Courseiva
Describe the capabilities of Microsoft EntraeasyMultiple ChoiceObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

You are a security administrator for a company using Microsoft Entra ID P2. The company has a critical application that should only be accessible by a specific group of users (the 'Finance' group). You need to ensure that any access to this application is automatically logged and that an administrator is notified when a user outside the Finance group attempts to access it. Additionally, the CEO wants a quarterly review of all users who have access to this application. Which combination of features should you use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a Conditional Access policy that restricts access to the Finance group, configure audit logging for the application, and set up an access review for the Finance group.

It combines Conditional Access to restrict access to the Finance group, audit logging to log access attempts (and trigger alerts), and access reviews for quarterly recertification. Option A is wrong because B2B collaboration is for external users, not for internal group-based access control. Option B is wrong because Identity Protection is for risk detection, not for group-based access restrictions. Option C is wrong because Privileged Identity Management (PIM) is for managing privileged roles, not for assigning application access to standard user groups.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Grant access to the application via B2B collaboration and configure auditing.

    Why it's wrong here

    B2B is for external users, not internal group management.

  • Use Identity Protection to detect access attempts from non-Finance users and send alerts.

    Why it's wrong here

    Identity Protection does not block access based on group membership.

  • Assign the application to the Finance group using Privileged Identity Management, and enable sign-in logs.

    Why it's wrong here

    PIM is for role activation, not application assignment.

  • Create a Conditional Access policy that restricts access to the Finance group, configure audit logging for the application, and set up an access review for the Finance group.

    Why this is correct

    Conditional Access enforces access restriction, audit logs capture activity, and access reviews provide periodic recertification.

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.