Courseiva
Describe the capabilities of Microsoft EntrahardMultiple ChoiceObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

Your organization uses Microsoft Entra ID and Microsoft Sentinel. You need to analyze sign-in logs to detect risky sign-ins that are not blocked by Conditional Access policies. Which Microsoft Entra feature provides risk detection and can feed into Sentinel?

⚠ Common exam trap

Many exam-takers confuse Privileged Identity Management (PIM) with Identity Protection because both involve 'protection' and security, but PIM focuses on privileged role access, not sign-in risk detection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Entra Identity Protection

Microsoft Entra Identity Protection is the correct feature because it specifically provides risk detection for sign-ins and users, including leaked credentials, anonymous IP addresses, and atypical travel. It can feed these risk detections directly into Microsoft Sentinel via a connector, enabling advanced analysis and automated response. Conditional Access policies can use Identity Protection's risk signals to block or require MFA, but Identity Protection itself identifies the risky sign-ins that policies may not block.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Entra Verified ID

    Why it's wrong here

    Microsoft Entra Verified ID enables organizations to issue, hold, and verify digital verifiable credentials based on open standards. It allows individuals to prove aspects of their identity (e.g., employment, education) in a privacy-preserving manner without sharing underlying personal data directly. While it enhances trust in identity verification, its core function is not to proactively detect risky sign-ins or user behavior within an organization's Microsoft Entra ID tenant, which is the requirement for integration with Microsoft Sentinel for security monitoring.

  • Microsoft Entra Identity Protection

    Why this is correct

    Microsoft Entra Identity Protection is a crucial security capability that automatically detects, remediates, and investigates identity-based risks in an organization. It identifies potential vulnerabilities affecting identities, such as leaked credentials, and detects suspicious actions like anomalous sign-in locations or impossible travel. These risk detections are fed directly into Microsoft Sentinel as incidents, enabling security analysts to correlate identity risk data with other security logs for comprehensive threat detection and response.

  • Microsoft Entra Privileged Identity Management

    Why it's wrong here

    Microsoft Entra Privileged Identity Management (PIM) is designed to manage, control, and monitor access to important resources within an organization. It provides just-in-time (JIT) privileged access to Microsoft Entra ID and Azure resources, requiring users to activate roles for a limited time. While PIM significantly reduces the attack surface by minimizing standing access, its primary function is access governance and auditing of privileged roles, not the real-time detection of risky user sign-ins or compromised accounts.

  • Microsoft Entra Entitlement Management

    Why it's wrong here

    Microsoft Entra Entitlement Management is an identity governance feature that enables organizations to manage identity and access lifecycle at scale. It allows for the creation of access packages that bundle resources and define policies for requesting and approving access. This service streamlines access requests, reviews, and expiration for internal and external users, ensuring appropriate access to resources. However, its purpose is access provisioning and governance, not the continuous monitoring and detection of risky user behavior or sign-in anomalies.

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.