Courseiva
Describe the capabilities of Microsoft EntrahardMultiple ChoiceObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

Your organization, Contoso, uses Microsoft Entra ID for identity management. The security team has recently identified that several users have had their credentials compromised. You need to implement a solution that automatically enforces a password change for high-risk users and blocks sign-ins from risky locations. Additionally, you want to allow users to self-remediate by changing their password when they are at medium risk. You have the following requirements: - Users detected as high risk must be blocked from signing in until an administrator resets their password. - Users detected as medium risk must be prompted to change their password via self-service password reset before they can access resources. - All risk detections must be logged and reported to the security team. - The solution must use built-in Microsoft Entra capabilities without third-party tools.

Which of the following actions should you take to meet the requirements?

⚠ Common exam trap

A common mix-up: candidates confuse conditional access policies (which control access based on conditions like location or device) with Identity Protection risk policies (which specifically enforce actions based on user or sign-in risk levels), leading them to choose Option A instead of the correct risk-based policy configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure Microsoft Entra ID Protection user risk policies: set a policy to block access for high user risk and a policy to require password change for medium user risk. Enable risk reporting.

Microsoft Entra ID Protection provides built-in user risk policies that automatically block sign-ins for high-risk users and require a password change for medium-risk users, meeting the requirements for automated enforcement and self-remediation. Additionally, ID Protection includes risk reporting capabilities that log all risk detections for the security team, all without third-party tools.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create conditional access policies that block sign-ins based on location and require MFA for all users.

    Why it's wrong here

    Creating Conditional Access policies to block sign-ins based on location or enforce MFA for all users does not directly address the need for risk-based automated remediation, such as forcing a password change for medium user risk. While Conditional Access can enforce MFA, it lacks the dynamic intelligence of Entra ID Protection to detect compromised credentials and automatically trigger a password reset based on specific user risk levels. Location-based blocking is a static control, not a response to dynamic user risk.

  • Configure Microsoft Entra ID Protection user risk policies: set a policy to block access for high user risk and a policy to require password change for medium user risk. Enable risk reporting.

    Why this is correct

    Configuring Microsoft Entra ID Protection user risk policies directly fulfills all requirements by leveraging machine learning to detect anomalous user behavior and assign a risk level. A policy can be set to automatically block access for users deemed high risk, preventing potential breaches. Concurrently, another policy can enforce a password change for users with medium risk, proactively mitigating credential compromise. Enabling risk reporting ensures ongoing visibility and auditing of these security events.

  • Administratively assign users to administrative units and require administrators to review risk manually.

    Why it's wrong here

    Administratively assigning users to administrative units is a feature designed for delegating administrative permissions over specific sets of users or devices, not for automated risk detection or remediation. While administrative units can help organize users, they do not provide the necessary intelligence to identify user risk or trigger automated responses like blocking access or requiring password changes. Relying on manual review for risk remediation is inefficient and does not meet the requirement for automated action.

  • Use Microsoft Entra ID Governance to create an access package and require approval for access.

    Why it's wrong here

    Using Microsoft Entra ID Governance to create an access package and require approval for access is a solution focused on managing the lifecycle of access to resources, including self-service access requests and access reviews. This feature is designed for provisioning and reviewing access entitlements, not for detecting or remediating identity-based security risks such as compromised credentials or anomalous user behavior. Access packages do not integrate with risk signals to trigger security actions like password resets or access blocking.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.