SC-300 Azure AD Identity Protection 1 — Questions and Answers
Question 1: Which Identity Protection policy automatically blocks or requires MFA for sign-ins that are detected as medium or high risk?
- User risk policy
- Sign-in risk policy (Correct answer)
- MFA registration policy
- Conditional Access policy
Correct answer: Sign-in risk policy
The sign-in risk policy in Identity Protection evaluates the risk level of each authentication request and can block access or require MFA based on the configured risk threshold.
Question 2: Which risk detection type in Azure AD Identity Protection flags sign-ins from IP addresses associated with anonymous proxies or Tor networks?
- Atypical travel
- Anonymous IP address (Correct answer)
- Leaked credentials
- Malware linked IP address
Correct answer: Anonymous IP address
The 'Anonymous IP address' risk detection identifies sign-ins originating from IP addresses used by anonymizing services such as Tor browsers and anonymous VPN providers.
Question 3: A user's account is flagged with a high user risk in Azure AD Identity Protection. Which remediation action can the user self-perform to resolve the risk?
- Disable their own account
- Perform a secure password change via SSPR (Correct answer)
- Delete their MFA registration
- Contact Microsoft Support directly
Correct answer: Perform a secure password change via SSPR
Users with high user risk can self-remediate by performing a secure password reset through SSPR, which signals to Identity Protection that the compromised credential has been changed.
Question 4: What minimum license is required to access Azure AD Identity Protection risk reports and configure risk policies?
- Azure AD Free
- Azure AD Premium P1
- Azure AD Premium P2 (Correct answer)
- Microsoft 365 Business Standard
Correct answer: Azure AD Premium P2
Azure AD Identity Protection features, including risk policies and detailed risk detection reports, require an Azure AD Premium P2 license.
Question 5: Which Identity Protection policy is used to enforce MFA registration for users who have not yet registered their authentication methods?
- Sign-in risk policy
- User risk policy
- MFA registration policy (Correct answer)
- Conditional Access registration policy
Correct answer: MFA registration policy
The MFA registration policy in Identity Protection targets users who have not registered for MFA and prompts them to complete registration during their next sign-in.
Question 6: An administrator wants to dismiss all active risk detections for a specific user who was confirmed safe after investigation. Which action should they take in Identity Protection?
- Delete the user and recreate the account
- Confirm the user as compromised
- Dismiss user risk (Correct answer)
- Disable the sign-in risk policy
Correct answer: Dismiss user risk
The 'Dismiss user risk' action in Identity Protection clears all active risk detections associated with a user, resetting their risk level to none after an investigation confirms they are safe.
Which Identity Protection policy automatically blocks or requires MFA for sign-ins that are detected as medium or high risk?