← All SC-900 Flashcard Decks

Microsoft Security, Compliance, and Identity Fundamentals Identity Protection and Governance Flashcards

7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Microsoft Security, Compliance, and Identity Fundamentals Identity Protection and Governance flashcards as text
  1. What is the difference between 'eligible' and 'active' role assignments in Azure AD Privileged Identity Management?

    Answer: Eligible means the user can activate the role when needed; active means the role is always on

    In PIM, eligible assignments grant the right to activate a privileged role on demand (just-in-time), while active assignments mean the user continuously holds the role without needing to activate it.

  2. Which Azure AD Identity Protection detection identifies when a user signs in from two geographically distant locations within an impossible travel timeframe?

    Answer: Impossible travel

    The 'Impossible travel' risk detection flags sign-ins from two locations that could not be reached within the time between the two sign-ins, indicating credential compromise.

  3. What is the primary benefit of using Azure AD External Identities (B2B) over creating separate local accounts for partners?

    Answer: Partners authenticate with their own organizational credentials, reducing password management overhead for both parties

    B2B allows external partners to use their existing identity (work, school, or social account), so your organization doesn't need to create and manage separate credentials for them.

  4. An administrator wants to require approval before a user can activate the Security Administrator role in PIM. Where is this configured?

    Answer: In the PIM role settings for Security Administrator

    PIM role settings allow administrators to require approvers, set activation duration, mandate MFA, and require justification — all configured per role in the PIM blade.

  5. What happens to a user's access when an Access Review concludes and the reviewer chose 'auto-apply results'?

    Answer: Users whose access was denied by reviewers automatically have that access removed

    When auto-apply is enabled, Access Reviews automatically remove access for users whose access was denied or not reviewed, enforcing the principle of least privilege without manual admin intervention.

  6. Which Azure AD governance feature helps organizations manage the entire lifecycle of user access — from request through approval, assignment, and eventual expiration?

    Answer: Entitlement Management

    Entitlement Management handles the full identity governance lifecycle: users request access packages, approvers grant them, access is time-limited, and expiration triggers removal or renewal.

  7. What is 'user risk' in Azure AD Identity Protection, as distinct from 'sign-in risk'?

    Answer: User risk is a persistent probability that an account is compromised, based on detected anomalies over time

    User risk reflects the overall probability that a user's identity is compromised based on cumulative detections (like leaked credentials or suspicious activity patterns), whereas sign-in risk evaluates a single authentication event.