SC-900 Microsoft Security, Compliance, and Identity Fundamentals Identity Protection and Governance 2 — Questions and Answers
Question 1: Which Azure AD feature automatically blocks or challenges sign-ins that are flagged as risky based on machine learning analysis?
- Azure AD Identity Protection risk-based Conditional Access (Correct answer)
- Azure AD Privileged Identity Management
- Microsoft Defender for Identity
- Azure AD Access Reviews
Correct answer: Azure AD Identity Protection risk-based Conditional Access
Azure AD Identity Protection integrates with Conditional Access to automatically enforce policies (block, MFA, or password reset) when sign-in or user risk levels exceed configured thresholds.
Question 2: What is the purpose of Privileged Identity Management (PIM) 'justification' when activating a role?
- It records the business reason for the temporary role activation for audit purposes (Correct answer)
- It automatically approves the role without manager review
- It permanently assigns the role to the user
- It disables MFA for the duration of the privileged session
Correct answer: It records the business reason for the temporary role activation for audit purposes
PIM requires users to provide a justification (business reason) when activating a privileged role, creating an auditable record of why elevated access was needed.
Question 3: An organization wants to ensure users periodically confirm they still need access to a sensitive SharePoint site. Which Azure AD feature should they use?
- Access Reviews (Correct answer)
- Entitlement Management
- Conditional Access
- Identity Protection
Correct answer: Access Reviews
Azure AD Access Reviews allow administrators to schedule periodic reviews where resource owners or users themselves certify ongoing need for access, and automatically remove access if not confirmed.
Question 4: Which identity governance feature in Azure AD allows organizations to define packages of access to multiple resources that users can request?
- Entitlement Management (Correct answer)
- Privileged Identity Management
- Access Reviews
- Identity Protection
Correct answer: Entitlement Management
Entitlement Management lets administrators bundle access to groups, apps, and SharePoint sites into 'access packages' that users can self-request through an approval workflow.
Question 5: What does a 'sign-in risk' level of 'High' in Azure AD Identity Protection indicate?
- Microsoft's ML models are highly confident the sign-in is not from the legitimate account owner (Correct answer)
- The user has too many assigned roles
- The account password has expired
- The device used to sign in is not compliant
Correct answer: Microsoft's ML models are highly confident the sign-in is not from the legitimate account owner
A High sign-in risk means Identity Protection's machine learning has high confidence that the authentication attempt is fraudulent or compromised, such as impossible travel or known malicious IP.
Question 6: In Azure AD, what is a 'guest user' account primarily used for?
- Providing external partners or vendors with limited access to organizational resources via Azure AD B2B (Correct answer)
- Granting full administrative access to external consultants
- Creating temporary accounts for new employees during onboarding
- Allowing anonymous access to public-facing applications
Correct answer: Providing external partners or vendors with limited access to organizational resources via Azure AD B2B
Guest user accounts (Azure AD B2B) allow external users to authenticate with their own identity provider and access specific resources in your organization without being full members of your directory.
Question 7: Which report in Azure AD Identity Protection shows users whose credentials may have been compromised based on leaked credential databases?
- Users flagged for risk (Correct answer)
- Risky sign-ins
- Audit logs
- Sign-in logs
Correct answer: Users flagged for risk
The 'Users flagged for risk' report in Identity Protection lists accounts where Microsoft detected user-level risk, including leaked credentials found in breach databases.
Which Azure AD feature automatically blocks or challenges sign-ins that are flagged as risky based on machine learning analysis?