Microsoft Security, Compliance, and Identity Fundamentals Identity Protection and Governance Flashcards
7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Microsoft Security, Compliance, and Identity Fundamentals Identity Protection and Governance flashcards as text
Which Azure AD feature automatically blocks or challenges sign-ins that are flagged as risky based on machine learning analysis?
Answer: Azure AD Identity Protection risk-based Conditional Access
Azure AD Identity Protection integrates with Conditional Access to automatically enforce policies (block, MFA, or password reset) when sign-in or user risk levels exceed configured thresholds.
What is the purpose of Privileged Identity Management (PIM) 'justification' when activating a role?
Answer: It records the business reason for the temporary role activation for audit purposes
PIM requires users to provide a justification (business reason) when activating a privileged role, creating an auditable record of why elevated access was needed.
An organization wants to ensure users periodically confirm they still need access to a sensitive SharePoint site. Which Azure AD feature should they use?
Answer: Access Reviews
Azure AD Access Reviews allow administrators to schedule periodic reviews where resource owners or users themselves certify ongoing need for access, and automatically remove access if not confirmed.
Which identity governance feature in Azure AD allows organizations to define packages of access to multiple resources that users can request?
Answer: Entitlement Management
Entitlement Management lets administrators bundle access to groups, apps, and SharePoint sites into 'access packages' that users can self-request through an approval workflow.
What does a 'sign-in risk' level of 'High' in Azure AD Identity Protection indicate?
Answer: Microsoft's ML models are highly confident the sign-in is not from the legitimate account owner
A High sign-in risk means Identity Protection's machine learning has high confidence that the authentication attempt is fraudulent or compromised, such as impossible travel or known malicious IP.
In Azure AD, what is a 'guest user' account primarily used for?
Answer: Providing external partners or vendors with limited access to organizational resources via Azure AD B2B
Guest user accounts (Azure AD B2B) allow external users to authenticate with their own identity provider and access specific resources in your organization without being full members of your directory.
Which report in Azure AD Identity Protection shows users whose credentials may have been compromised based on leaked credential databases?
Answer: Users flagged for risk
The 'Users flagged for risk' report in Identity Protection lists accounts where Microsoft detected user-level risk, including leaked credentials found in breach databases.