MS-100 Risk Assessment & Management 2 — Questions and Answers
Question 1: A security administrator needs to identify users whose credentials may have been leaked on the dark web. Which Microsoft 365 feature detects this risk?
- Azure AD Password Protection
- Identity Protection leaked credentials detection (Correct answer)
- Microsoft Secure Score
- Privileged Identity Management
Correct answer: Identity Protection leaked credentials detection
Azure AD Identity Protection automatically detects leaked credentials by comparing user credentials against known breached credential lists.
Question 2: An organization wants to require additional verification when a sign-in risk level is 'High'. Which Identity Protection policy type should be configured?
- User risk policy
- Sign-in risk policy (Correct answer)
- MFA registration policy
- Conditional Access named location policy
Correct answer: Sign-in risk policy
A sign-in risk policy in Identity Protection evaluates real-time risk signals during authentication and can enforce MFA or block access based on the detected risk level.
Question 3: After remediating a compromised account, what action should an admin take in Identity Protection to reset the user's risk state?
- Delete and recreate the user account
- Dismiss the user risk (Correct answer)
- Revoke all refresh tokens only
- Reset the user's MFA methods
Correct answer: Dismiss the user risk
Dismissing the user risk in Identity Protection manually resets the risk state after an admin has confirmed the account is secure.
Question 4: Which risk detection in Azure AD Identity Protection indicates that a user signed in from an IP address associated with anonymous proxy services?
- Unfamiliar sign-in properties
- Anonymous IP address (Correct answer)
- Atypical travel
- Malware-linked IP address
Correct answer: Anonymous IP address
The 'Anonymous IP address' risk detection fires when a sign-in originates from a known anonymizing service like Tor or VPNs used to mask identity.
Question 5: A Conditional Access policy is set to require MFA when sign-in risk is Medium or above. A user with a High risk sign-in successfully passes MFA. What is the resulting risk state?
- Risk is automatically dismissed after MFA success
- Risk remains High until manually dismissed or self-remediated (Correct answer)
- Risk is downgraded to Low
- Risk is removed by the Conditional Access engine
Correct answer: Risk remains High until manually dismissed or self-remediated
Completing MFA satisfies the Conditional Access grant control but does not automatically lower or dismiss the Identity Protection risk level; the risk state persists until remediated.
Question 6: An administrator reviews the Microsoft Secure Score dashboard and notices an improvement action to 'Enable Identity Protection sign-in risk policies'. What does implementing this action primarily mitigate?
- Data exfiltration via email
- Unauthorized access from risky authentication events (Correct answer)
- Malware on managed endpoints
- Excessive admin role assignments
Correct answer: Unauthorized access from risky authentication events
Sign-in risk policies in Identity Protection mitigate unauthorized access by enforcing controls like MFA or blocking when suspicious sign-in behavior is detected.
Question 7: Which report in the Azure AD portal lists all sign-ins that were flagged as risky and the specific detections that triggered the flag?
- Sign-in logs
- Risky sign-ins report (Correct answer)
- Audit logs
- Provisioning logs
Correct answer: Risky sign-ins report
The Risky sign-ins report in Identity Protection consolidates sign-ins with associated risk detections, showing the risk level and detection types that triggered each event.
A security administrator needs to identify users whose credentials may have been leaked on the dark web.
Which Microsoft 365 feature detects this risk?