SC-900 Describe the capabilities of Microsoft Entra Practice Question
You are a security administrator for a company using Microsoft Entra ID P2. The company has a critical application that should only be accessible by a specific group of users (the 'Finance' group). You need to ensure that any access to this application is automatically logged and that an administrator is notified when a user outside the Finance group attempts to access it. Additionally, the CEO wants a quarterly review of all users who have access to this application. Which combination of features should you use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Conditional Access policy that restricts access to the Finance group, configure audit logging for the application, and set up an access review for the Finance group.
It combines Conditional Access to restrict access to the Finance group, audit logging to log access attempts (and trigger alerts), and access reviews for quarterly recertification. Option A is wrong because B2B collaboration is for external users, not for internal group-based access control. Option B is wrong because Identity Protection is for risk detection, not for group-based access restrictions. Option C is wrong because Privileged Identity Management (PIM) is for managing privileged roles, not for assigning application access to standard user groups.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Grant access to the application via B2B collaboration and configure auditing.
Why it's wrong here
B2B is for external users, not internal group management.
- ✗
Use Identity Protection to detect access attempts from non-Finance users and send alerts.
Why it's wrong here
Identity Protection does not block access based on group membership.
- ✗
Assign the application to the Finance group using Privileged Identity Management, and enable sign-in logs.
Why it's wrong here
PIM is for role activation, not application assignment.
- ✓
Create a Conditional Access policy that restricts access to the Finance group, configure audit logging for the application, and set up an access review for the Finance group.
Why this is correct
Conditional Access enforces access restriction, audit logs capture activity, and access reviews provide periodic recertification.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
PIM
Privileged Identity Management, a Microsoft Azure Active Directory tool that manages, monitors, and controls access to privileged roles on a just-in-time basis.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.