention. While it improves user experience and reduces help desk calls, SSPR does not prevent credential theft; rather, it facilitates regaining access *after* a password issue, which could include a compromise. Its primary function is access recovery, not proactive protection against initial theft.

  • ✗

    Microsoft Entra ID Domain Services

    Why it's wrong here

    Microsoft Entra ID Domain Services provides managed domain services, such as domain join, group policy, LDAP, and Kerberos/NTLM authentication, for cloud-based virtual machines and applications. It extends traditional Active Directory capabilities to Azure, allowing legacy applications to run without deploying and managing domain controllers. However, it is an infrastructure service that *uses* credentials within a managed domain environment, not a direct feature for *preventing* credential theft from Microsoft Entra ID itself.

  • ✗

    Microsoft Entra ID Connect

    Why it's wrong here

    Microsoft Entra ID Connect is a synchronization tool that bridges an on-premises Active Directory environment with Microsoft Entra ID, facilitating a hybrid identity solution. Its primary function is to synchronize user accounts, password hashes (via Password Hash Synchronization), or enable pass-through authentication, and other identity data between the two directories. While essential for hybrid identity management, it does not inherently provide features to *prevent* credential theft; rather, it ensures identity consistency, which then relies on other Microsoft Entra ID security features for protection.

  • ✓

    Conditional Access policies that require MFA

    Why this is correct

    Conditional Access policies are powerful security controls in Microsoft Entra ID that enforce specific access requirements based on various conditions, such as user location, device state, or application being accessed. By configuring a Conditional Access policy to require Multi-Factor Authentication (MFA) for specific scenarios, even if an attacker manages to steal a user's password, they would be unable to gain unauthorized access without also possessing the second authentication factor. This significantly elevates the barrier for credential-based attacks.

Go deeper

Related to this question

About these practice questions

One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.