Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Which TWO of the following are included in Microsoft Entra ID Protection?

⚠ Common exam trap

Many candidates confuse the broader Microsoft Entra suite with the specific scope of Entra ID Protection, mistakenly selecting features like PIM or passwordless authentication that are part of Entra but not within ID Protection's risk-detection and remediation capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk-based Conditional Access policies

Option C (Risk-based Conditional Access policies) is correct because Microsoft Entra ID Protection surfaces user and sign-in risk levels that can be consumed directly by Conditional Access as conditions, allowing policies to block access or require MFA/password change when risk is detected. Option D (Sign-in risk detections such as anonymous IP address) is correct because ID Protection natively detects and reports sign-in risks like anonymous IP, atypical travel, malware-linked IP, and unfamiliar sign-in properties, and these detections feed the risk evaluations used by the service. Options A, B, and E are not part of ID Protection: DLP is a Microsoft Purview/Defender for Cloud Apps capability, PIM is a separate Microsoft Entra ID Governance/Privileged Identity Management service for just-in-time role activation, and passwordless authentication (FIDO2, Windows Hello, Authenticator) is a Microsoft Entra authentication method feature rather than an ID Protection component.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data loss prevention (DLP)

    Why it's wrong here

    Data loss prevention (DLP) is a capability within Microsoft Purview, not Microsoft Entra ID Protection. DLP solutions focus on identifying, monitoring, and protecting sensitive information across various locations like Microsoft 365 services, endpoints, and on-premises file shares. Entra ID Protection, conversely, is centered on detecting identity-based risks and vulnerabilities.

  • ✗

    Privileged Identity Management (PIM)

    Why it's wrong here

    Privileged Identity Management (PIM) is a feature of Microsoft Entra ID P2 that enables just-in-time and just-enough access for privileged roles, reducing the attack surface for administrative accounts. While both PIM and Entra ID Protection are premium Entra ID capabilities, PIM focuses on managing and governing access to privileged roles, whereas ID Protection specifically detects and remediates identity-based risks and vulnerabilities. They are complementary but distinct services.

  • ✓

    Risk-based Conditional Access policies

    Why this is correct

    Microsoft Entra ID Protection directly integrates with Conditional Access policies to enable risk-based access decisions. When ID Protection detects a sign-in or user risk, such as an unfamiliar sign-in property or leaked credentials, it can feed this risk information into Conditional Access. These policies can then automatically enforce actions like requiring multi-factor authentication, password changes, or blocking access entirely, thereby protecting resources dynamically.

  • ✓

    Sign-in risk detections (e.g., anonymous IP address)

    Why this is correct

    Microsoft Entra ID Protection is fundamentally designed to detect and report identity-based risks, including various sign-in risk detections. These detections identify suspicious activities during a user's sign-in attempt, such as sign-ins from anonymous IP addresses, unfamiliar locations, impossible travel scenarios, or infected devices. By analyzing these indicators, ID Protection helps organizations identify compromised accounts and potential threats in real-time.

  • ✗

    Passwordless authentication support

    Why it's wrong here

    Passwordless authentication support, encompassing methods like FIDO2 security keys, Windows Hello for Business, and the Microsoft Authenticator app, is a fundamental capability of Microsoft Entra ID. This feature aims to enhance security and user experience by eliminating passwords. While it contributes to overall identity security, it is a core authentication method offered by Entra ID itself, rather than a specific component or feature of Entra ID Protection, which focuses on risk detection and remediation.

Go deeper

Related to this question

About these practice questions

This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.