SC-900 Describe the capabilities of Microsoft Entra Practice Question
Your organization has a Microsoft Entra ID tenant with 5,000 users. You need to implement a solution that automatically detects and remediates users with leaked credentials. Additionally, you need to require users to change their password when a high risk is detected. Which Microsoft Entra features should you configure?
⚠ Common exam trap
Candidates often confuse user risk (which detects leaked credentials and other user-level threats) with sign-in risk (which evaluates real-time session anomalies), leading candidates to incorrectly select Option D, which only addresses sign-in risk and not the required leaked credential detection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Microsoft Entra Identity Protection, configure a user risk policy to require password change when risk is medium or high.
Microsoft Entra Identity Protection detects leaked credentials by monitoring for credential exposures on the dark web and other sources. Configuring a user risk policy to require a password change when risk is medium or high automatically remediates the detected risk by forcing the user to update their password, directly addressing the requirement for automatic detection and remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable Microsoft Entra Identity Protection, configure a user risk policy to require password change when risk is medium or high.
Why this is correct
Microsoft Entra Identity Protection actively monitors for various risk detections, including leaked credentials, which are identified through dark web monitoring and other sources. A user risk policy, configured within Identity Protection, can then automatically enforce remediation actions like requiring a password change when a user's aggregated risk level (e.g., medium or high) indicates potential compromise. This direct linkage ensures that detected credential compromises are promptly addressed.
- ✗
Create an Access Review for all users and require them to confirm their access quarterly.
Why it's wrong here
Access Reviews are a governance tool designed to periodically ensure that users still have appropriate access to resources, often by requiring managers or resource owners to confirm continued need. While crucial for maintaining a strong security posture by removing stale or excessive permissions, they do not actively monitor for or detect security incidents like leaked credentials. Their purpose is about validating existing access, not identifying external compromises.
- ✗
Enable Privileged Identity Management (PIM) and require multi-factor authentication for all role activations.
Why it's wrong here
Microsoft Entra Privileged Identity Management (PIM) focuses on managing, controlling, and monitoring access to important resources within Microsoft Entra ID, Azure, and other Microsoft services. It enables just-in-time access, requiring users to activate roles for a limited time and often with multi-factor authentication, thereby reducing the attack surface for privileged accounts. However, PIM's core function is not to detect external security threats like leaked credentials; it's about securing the *use* of privileged roles.
- ✗
Configure a Conditional Access policy to require password change when sign-in risk is high.
Why it's wrong here
Conditional Access policies can indeed leverage sign-in risk signals to enforce actions like requiring a password change. However, Conditional Access itself does not *detect* leaked credentials; it consumes risk scores provided by Microsoft Entra ID Protection's real-time sign-in risk detections. While a Conditional Access policy can *respond* to high sign-in risk, it's Identity Protection that performs the underlying analysis, including identifying leaked credentials, which then feeds into the sign-in risk assessment.
Go deeper
Related to this question
Learn chapter
Identity Concepts
Key term
Identity protection
Identity protection is the set of policies, technologies, and practices used to secure digital identities and prevent unauthorized access to systems and data.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.