Courseiva

SC-900 Describe the capabilities of Microsoft Entra Practice Question

Your organization uses Microsoft Entra ID Governance. You need to ensure that guest users' access to internal applications is automatically removed after 90 days. What should you configure?

⚠ Common exam trap

The trap here is that candidates might consider Access Reviews for managing guest access, but Access Reviews are primarily for certifying existing access and removing it based on review decisions or lack thereof, not for automatically enforcing a fixed access duration from the point of initial access. Entitlement Management's access package expiration is designed for this specific time-based access lifecycle management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Entitlement management

Microsoft Entra ID Governance's Entitlement Management allows you to define access packages with specific policies, including an expiration date for assignments. By configuring an access package to grant access to the internal applications and setting its assignment policy to expire after 90 days, guest users' access will be automatically revoked at the end of that period. This directly fulfills the requirement for time-based automatic removal after 90 days.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Entitlement management

    Why this is correct

    Entitlement management primarily focuses on streamlining the request and approval process for access to resources through access packages. While access packages can be configured with an expiration date, this feature sets a fixed end date for access rather than facilitating a periodic review of ongoing need. It does not provide the mechanism for reviewers to attest to continued access and then automatically remove it if justification is lacking or the review is ignored.

  • ✗

    Access reviews

    Why it's wrong here

    Access reviews are specifically designed to manage the lifecycle of access by enabling periodic re-certification of user permissions to groups, applications, and resources. They can be configured to automatically remove access for users, including guests, if reviewers deny access, do not respond to the review, or if the access is no longer deemed necessary. This capability directly addresses the requirement for automatic access removal after a specified period based on a governance review.

  • ✗

    Identity Protection

    Why it's wrong here

    Microsoft Entra ID Protection is a security feature focused on detecting, investigating, and remediating identity-based risks, such as suspicious sign-ins or leaked credentials. It uses machine learning and heuristics to identify vulnerabilities and enforce protective policies like requiring multi-factor authentication or password resets. Its purpose is to safeguard identities from compromise, not to govern or automatically remove access based on a periodic review of access rights.

  • ✗

    Privileged Identity Management (PIM)

    Why it's wrong here

    Privileged Identity Management (PIM) is a governance tool that manages, controls, and monitors access to important resources within Microsoft Entra ID, Azure, and other Microsoft Online Services. It focuses on providing just-in-time (JIT) and time-bound access to privileged roles and resources, minimizing the attack surface by ensuring elevated permissions are granted only when needed. PIM's scope is specifically for privileged access lifecycle, not general guest access lifecycle management or periodic reviews for non-privileged access.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.