SC-900 Describe the capabilities of Microsoft Entra Practice Question
Your company uses Microsoft Entra ID. You need to monitor and detect suspicious sign-in activities, such as sign-ins from anonymous IP addresses or unfamiliar locations. Which Microsoft Entra feature provides this capability?
⚠ Common exam trap
Many candidates confuse Conditional Access (a policy enforcement engine) with the detection capability itself, not realizing that Conditional Access relies on risk assessments from ID Protection to act on suspicious sign-ins.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID Protection
Microsoft Entra ID Protection is the correct answer because it is specifically designed to detect and respond to identity-based risks, including suspicious sign-in activities such as sign-ins from anonymous IP addresses (e.g., Tor network) and unfamiliar locations. It uses machine learning algorithms and heuristic detection to assign a risk level to each sign-in, enabling automated remediation or alerting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra audit logs
Why it's wrong here
Microsoft Entra audit logs provide a historical record of all activities within the tenant, such as user sign-ins, application access, and administrative changes. While crucial for forensic analysis and compliance, these logs are primarily a data source. They do not inherently perform real-time analysis or apply machine learning algorithms to identify anomalous or suspicious patterns indicative of identity compromise, which requires a dedicated threat detection service.
- ✗
Conditional Access
Why it's wrong here
Conditional Access policies are a powerful enforcement engine that evaluates specific conditions, such as user location, device compliance, or sign-in risk level, to grant or block access to resources. Its primary function is to enforce predefined access controls based on these conditions. However, Conditional Access itself does not actively detect or identify suspicious user behavior or identity-based threats; it relies on other services, like Microsoft Entra ID Protection, to provide the risk signals it can then act upon.
- ✗
Microsoft Entra Connect
Why it's wrong here
Microsoft Entra Connect is a synchronization service designed to integrate on-premises directories, such as Active Directory Domain Services, with Microsoft Entra ID. Its core purpose is to provision and synchronize user identities, groups, and contacts between these environments, ensuring a consistent identity experience. This tool is solely focused on directory synchronization and has no capabilities for monitoring sign-in activities, detecting identity-based risks, or identifying suspicious patterns.
- ✓
Microsoft Entra ID Protection
Why this is correct
Microsoft Entra ID Protection is specifically designed to detect, investigate, and remediate identity-based risks. It leverages machine learning and heuristic rules to analyze sign-in and user behavior data in real-time, identifying suspicious patterns such as impossible travel, unfamiliar sign-in properties, or leaked credentials. This service automatically generates risk detections and can trigger automated responses, like requiring multi-factor authentication or blocking access, making it the primary tool for monitoring and protecting against identity threats.
Go deeper
Related to this question
Learn chapter
Identity Concepts
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.