Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft SC-900 Exam - Topic 2 Question 80 Discussion

Actual exam question for Microsoft's SC-900 exam
Question #: 80
Topic #: 2
[All SC-900 Questions]

Which three tasks can be performed by using Azure Active Directory (Azure AD) Identity Protection? Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point.

Show Suggested Answer Hide Answer
Suggested Answer: B, C, D

Microsoft Entra ID Identity Protection is a risk-based conditional access capability that ''automates the detection and remediation of identity-based risks'' and enables admins to investigate risky users and sign-ins. SCI guidance explains that Identity Protection evaluates signals such as user risk and sign-in risk, raises risk detections, and can automatically remediate by enforcing actions like password reset or blocking access via risk-based policies. The portal provides rich investigation experiences for risky users, risky sign-ins, and risk detections, allowing security teams to review evidence and confirm/dismiss risks. In addition, identity risk data can be exported through Azure Monitor/diagnostic settings and integrated with SIEM/SOAR tools, enabling ''export of risk detections and security alerts to third-party solutions'' for correlation and response. Tasks such as configuring external access for partner organizations are handled by B2B collaboration features, and creating/assigning sensitivity labels belongs to Microsoft Purview Information Protection---not Identity Protection. Therefore, the tasks Identity Protection supports are: export risk detection (B), automate detection and remediation of identity-based risks (C), and investigate risks related to user authentication (D).


Contribute your Thoughts:

0/2000 characters
Meaghan
4 hours ago
A is not related to Azure AD Identity Protection.
upvoted 0 times
...
Horace
5 days ago
Wait, can you really automate remediation? That's impressive!
upvoted 0 times
...
Santos
10 days ago
I think B is also a valid option.
upvoted 0 times
...
Jacinta
16 days ago
C and D are definitely correct!
upvoted 0 times
...
Franchesca
21 days ago
I think options A and E are related to other Azure services, not specifically Identity Protection, but I'm a bit confused about that.
upvoted 0 times
...
Desmond
26 days ago
I feel like option B could be a trick question. I don't recall Azure AD Identity Protection exporting to third-party tools.
upvoted 0 times
...
Ronny
1 month ago
I'm not entirely sure about option D, but I remember something about investigating user authentication risks in Azure AD.
upvoted 0 times
...
Ciara
1 month ago
I think option C is definitely one of the tasks, as we practiced automating risk detection in our labs.
upvoted 0 times
...

Save Cancel