SC-900 Describe the capabilities of Microsoft Entra Practice Question
Which TWO scenarios are addressed by Microsoft Entra ID Protection? (Choose two.)
⚠ Common exam trap
Many exam-takers confuse Identity Protection's risk detection and remediation capabilities with other Microsoft Entra features like SSPR, access reviews, or device compliance, leading candidates to select options that are not part of the Identity Protection service.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Detecting leaked credentials on the dark web
Entra ID Protection is a risk-based identity protection service that detects and remediates identity risks in real time. Option A is correct because ID Protection's leaked credentials detection scans the dark web for compromised user credentials and raises a user risk when a match is found, prompting remediation such as password reset or risk-based Conditional Access. Option E is correct because ID Protection includes sign-in risk detections such as 'Anonymous IP address' (along with atypical travel, impossible travel, malware-linked IP, and unfamiliar sign-in properties) that can block or challenge sign-ins via Conditional Access policies. Option B is not correct because reviewing group membership assignments is a governance/access-review task handled by Entra ID Access Reviews or entitlement management, not ID Protection. Option C is not correct because device compliance enforcement is handled by Microsoft Intune and Conditional Access device-compliance policies, not by ID Protection. Option D is not correct because self-service password reset (SSPR) is a separate Entra ID feature for credential recovery, not a risk detection or remediation capability of ID Protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Detecting leaked credentials on the dark web
Why this is correct
Microsoft Entra ID Protection ingests signals indicating compromised accounts, including leaked credential pairs discovered on dark web sources. This detection surfaces as a risk detection, letting risk-based Conditional Access policies respond, which satisfies the leaked-credentials scenario named in the question.
- ✗
Reviewing group membership assignments
Why it's wrong here
ID Protection surfaces risk detections and risk-based conditional access policies; group membership review is handled by access reviews in Microsoft Entra ID Governance. It is tempting because both concern identity hygiene, but reviewing assignments addresses entitlement creep, not sign-in risk.
- ✗
Enforcing device compliance policies
Why it's wrong here
Device compliance policies are enforced by Conditional Access, which evaluates device state at sign-in; Entra ID Protection instead detects and scores identity risk signals such as leaked credentials and anomalous sign-ins. It would be tempting when the requirement is blocking unmanaged devices from accessing resources, where Conditional Access is the correct control.
- ✗
Resetting forgotten passwords
Why it's wrong here
ID Protection detects and remediates risky sign-ins and compromised identities; self-service password reset is a separate Microsoft Entra ID feature. It is tempting because both reduce helpdesk load, but password resetting addresses credential recovery, not risk detection.
- ✓
Blocking sign-ins from anonymous IP addresses
Why this is correct
Microsoft Entra ID Protection flags sign-ins originating from anonymous IP addresses, such as Tor exit nodes or anonymising proxies, as a risk detection. Administrators then apply risk-based Conditional Access to block or challenge those sign-ins, satisfying the anonymous IP scenario in the stem.
Go deeper
Related to this question
Learn chapter
Microsoft Defender for Identity
Key term
Device compliance
Device compliance is the process of ensuring that a device meets an organization's security and configuration policies before it can access network resources.
Key term
Governance
Governance is the framework of policies, processes, and controls that ensures IT activities align with business goals and comply with regulations.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.