SC-900 Describe the capabilities of Microsoft Entra Practice Question
Your organization is using Microsoft Entra Permissions Management (CIEM). You need to identify overprivileged identities in AWS. Which capability should you use?
⚠ Common exam trap
Many exam-takers confuse 'Permissions Analytics Report' with generic auditing features like Audit trail or Activity trail, assuming any logging tool can identify overprivileged identities, but only the report performs the specific analysis of permissions versus usage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Permissions Analytics Report
Permissions Analytics Report is the correct capability because it specifically analyzes permissions across AWS, Azure, and GCP to identify overprivileged identities, unused permissions, and risky actions. It generates a detailed report that highlights identities with excessive permissions, enabling remediation to enforce least privilege. This aligns directly with the CIEM (Cloud Infrastructure Entitlement Management) goal of reducing privilege risks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Audit trail
Why it's wrong here
An audit trail in Microsoft Entra records administrative and configuration changes, such as when a user's role was assigned or modified, or when a policy was created. While crucial for security investigations and compliance by showing who performed what action and when, it does not inherently analyze the current state of an identity's permissions against their actual usage to identify overprivileged access. Its primary function is to log changes, not to proactively report on the excessiveness of existing permissions.
- ✓
Permissions Analytics Report
Why this is correct
The Permissions Analytics Report within Microsoft Entra Permissions Management is specifically designed to identify overprivileged identities by analyzing granted permissions against actual usage data over a defined period. This report leverages machine learning to compare an identity's assigned permissions with the specific actions they have performed, highlighting unused, high-risk, or excessive permissions. It provides actionable insights to right-size permissions and enforce the principle of least privilege effectively.
- ✗
Identity governance
Why it's wrong here
Identity governance in Microsoft Entra is a broad capability set that helps organizations manage identity and access lifecycles, including access reviews, entitlement management, and privileged identity management (PIM). While identifying overprivileged identities is a key objective within identity governance, "Identity governance" itself is not a specific report or feature that directly performs the analytical task of comparing granted permissions to usage to pinpoint overprivilege. Instead, it's an overarching framework that utilizes tools like Permissions Management.
- ✗
Activity trail
Why it's wrong here
An activity trail, often referring to activity logs or resource logs, provides a record of operations performed on Azure resources by users, applications, or services. These logs detail what happened (e.g., a virtual machine was started, a storage account was accessed) and who initiated it. However, an activity trail merely presents raw usage data; it does not automatically analyze this data in conjunction with an identity's granted permissions to determine if those permissions are excessive or unused, which is necessary for identifying overprivileged access.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.