Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

Which TWO of the following are benefits of using Microsoft Entra ID for identity management?

⚠ Common exam trap

SC-900 often tests whether candidates confuse Entra ID features (like password hash sync) with benefits, or mistakenly believe Entra ID replaces on-premises Active Directory.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Single sign-on (SSO) to cloud applications

Option A is correct because Microsoft Entra ID provides single sign-on (SSO), allowing users to authenticate once and access many cloud applications (e.g., Microsoft 365, Salesforce) via protocols like SAML 2.0, WS-Federation, or OpenID Connect, which is a core identity-management benefit. Option C is correct because Entra ID natively supports multi-factor authentication (MFA), adding a second verification factor (such as the Microsoft Authenticator app, SMS, or FIDO2 key) to strengthen sign-in security, which is a primary benefit of the service. Option B is not a benefit of Entra ID itself but rather a specific hybrid identity synchronization method (via Microsoft Entra Connect) used to sync on-premises password hashes to the cloud. Option D is incorrect because automated security incident detection is a capability of Microsoft Defender/Sentinel, not a core identity-management benefit of Entra ID. Option E is incorrect because Entra ID is a cloud identity provider and does not replace on-premises Active Directory Domain Services; the two are typically used together in hybrid scenarios.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Single sign-on (SSO) to cloud applications

    Why this is correct

    Single sign-on (SSO) to cloud applications is a core benefit of Microsoft Entra ID, enabling users to authenticate once with their Entra ID credentials and gain seamless access to thousands of integrated Software-as-a-Service (SaaS) applications. This capability significantly enhances user productivity by eliminating the need to remember multiple passwords and repeatedly log in, while also improving security by centralizing identity management. Entra ID acts as the central identity provider, issuing secure tokens after initial authentication.

  • ✗

    Password hash synchronization

    Why it's wrong here

    Password hash synchronization (PHS) is a specific method utilized by Microsoft Entra Connect to synchronize user identities and their password hashes from an on-premises Active Directory to Microsoft Entra ID. While PHS is a crucial component for enabling hybrid identity scenarios and allowing users to authenticate to cloud services with their existing on-premises credentials, it is a *feature* or *method* of synchronization, not a direct end-user or administrative *benefit* of Entra ID itself. The benefit comes from the resulting unified identity experience, which PHS helps facilitate.

  • ✓

    Multi-factor authentication (MFA)

    Why this is correct

    Multi-factor authentication (MFA) is a fundamental security benefit provided by Microsoft Entra ID, allowing organizations to require users to verify their identity using two or more verification methods. Entra ID offers robust, built-in MFA capabilities, supporting various methods such as the Microsoft Authenticator app, FIDO2 security keys, and biometrics. Implementing MFA significantly strengthens security by making it much harder for unauthorized users to gain access, even if they manage to compromise a user's password.

  • ✗

    Automated security incident detection

    Why it's wrong here

    Automated security incident detection is not a primary or core benefit of Microsoft Entra ID itself, which primarily focuses on identity and access management. While Entra ID generates extensive audit logs and sign-in reports that can be used for security analysis, the advanced, automated detection and response to security incidents across an entire environment are typically handled by broader security services. These capabilities are provided by solutions like Microsoft Sentinel for Security Information and Event Management (SIEM) or Microsoft 365 Defender for Extended Detection and Response (XDR), which consume Entra ID data but operate at a higher level of security operations.

  • ✗

    Replacement of on-premises Active Directory

    Why it's wrong here

    Microsoft Entra ID is not a replacement for on-premises Active Directory Domain Services (AD DS); rather, it is a complementary cloud-based identity and access management solution designed for cloud applications and services. Many organizations operate in a hybrid identity model where Entra ID coexists with on-premises AD DS, with identities synchronized between the two using Microsoft Entra Connect. This allows users to access both on-premises resources managed by AD DS and cloud resources managed by Entra ID using a single set of credentials, leveraging the strengths of both systems.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.