SC-900 Practice Question: Describe the concepts of security, compliance, and identity
Your organization is adopting a Zero Trust security model. You are tasked with implementing identity protection. The requirements are: enforce multi-factor authentication (MFA) for all users when accessing cloud applications, ensure that risky sign-ins are detected and blocked automatically, and provide administrators with a dashboard showing user risk levels. You have Microsoft Entra ID P2 licenses. What should you configure?
⚠ Common exam trap
SC-900 often tests the confusion between Microsoft Entra ID Identity Protection and other security services like Microsoft Defender for Cloud Apps or Microsoft Sentinel, leading candidates to choose a CASB or SIEM solution for identity protection requirements that are natively handled by Entra ID P2 features.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a Conditional Access policy to require MFA for all cloud apps, enable Identity Protection to detect and automatically block risky sign-ins, and use the Identity Protection dashboard.
Microsoft Entra ID P2 includes Identity Protection, which provides risk detection for sign-ins and users, and Conditional Access, which enforces access controls like MFA. A Conditional Access policy requiring MFA for all cloud apps directly meets the first requirement. Enabling Identity Protection allows automatic blocking of risky sign-ins via risk-based Conditional Access policies, and the Identity Protection dashboard shows user risk levels, satisfying the remaining requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure Microsoft Sentinel to collect sign-in logs and create custom alerts for risky sign-ins.
Why it's wrong here
Sentinel ingests sign-in logs and raises alerts, but it neither enforces MFA nor blocks risky sign-ins, and its workbooks are not Entra ID's risk dashboard. It suits custom SIEM correlation and long-term log analytics across many sources, not identity protection enforcement.
- ✓
Configure a Conditional Access policy to require MFA for all cloud apps, enable Identity Protection to detect and automatically block risky sign-ins, and use the Identity Protection dashboard.
Why this is correct
Conditional Access enforces MFA for all cloud apps, while Microsoft Entra ID Protection detects risky sign-ins and can automatically block them, and its dashboard surfaces user risk levels. Together these satisfy all three stated requirements using the P2 licences already held.
- ✗
Configure Privileged Identity Management for all users and enable MFA.
Why it's wrong here
Privileged Identity Management governs eligible role activation and just-in-time elevation for privileged accounts, not sign-in risk evaluation or MFA enforcement for all users. It is the right choice when you need approval workflows and time-bound role assignments for administrators.
- ✗
Configure Microsoft Defender for Cloud Apps to require MFA and detect risky sign-ins.
Why it's wrong here
Defender for Cloud Apps applies Conditional Access App Control to sessions and detects anomalies, but it does not compute Entra ID's own sign-in and user risk levels or present the Identity Protection risk reports. It suits cloud app discovery and session policies for sanctioned SaaS apps.
Go deeper
Related to this question
Learn chapter
Microsoft Defender for Cloud Apps
Key term
Time-based One-time Password
A temporary, automatically generated code that changes every few seconds and is used as an extra layer of security when logging into an account.
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.