Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft SC-900 Exam - Topic 2 Question 80 Discussion

Which three tasks can be performed by using Azure Active Directory (Azure AD) Identity Protection? Each correct answer presents a complete solution.NOTE: Each correct selection is worth one point.
B) Export risk detection to third-party utilities. and C) Automate the detection and remediation of identity based-risks. and D) Investigate risks that relate to user authentication.
A) Configure external access for partner organizations.
E) Create and automatically assign sensitivity labels to data.

Microsoft SC-900 Exam - Topic 2 Question 80 Discussion

Actual exam question for Microsoft's SC-900 exam
Question #: 80
Topic #: 2
[All SC-900 Questions]

Which three tasks can be performed by using Azure Active Directory (Azure AD) Identity Protection? Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point.

Show Suggested Answer Hide Answer
Suggested Answer: B, C, D

Microsoft Entra ID Identity Protection is a risk-based conditional access capability that ''automates the detection and remediation of identity-based risks'' and enables admins to investigate risky users and sign-ins. SCI guidance explains that Identity Protection evaluates signals such as user risk and sign-in risk, raises risk detections, and can automatically remediate by enforcing actions like password reset or blocking access via risk-based policies. The portal provides rich investigation experiences for risky users, risky sign-ins, and risk detections, allowing security teams to review evidence and confirm/dismiss risks. In addition, identity risk data can be exported through Azure Monitor/diagnostic settings and integrated with SIEM/SOAR tools, enabling ''export of risk detections and security alerts to third-party solutions'' for correlation and response. Tasks such as configuring external access for partner organizations are handled by B2B collaboration features, and creating/assigning sensitivity labels belongs to Microsoft Purview Information Protection---not Identity Protection. Therefore, the tasks Identity Protection supports are: export risk detection (B), automate detection and remediation of identity-based risks (C), and investigate risks related to user authentication (D).


Contribute your Thoughts:

0/2000 characters
Gwenn
25 days ago
Wait, can you really export risk detection? Sounds odd.
upvoted 0 times
...
Silvana
1 month ago
A is not a task for Azure AD Identity Protection.
upvoted 0 times
...
Chun
1 month ago
C and D are definitely correct!
upvoted 0 times
...
Bobbie
1 month ago
I’m not sure about E, seems off for this context.
upvoted 0 times
...
Meaghan
2 months ago
A is not related to Azure AD Identity Protection.
upvoted 0 times
...
Horace
2 months ago
Wait, can you really automate remediation? That's impressive!
upvoted 0 times
...
Santos
2 months ago
I think B is also a valid option.
upvoted 0 times
...
Jacinta
2 months ago
C and D are definitely correct!
upvoted 0 times
...
Franchesca
2 months ago
I think options A and E are related to other Azure services, not specifically Identity Protection, but I'm a bit confused about that.
upvoted 0 times
...
Desmond
2 months ago
I feel like option B could be a trick question. I don't recall Azure AD Identity Protection exporting to third-party tools.
upvoted 0 times
...
Ronny
3 months ago
I'm not entirely sure about option D, but I remember something about investigating user authentication risks in Azure AD.
upvoted 0 times
...
Ciara
3 months ago
I think option C is definitely one of the tasks, as we practiced automating risk detection in our labs.
upvoted 0 times
...

Save Cancel