Microsoft SC-300 Identity Protection and Risk Remediation Practice Test

 

Topic 07 covers identity protection and risk remediation for the Microsoft Certified: Identity and Access Administrator Associate certification. These original practice questions apply the verified SC-300 objectives to practical decisions and troubleshooting. Select one answer unless a fixed number is requested. For broader preparation, visit the SC-300 Exam Dumps page. Each option includes an explanation of the relevant behavior and scenario constraints.

Question 1

The security review of a high-risk sign-in from an unfamiliar source focuses on one acceptance criterion: a clear distinction between accumulated user risk and individual sign-in risk. The current population and assignment scope must be preserved. Which action best satisfies the requirement?

  1. Use risk detections, risky-user or risky-sign-in records, and remediation state to diagnose campaign prompt suppression or unsupported method.
  2. Treat user risk as the identity’s accumulated compromise likelihood and sign-in risk as the risk of the individual authentication event.
  3. Use risk detections, risky-user or risky-sign-in records, and remediation state to distinguish detection timing from immediate enforcement.
  4. Move the legacy sign-in-risk configuration to Conditional Access before the documented retirement date, validating the new policy in report-only mode first.
  5. Exclude emergency identities while preserving monitored response narrowly while preserving monitoring and the intended control for all other identities.

Correct Answer: B

 

Correct Answer

Answer B is correct because This action directly provides a clear distinction between accumulated user risk and individual sign-in risk. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is diagnosis of campaign prompt suppression or unsupported method. The scenario instead requires a clear distinction between accumulated user risk and individual sign-in risk, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is a clear distinction between detection timing and immediate enforcement. The scenario instead requires a clear distinction between accumulated user risk and individual sign-in risk, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is a controlled migration of legacy sign-in-risk policy with date explicit. The scenario instead requires a clear distinction between accumulated user risk and individual sign-in risk, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is exclude emergency identities while preserving monitored response. The scenario instead requires a clear distinction between accumulated user risk and individual sign-in risk, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 2

The team is validating an identity-risk investigation. The decisive requirement is: the required setting for user-risk remediation for registered MFA users. Existing working access outside the stated scope must remain unchanged. Which action best satisfies the requirement?

  1. Correlate risky sign-in with user investigation evidence using risk detections, risky-user or risky-sign-in records, and remediation state before deciding on remediation.
  2. Evaluate passwordless sign-in-risk control compatibility using risk detections, risky-user or risky-sign-in records, and remediation state before changing production configuration.
  3. Use a user-risk Conditional Access/ID Protection remediation that requires secure password change when supported and appropriate.
  4. Prioritize risky user using evidence rather than risk label alone according to the risk and impact shown by risk detections, risky-user or risky-sign-in records, and remediation state.
  5. Choose sign-in-risk threshold for stated exposure in Microsoft Entra ID Protection and verify the resulting behavior.

Correct Answer: C

 

Correct Answer

Answer C is correct because This action directly provides the required setting for user-risk remediation for registered MFA users. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is correlate risky sign-in with user investigation evidence. The scenario instead requires the required setting for user-risk remediation for registered MFA users, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is evaluation of passwordless sign-in-risk control compatibility. The scenario instead requires the required setting for user-risk remediation for registered MFA users, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is prioritization of risky user using evidence rather than risk label alone. The scenario instead requires the required setting for user-risk remediation for registered MFA users, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is the appropriate sign-in-risk threshold for stated exposure. The scenario instead requires the required setting for user-risk remediation for registered MFA users, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 3

Operations staff investigating an identity-risk investigation have isolated the issue to: handling of high-risk user unable to self-remediate. The change will be piloted before broader enforcement. Which action best satisfies the requirement?

  1. Investigate the high-risk user, confirm compromise status, and perform administrator remediation when self-remediation is not possible.
  2. Require appropriate remediation for risky authentication through the relevant Microsoft Entra ID Protection control.
  3. Configure an authentication-method registration campaign for the intended unregistered population and monitor completion.
  4. Use the risky-user investigation workflow to confirm compromise, preserve evidence, and then remediate or dismiss the risk appropriately.
  5. Interpret service-principal risk detection context using risk detections, risky-user or risky-sign-in records, and remediation state rather than inferring it from configuration alone.

Correct Answer: A

 

Correct Answer

Answer A is correct because This action directly provides handling of high-risk user unable to self-remediate. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer B is incorrect because This action is appropriate when the requirement is enforcement of appropriate remediation for risky authentication. The scenario instead requires handling of high-risk user unable to self-remediate, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is the appropriate registration campaign for target authentication method. The scenario instead requires handling of high-risk user unable to self-remediate, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is the appropriate confirm compromised versus dismiss risk. The scenario instead requires handling of high-risk user unable to self-remediate, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is correct interpretation of service-principal risk detection context. The scenario instead requires handling of high-risk user unable to self-remediate, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 4

The administrator must correct an identity-risk investigation without changing adjacent controls. The target condition is: evaluation of passwordless user-risk remediation requirements. The tenant has the licensing required for the named capability. Which action best satisfies the requirement?

  1. Select secure password reset or administrative containment in Microsoft Entra ID Protection and verify the resulting behavior.
  2. Choose workload containment without user mfa assumption in Microsoft Entra ID Protection and verify the resulting behavior.
  3. For a passwordless user-risk design, verify that the required remediation path is actually available to the user; do not assume a password-change workflow fits every passwordless account.
  4. Use a sign-in-risk policy/Conditional Access control that requires the configured remediation for risky authentication events.
  5. Use risk detections, risky-user or risky-sign-in records, and remediation state to distinguish registration eligibility from mfa enforcement.

Correct Answer: C

 

Correct Answer

Answer C is correct because This option directly tests evaluate passwordless user-risk remediation requirements at the control boundary named in the scenario. It addresses that specific stage or distinction rather than collapsing it into a neighboring workflow step.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is the appropriate secure password reset or administrative containment. The scenario instead requires evaluation of passwordless user-risk remediation requirements, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is the appropriate workload containment without user MFA assumption. The scenario instead requires evaluation of passwordless user-risk remediation requirements, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is a clear distinction between transient sign-in risk and compromised account. The scenario instead requires evaluation of passwordless user-risk remediation requirements, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is a clear distinction between registration eligibility and MFA enforcement. The scenario instead requires evaluation of passwordless user-risk remediation requirements, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 5

An audit of a tenant migrating legacy risk policies before retirement identifies this control gap: a controlled migration of legacy user-risk policy before dated retirement. The correction must address the named control boundary rather than reset unrelated tenant settings. Which action best satisfies the requirement?

  1. Use risk detections, risky-user or risky-sign-in records, and remediation state to diagnose block caused by missing remediation prerequisites.
  2. Resolve investigation when risk persists after remediation in Microsoft Entra ID Protection without broadening unrelated access.
  3. Move the legacy user-risk configuration to Conditional Access before the documented retirement date, preserving equivalent scope and remediation.
  4. Target the registration campaign to users who have not registered the required method while excluding the documented exception cohort.
  5. Revoke or replace exposed application credential through Microsoft Entra ID Protection and verify whether any separate application session remains.

Correct Answer: C

 

Correct Answer

Answer C is correct because This action directly provides a controlled migration of legacy user-risk policy before dated retirement. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is diagnosis of block caused by missing remediation prerequisites. The scenario instead requires a controlled migration of legacy user-risk policy before dated retirement, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is resolution of investigation when risk persists after remediation. The scenario instead requires a controlled migration of legacy user-risk policy before dated retirement, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is targeting of unregistered users without disrupting excluded cohort. The scenario instead requires a controlled migration of legacy user-risk policy before dated retirement, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is revocation of or replace exposed application credential. The scenario instead requires a controlled migration of legacy user-risk policy before dated retirement, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 6

The documented success criterion for an identity-risk investigation is: exclude emergency identities while preserving monitored response. No new standing administrator privilege may be introduced. Choose TWO actions that together implement and verify the requirement.

  1. Scope risk policy to supported workload identity to the intended population in Microsoft Entra ID Protection.
  2. Exclude emergency identities while preserving monitored response narrowly while preserving monitoring and the intended control for all other identities.
  3. Review the relevant risk detection, risk state, and remediation result in Microsoft Entra ID Protection.
  4. Use risk detections, risky-user or risky-sign-in records, and remediation state to distinguish detection timing from immediate enforcement.
  5. Move the legacy sign-in-risk configuration to Conditional Access before the documented retirement date, validating the new policy in report-only mode first.
  6. Use risk detections, risky-user or risky-sign-in records, and remediation state to diagnose campaign prompt suppression or unsupported method.

Correct Answers: B, C

 

Correct Answers

Answer B is correct because This action directly provides exclude emergency identities while preserving monitored response at the correct Microsoft Entra control boundary.

Answer C is correct because This verification step confirms that the selected control changes effective behavior for the intended pilot and exposes policy, assignment, propagation, or evidence problems before wider rollout.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is scoping of risk policy to supported workload identity. It does not implement or verify exclude emergency identities while preserving monitored response in this scenario.

Answer D is incorrect because This action is appropriate when the requirement is a clear distinction between detection timing and immediate enforcement. It does not implement or verify exclude emergency identities while preserving monitored response in this scenario.

Answer E is incorrect because This action is appropriate when the requirement is a controlled migration of legacy sign-in-risk policy with date explicit. It does not implement or verify exclude emergency identities while preserving monitored response in this scenario.

Answer F is incorrect because This action is appropriate when the requirement is diagnosis of campaign prompt suppression or unsupported method. It does not implement or verify exclude emergency identities while preserving monitored response in this scenario.

 

Question 7

The current configuration of an identity-risk investigation is otherwise acceptable. The unresolved requirement is: the appropriate sign-in-risk threshold for stated exposure. General network connectivity outside the identity path is already verified. Which action best satisfies the requirement?

  1. Use risk detections, risky-user or risky-sign-in records, and remediation state to diagnose workload remediation versus managed-identity eligibility.
  2. Evaluate passwordless sign-in-risk control compatibility using risk detections, risky-user or risky-sign-in records, and remediation state before changing production configuration.
  3. Correlate risky sign-in with user investigation evidence using risk detections, risky-user or risky-sign-in records, and remediation state before deciding on remediation.
  4. Choose sign-in-risk threshold for stated exposure in Microsoft Entra ID Protection and verify the resulting behavior.
  5. Prioritize risky user using evidence rather than risk label alone according to the risk and impact shown by risk detections, risky-user or risky-sign-in records, and remediation state.

Correct Answer: D

 

Correct Answer

Answer D is correct because This action directly provides the appropriate sign-in-risk threshold for stated exposure. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is diagnosis of workload remediation versus managed-identity eligibility. The scenario instead requires the appropriate sign-in-risk threshold for stated exposure, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is evaluation of passwordless sign-in-risk control compatibility. The scenario instead requires the appropriate sign-in-risk threshold for stated exposure, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is correlate risky sign-in with user investigation evidence. The scenario instead requires the appropriate sign-in-risk threshold for stated exposure, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is prioritization of risky user using evidence rather than risk label alone. The scenario instead requires the appropriate sign-in-risk threshold for stated exposure, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 8

A troubleshooting review of an identity-risk investigation confirms that the next action must address: enforcement of appropriate remediation for risky authentication. Resource permissions outside the identity control are already correct. Which action best satisfies the requirement?

  1. Use the risky-user investigation workflow to confirm compromise, preserve evidence, and then remediate or dismiss the risk appropriately.
  2. Require appropriate remediation for risky authentication through the relevant Microsoft Entra ID Protection control.
  3. Reassess workload risk after verified response using risk detections, risky-user or risky-sign-in records, and remediation state after the verified remediation.
  4. Configure an authentication-method registration campaign for the intended unregistered population and monitor completion.
  5. Interpret service-principal risk detection context using risk detections, risky-user or risky-sign-in records, and remediation state rather than inferring it from configuration alone.

Correct Answer: B

 

Correct Answer

Answer B is correct because This action directly provides enforcement of appropriate remediation for risky authentication. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is the appropriate confirm compromised versus dismiss risk. The scenario instead requires enforcement of appropriate remediation for risky authentication, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is reassess workload risk after verified response. The scenario instead requires enforcement of appropriate remediation for risky authentication, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is the appropriate registration campaign for target authentication method. The scenario instead requires enforcement of appropriate remediation for risky authentication, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is correct interpretation of service-principal risk detection context. The scenario instead requires enforcement of appropriate remediation for risky authentication, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 9

A staged rollout of a high-risk sign-in from an unfamiliar source cannot proceed until the team can demonstrate: a clear distinction between transient sign-in risk and compromised account. The administrator must verify the effective result from Microsoft Entra evidence. Which action best satisfies the requirement?

  1. Select secure password reset or administrative containment in Microsoft Entra ID Protection and verify the resulting behavior.
  2. Use a sign-in-risk policy/Conditional Access control that requires the configured remediation for risky authentication events.
  3. Use risk detections, risky-user or risky-sign-in records, and remediation state to distinguish registration eligibility from mfa enforcement.
  4. Choose workload containment without user mfa assumption in Microsoft Entra ID Protection and verify the resulting behavior.
  5. Treat user risk as the identity’s accumulated compromise likelihood and sign-in risk as the risk of the individual authentication event.

Correct Answer: B

 

Correct Answer

Answer B is correct because This action directly provides a clear distinction between transient sign-in risk and compromised account. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is the appropriate secure password reset or administrative containment. The scenario instead requires a clear distinction between transient sign-in risk and compromised account, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is a clear distinction between registration eligibility and MFA enforcement. The scenario instead requires a clear distinction between transient sign-in risk and compromised account, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is the appropriate workload containment without user MFA assumption. The scenario instead requires a clear distinction between transient sign-in risk and compromised account, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is a clear distinction between accumulated user risk and individual sign-in risk. The scenario instead requires a clear distinction between transient sign-in risk and compromised account, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 10

The team compares supported controls for an identity-risk investigation. The deciding condition is: diagnosis of block caused by missing remediation prerequisites. The organization requires a supported Microsoft-managed control. Which action best satisfies the requirement?

  1. Resolve investigation when risk persists after remediation in Microsoft Entra ID Protection without broadening unrelated access.
  2. Target the registration campaign to users who have not registered the required method while excluding the documented exception cohort.
  3. Use a user-risk Conditional Access/ID Protection remediation that requires secure password change when supported and appropriate.
  4. Revoke or replace exposed application credential through Microsoft Entra ID Protection and verify whether any separate application session remains.
  5. Use risk detections, risky-user or risky-sign-in records, and remediation state to diagnose block caused by missing remediation prerequisites.

Correct Answer: E

 

Correct Answer

Answer E is correct because This action directly provides diagnosis of block caused by missing remediation prerequisites. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is resolution of investigation when risk persists after remediation. The scenario instead requires diagnosis of block caused by missing remediation prerequisites, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is targeting of unregistered users without disrupting excluded cohort. The scenario instead requires diagnosis of block caused by missing remediation prerequisites, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is the required setting for user-risk remediation for registered MFA users. The scenario instead requires diagnosis of block caused by missing remediation prerequisites, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is revocation of or replace exposed application credential. The scenario instead requires diagnosis of block caused by missing remediation prerequisites, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 11

The identity architect is reviewing a tenant migrating legacy risk policies before retirement. The required outcome is: a controlled migration of legacy sign-in-risk policy with date explicit. The current population and assignment scope must be preserved. Which action best satisfies the requirement?

  1. Move the legacy sign-in-risk configuration to Conditional Access before the documented retirement date, validating the new policy in report-only mode first.
  2. Use risk detections, risky-user or risky-sign-in records, and remediation state to diagnose campaign prompt suppression or unsupported method.
  3. Investigate the high-risk user, confirm compromise status, and perform administrator remediation when self-remediation is not possible.
  4. Scope risk policy to supported workload identity to the intended population in Microsoft Entra ID Protection.
  5. Use risk detections, risky-user or risky-sign-in records, and remediation state to distinguish detection timing from immediate enforcement.

Correct Answer: A

 

Correct Answer

Answer A is correct because This action directly provides a controlled migration of legacy sign-in-risk policy with date explicit. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer B is incorrect because This action is appropriate when the requirement is diagnosis of campaign prompt suppression or unsupported method. The scenario instead requires a controlled migration of legacy sign-in-risk policy with date explicit, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is handling of high-risk user unable to self-remediate. The scenario instead requires a controlled migration of legacy sign-in-risk policy with date explicit, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is scoping of risk policy to supported workload identity. The scenario instead requires a controlled migration of legacy sign-in-risk policy with date explicit, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is a clear distinction between detection timing and immediate enforcement. The scenario instead requires a controlled migration of legacy sign-in-risk policy with date explicit, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 12

The change owner has limited the remediation for an identity-risk investigation to this outcome: evaluation of passwordless sign-in-risk control compatibility. Existing working access outside the stated scope must remain unchanged. Choose TWO actions that together implement and verify the requirement.

  1. Review the relevant risk detection, risk state, and remediation result in Microsoft Entra ID Protection.
  2. Correlate risky sign-in with user investigation evidence using risk detections, risky-user or risky-sign-in records, and remediation state before deciding on remediation.
  3. Use a user-risk Conditional Access/ID Protection remediation that requires secure password change when supported and appropriate.
  4. Validate that the selected sign-in-risk remediation is supported for the user’s authentication state before enforcing the risk policy.
  5. Use risk detections, risky-user or risky-sign-in records, and remediation state to diagnose workload remediation versus managed-identity eligibility.
  6. Prioritize risky user using evidence rather than risk label alone according to the risk and impact shown by risk detections, risky-user or risky-sign-in records, and remediation state.

Correct Answers: A, D

 

Correct Answers

Answer A is correct because This verification step confirms that the selected control changes effective behavior for the intended pilot and exposes policy, assignment, propagation, or evidence problems before wider rollout.

Answer D is correct because This action directly resolves evaluate passwordless sign-in-risk control compatibility at the evidence or control boundary described by the scenario, rather than substituting a neighboring identity workflow.

Incorrect Answers

Answer B is incorrect because This action is appropriate when the requirement is correlate risky sign-in with user investigation evidence. It does not implement or verify evaluation of passwordless sign-in-risk control compatibility in this scenario.

Answer C is incorrect because This action is appropriate when the requirement is evaluation of passwordless user-risk remediation requirements. It does not implement or verify evaluation of passwordless sign-in-risk control compatibility in this scenario.

Answer E is incorrect because This action is appropriate when the requirement is diagnosis of workload remediation versus managed-identity eligibility. It does not implement or verify evaluation of passwordless sign-in-risk control compatibility in this scenario.

Answer F is incorrect because This action is appropriate when the requirement is prioritization of risky user using evidence rather than risk label alone. It does not implement or verify evaluation of passwordless sign-in-risk control compatibility in this scenario.

 

Question 13

A change request for users who have not registered the required authentication method will be accepted only when the following is true: the appropriate registration campaign for target authentication method. The change will be piloted before broader enforcement. Which action best satisfies the requirement?

  1. Interpret service-principal risk detection context using risk detections, risky-user or risky-sign-in records, and remediation state rather than inferring it from configuration alone.
  2. Reassess workload risk after verified response using risk detections, risky-user or risky-sign-in records, and remediation state after the verified remediation.
  3. Configure an authentication-method registration campaign for the intended unregistered population and monitor completion.
  4. Move the legacy user-risk configuration to Conditional Access before the documented retirement date, preserving equivalent scope and remediation.
  5. Use the risky-user investigation workflow to confirm compromise, preserve evidence, and then remediate or dismiss the risk appropriately.

Correct Answer: C

 

Correct Answer

Answer C is correct because This action directly provides the appropriate registration campaign for target authentication method. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is correct interpretation of service-principal risk detection context. The scenario instead requires the appropriate registration campaign for target authentication method, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is reassess workload risk after verified response. The scenario instead requires the appropriate registration campaign for target authentication method, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is a controlled migration of legacy user-risk policy before dated retirement. The scenario instead requires the appropriate registration campaign for target authentication method, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is the appropriate confirm compromised versus dismiss risk. The scenario instead requires the appropriate registration campaign for target authentication method, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 14

The implementation of users who have not registered the required authentication method is complete except for this requirement: a clear distinction between registration eligibility and MFA enforcement. The tenant has the licensing required for the named capability. Which action best satisfies the requirement?

  1. Use risk detections, risky-user or risky-sign-in records, and remediation state to distinguish registration eligibility from mfa enforcement.
  2. Treat user risk as the identity’s accumulated compromise likelihood and sign-in risk as the risk of the individual authentication event.
  3. Choose workload containment without user mfa assumption in Microsoft Entra ID Protection and verify the resulting behavior.
  4. Select secure password reset or administrative containment in Microsoft Entra ID Protection and verify the resulting behavior.
  5. Exclude emergency identities while preserving monitored response narrowly while preserving monitoring and the intended control for all other identities.

Correct Answer: A

 

Correct Answer

Answer A is correct because This action directly provides a clear distinction between registration eligibility and MFA enforcement. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer B is incorrect because This action is appropriate when the requirement is a clear distinction between accumulated user risk and individual sign-in risk. The scenario instead requires a clear distinction between registration eligibility and MFA enforcement, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is the appropriate workload containment without user MFA assumption. The scenario instead requires a clear distinction between registration eligibility and MFA enforcement, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is the appropriate secure password reset or administrative containment. The scenario instead requires a clear distinction between registration eligibility and MFA enforcement, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is exclude emergency identities while preserving monitored response. The scenario instead requires a clear distinction between registration eligibility and MFA enforcement, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 15

The support team has ruled out unrelated causes in an identity-risk investigation. The remaining issue is: targeting of unregistered users without disrupting excluded cohort. The correction must address the named control boundary rather than reset unrelated tenant settings. Which action best satisfies the requirement?

  1. Target the registration campaign to users who have not registered the required method while excluding the documented exception cohort.
  2. Revoke or replace exposed application credential through Microsoft Entra ID Protection and verify whether any separate application session remains.
  3. Choose sign-in-risk threshold for stated exposure in Microsoft Entra ID Protection and verify the resulting behavior.
  4. Resolve investigation when risk persists after remediation in Microsoft Entra ID Protection without broadening unrelated access.
  5. Use a user-risk Conditional Access/ID Protection remediation that requires secure password change when supported and appropriate.

Correct Answer: A

 

Correct Answer

Answer A is correct because This action directly provides targeting of unregistered users without disrupting excluded cohort. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer B is incorrect because This action is appropriate when the requirement is revocation of or replace exposed application credential. The scenario instead requires targeting of unregistered users without disrupting excluded cohort, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is the appropriate sign-in-risk threshold for stated exposure. The scenario instead requires targeting of unregistered users without disrupting excluded cohort, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is resolution of investigation when risk persists after remediation. The scenario instead requires targeting of unregistered users without disrupting excluded cohort, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is the required setting for user-risk remediation for registered MFA users. The scenario instead requires targeting of unregistered users without disrupting excluded cohort, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 16

A readiness check of an identity-risk investigation leaves one unresolved condition: diagnosis of campaign prompt suppression or unsupported method. No new standing administrator privilege may be introduced. Which action best satisfies the requirement?

  1. Scope risk policy to supported workload identity to the intended population in Microsoft Entra ID Protection.
  2. Use risk detections, risky-user or risky-sign-in records, and remediation state to diagnose campaign prompt suppression or unsupported method.
  3. Investigate the high-risk user, confirm compromise status, and perform administrator remediation when self-remediation is not possible.
  4. Require appropriate remediation for risky authentication through the relevant Microsoft Entra ID Protection control.
  5. Use risk detections, risky-user or risky-sign-in records, and remediation state to distinguish detection timing from immediate enforcement.

Correct Answer: B

 

Correct Answer

Answer B is correct because This action directly provides diagnosis of campaign prompt suppression or unsupported method. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is scoping of risk policy to supported workload identity. The scenario instead requires diagnosis of campaign prompt suppression or unsupported method, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is handling of high-risk user unable to self-remediate. The scenario instead requires diagnosis of campaign prompt suppression or unsupported method, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is enforcement of appropriate remediation for risky authentication. The scenario instead requires diagnosis of campaign prompt suppression or unsupported method, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is a clear distinction between detection timing and immediate enforcement. The scenario instead requires diagnosis of campaign prompt suppression or unsupported method, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 17

Testing of an identity-risk investigation is successful except for this condition: correlate risky sign-in with user investigation evidence. General network connectivity outside the identity path is already verified. Which action best satisfies the requirement?

  1. Use a user-risk Conditional Access/ID Protection remediation that requires secure password change when supported and appropriate.
  2. Prioritize risky user using evidence rather than risk label alone according to the risk and impact shown by risk detections, risky-user or risky-sign-in records, and remediation state.
  3. Use risk detections, risky-user or risky-sign-in records, and remediation state to diagnose workload remediation versus managed-identity eligibility.
  4. Correlate the risky sign-in record with the user’s risk detections, authentication event, and remediation state before deciding the response.
  5. Use a sign-in-risk policy/Conditional Access control that requires the configured remediation for risky authentication events.

Correct Answer: D

 

Correct Answer

Answer D is correct because This action directly resolves correlate risky sign-in with user investigation evidence at the evidence or control boundary described by the scenario, rather than substituting a neighboring identity workflow.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is evaluation of passwordless user-risk remediation requirements. The scenario instead requires correlate risky sign-in with user investigation evidence, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is prioritization of risky user using evidence rather than risk label alone. The scenario instead requires correlate risky sign-in with user investigation evidence, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is diagnosis of workload remediation versus managed-identity eligibility. The scenario instead requires correlate risky sign-in with user investigation evidence, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is a clear distinction between transient sign-in risk and compromised account. The scenario instead requires correlate risky sign-in with user investigation evidence, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 18

The organization wants the least-disruptive correction to an identity-risk investigation. It must provide: the appropriate confirm compromised versus dismiss risk. Resource permissions outside the identity control are already correct. Choose TWO actions that together implement and verify the requirement.

  1. Use risk detections, risky-user or risky-sign-in records, and remediation state to diagnose block caused by missing remediation prerequisites.
  2. Review the relevant risk detection, risk state, and remediation result in Microsoft Entra ID Protection.
  3. Use the risky-user investigation workflow to confirm compromise, preserve evidence, and then remediate or dismiss the risk appropriately.
  4. Reassess workload risk after verified response using risk detections, risky-user or risky-sign-in records, and remediation state after the verified remediation.
  5. Move the legacy user-risk configuration to Conditional Access before the documented retirement date, preserving equivalent scope and remediation.
  6. Interpret service-principal risk detection context using risk detections, risky-user or risky-sign-in records, and remediation state rather than inferring it from configuration alone.

Correct Answers: B, C

 

Correct Answers

Answer B is correct because This verification step confirms that the selected control changes effective behavior for the intended pilot and exposes policy, assignment, propagation, or evidence problems before wider rollout.

Answer C is correct because This action directly provides the appropriate confirm compromised versus dismiss risk at the correct Microsoft Entra control boundary.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is diagnosis of block caused by missing remediation prerequisites. It does not implement or verify the appropriate confirm compromised versus dismiss risk in this scenario.

Answer D is incorrect because This action is appropriate when the requirement is reassess workload risk after verified response. It does not implement or verify the appropriate confirm compromised versus dismiss risk in this scenario.

Answer E is incorrect because This action is appropriate when the requirement is a controlled migration of legacy user-risk policy before dated retirement. It does not implement or verify the appropriate confirm compromised versus dismiss risk in this scenario.

Answer F is incorrect because This action is appropriate when the requirement is correct interpretation of service-principal risk detection context. It does not implement or verify the appropriate confirm compromised versus dismiss risk in this scenario.

 

Question 19

A design review of an identity-risk investigation identifies one remaining requirement: the appropriate secure password reset or administrative containment. The administrator must verify the effective result from Microsoft Entra evidence. Which action best satisfies the requirement?

  1. Exclude emergency identities while preserving monitored response narrowly while preserving monitoring and the intended control for all other identities.
  2. Treat user risk as the identity’s accumulated compromise likelihood and sign-in risk as the risk of the individual authentication event.
  3. Move the legacy sign-in-risk configuration to Conditional Access before the documented retirement date, validating the new policy in report-only mode first.
  4. Select secure password reset or administrative containment in Microsoft Entra ID Protection and verify the resulting behavior.
  5. Choose workload containment without user mfa assumption in Microsoft Entra ID Protection and verify the resulting behavior.

Correct Answer: D

 

Correct Answer

Answer D is correct because This action directly provides the appropriate secure password reset or administrative containment. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is exclude emergency identities while preserving monitored response. The scenario instead requires the appropriate secure password reset or administrative containment, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is a clear distinction between accumulated user risk and individual sign-in risk. The scenario instead requires the appropriate secure password reset or administrative containment, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is a controlled migration of legacy sign-in-risk policy with date explicit. The scenario instead requires the appropriate secure password reset or administrative containment, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is the appropriate workload containment without user MFA assumption. The scenario instead requires the appropriate secure password reset or administrative containment, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 20

Current evidence from an identity-risk investigation shows that this requirement is not yet met: resolution of investigation when risk persists after remediation. The organization requires a supported Microsoft-managed control. Which action best satisfies the requirement?

  1. Evaluate passwordless sign-in-risk control compatibility using risk detections, risky-user or risky-sign-in records, and remediation state before changing production configuration.
  2. Revoke or replace exposed application credential through Microsoft Entra ID Protection and verify whether any separate application session remains.
  3. Choose sign-in-risk threshold for stated exposure in Microsoft Entra ID Protection and verify the resulting behavior.
  4. Resolve investigation when risk persists after remediation in Microsoft Entra ID Protection without broadening unrelated access.
  5. Use a user-risk Conditional Access/ID Protection remediation that requires secure password change when supported and appropriate.

Correct Answer: D

 

Correct Answer

Answer D is correct because This action directly provides resolution of investigation when risk persists after remediation. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is evaluation of passwordless sign-in-risk control compatibility. The scenario instead requires resolution of investigation when risk persists after remediation, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is revocation of or replace exposed application credential. The scenario instead requires resolution of investigation when risk persists after remediation, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is the appropriate sign-in-risk threshold for stated exposure. The scenario instead requires resolution of investigation when risk persists after remediation, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is the required setting for user-risk remediation for registered MFA users. The scenario instead requires resolution of investigation when risk persists after remediation, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 21

Before expanding an identity-risk investigation, the administrator must satisfy this condition: a clear distinction between detection timing and immediate enforcement. The current population and assignment scope must be preserved. Which action best satisfies the requirement?

  1. Use risk detections, risky-user or risky-sign-in records, and remediation state to distinguish detection timing from immediate enforcement.
  2. Investigate the high-risk user, confirm compromise status, and perform administrator remediation when self-remediation is not possible.
  3. Scope risk policy to supported workload identity to the intended population in Microsoft Entra ID Protection.
  4. Configure an authentication-method registration campaign for the intended unregistered population and monitor completion.
  5. Require appropriate remediation for risky authentication through the relevant Microsoft Entra ID Protection control.

Correct Answer: A

 

Correct Answer

Answer A is correct because This action directly provides a clear distinction between detection timing and immediate enforcement. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer B is incorrect because This action is appropriate when the requirement is handling of high-risk user unable to self-remediate. The scenario instead requires a clear distinction between detection timing and immediate enforcement, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is scoping of risk policy to supported workload identity. The scenario instead requires a clear distinction between detection timing and immediate enforcement, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is the appropriate registration campaign for target authentication method. The scenario instead requires a clear distinction between detection timing and immediate enforcement, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is enforcement of appropriate remediation for risky authentication. The scenario instead requires a clear distinction between detection timing and immediate enforcement, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 22

The administrator is preparing an identity-risk investigation for production. The required condition is: prioritization of risky user using evidence rather than risk label alone. Existing working access outside the stated scope must remain unchanged. Which action best satisfies the requirement?

  1. Use risk detections, risky-user or risky-sign-in records, and remediation state to distinguish registration eligibility from mfa enforcement.
  2. Use risk detections, risky-user or risky-sign-in records, and remediation state to diagnose workload remediation versus managed-identity eligibility.
  3. Use a sign-in-risk policy/Conditional Access control that requires the configured remediation for risky authentication events.
  4. Prioritize risky user using evidence rather than risk label alone according to the risk and impact shown by risk detections, risky-user or risky-sign-in records, and remediation state.
  5. Use a user-risk Conditional Access/ID Protection remediation that requires secure password change when supported and appropriate.

Correct Answer: D

 

Correct Answer

Answer D is correct because This action directly provides prioritization of risky user using evidence rather than risk label alone. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is a clear distinction between registration eligibility and MFA enforcement. The scenario instead requires prioritization of risky user using evidence rather than risk label alone, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is diagnosis of workload remediation versus managed-identity eligibility. The scenario instead requires prioritization of risky user using evidence rather than risk label alone, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is a clear distinction between transient sign-in risk and compromised account. The scenario instead requires prioritization of risky user using evidence rather than risk label alone, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is evaluation of passwordless user-risk remediation requirements. The scenario instead requires prioritization of risky user using evidence rather than risk label alone, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 23

A production issue involving an identity-risk investigation has been narrowed to this requirement: correct interpretation of service-principal risk detection context. The change will be piloted before broader enforcement. Which action best satisfies the requirement?

  1. Move the legacy user-risk configuration to Conditional Access before the documented retirement date, preserving equivalent scope and remediation.
  2. Reassess workload risk after verified response using risk detections, risky-user or risky-sign-in records, and remediation state after the verified remediation.
  3. Target the registration campaign to users who have not registered the required method while excluding the documented exception cohort.
  4. Use the risky workload identity or service-principal risk record and its detection details to interpret the workload risk context; do not apply user MFA assumptions.
  5. Use risk detections, risky-user or risky-sign-in records, and remediation state to diagnose block caused by missing remediation prerequisites.

Correct Answer: D

 

Correct Answer

Answer D is correct because This action directly resolves interpret service-principal risk detection context at the evidence or control boundary described by the scenario, rather than substituting a neighboring identity workflow.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is a controlled migration of legacy user-risk policy before dated retirement. The scenario instead requires correct interpretation of service-principal risk detection context, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is reassess workload risk after verified response. The scenario instead requires correct interpretation of service-principal risk detection context, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is targeting of unregistered users without disrupting excluded cohort. The scenario instead requires correct interpretation of service-principal risk detection context, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is diagnosis of block caused by missing remediation prerequisites. The scenario instead requires correct interpretation of service-principal risk detection context, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 24

The security review of a service principal flagged with suspicious workload-identity activity focuses on one acceptance criterion: the appropriate workload containment without user MFA assumption. The tenant has the licensing required for the named capability. Choose TWO actions that together implement and verify the requirement.

  1. Exclude emergency identities while preserving monitored response narrowly while preserving monitoring and the intended control for all other identities.
  2. Move the legacy sign-in-risk configuration to Conditional Access before the documented retirement date, validating the new policy in report-only mode first.
  3. Choose workload containment without user mfa assumption in Microsoft Entra ID Protection and verify the resulting behavior.
  4. Treat user risk as the identity’s accumulated compromise likelihood and sign-in risk as the risk of the individual authentication event.
  5. Use risk detections, risky-user or risky-sign-in records, and remediation state to diagnose campaign prompt suppression or unsupported method.
  6. Review the relevant risk detection, risk state, and remediation result in Microsoft Entra ID Protection.

Correct Answers: C, F

 

Correct Answers

Answer C is correct because This action directly provides the appropriate workload containment without user MFA assumption at the correct Microsoft Entra control boundary.

Answer F is correct because This verification step confirms that the selected control changes effective behavior for the intended pilot and exposes policy, assignment, propagation, or evidence problems before wider rollout.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is exclude emergency identities while preserving monitored response. It does not implement or verify the appropriate workload containment without user MFA assumption in this scenario.

Answer B is incorrect because This action is appropriate when the requirement is a controlled migration of legacy sign-in-risk policy with date explicit. It does not implement or verify the appropriate workload containment without user MFA assumption in this scenario.

Answer D is incorrect because This action is appropriate when the requirement is a clear distinction between accumulated user risk and individual sign-in risk. It does not implement or verify the appropriate workload containment without user MFA assumption in this scenario.

Answer E is incorrect because This action is appropriate when the requirement is diagnosis of campaign prompt suppression or unsupported method. It does not implement or verify the appropriate workload containment without user MFA assumption in this scenario.

 

Question 25

The team is validating an identity-risk investigation. The decisive requirement is: revocation of or replace exposed application credential. The correction must address the named control boundary rather than reset unrelated tenant settings. Which action best satisfies the requirement?

  1. Revoke or replace exposed application credential through Microsoft Entra ID Protection and verify whether any separate application session remains.
  2. Use a user-risk Conditional Access/ID Protection remediation that requires secure password change when supported and appropriate.
  3. Correlate risky sign-in with user investigation evidence using risk detections, risky-user or risky-sign-in records, and remediation state before deciding on remediation.
  4. Evaluate passwordless sign-in-risk control compatibility using risk detections, risky-user or risky-sign-in records, and remediation state before changing production configuration.
  5. Choose sign-in-risk threshold for stated exposure in Microsoft Entra ID Protection and verify the resulting behavior.

Correct Answer: A

 

Correct Answer

Answer A is correct because This action directly provides revocation of or replace exposed application credential. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer B is incorrect because This action is appropriate when the requirement is the required setting for user-risk remediation for registered MFA users. The scenario instead requires revocation of or replace exposed application credential, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is correlate risky sign-in with user investigation evidence. The scenario instead requires revocation of or replace exposed application credential, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is evaluation of passwordless sign-in-risk control compatibility. The scenario instead requires revocation of or replace exposed application credential, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is the appropriate sign-in-risk threshold for stated exposure. The scenario instead requires revocation of or replace exposed application credential, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 26

Operations staff investigating a service principal flagged with suspicious workload-identity activity have isolated the issue to: scoping of risk policy to supported workload identity. No new standing administrator privilege may be introduced. Which action best satisfies the requirement?

  1. Use the risky-user investigation workflow to confirm compromise, preserve evidence, and then remediate or dismiss the risk appropriately.
  2. Require appropriate remediation for risky authentication through the relevant Microsoft Entra ID Protection control.
  3. Configure an authentication-method registration campaign for the intended unregistered population and monitor completion.
  4. Investigate the high-risk user, confirm compromise status, and perform administrator remediation when self-remediation is not possible.
  5. Scope risk policy to supported workload identity to the intended population in Microsoft Entra ID Protection.

Correct Answer: E

 

Correct Answer

Answer E is correct because This action directly provides scoping of risk policy to supported workload identity. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is the appropriate confirm compromised versus dismiss risk. The scenario instead requires scoping of risk policy to supported workload identity, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is enforcement of appropriate remediation for risky authentication. The scenario instead requires scoping of risk policy to supported workload identity, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is the appropriate registration campaign for target authentication method. The scenario instead requires scoping of risk policy to supported workload identity, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is handling of high-risk user unable to self-remediate. The scenario instead requires scoping of risk policy to supported workload identity, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 27

The administrator must correct a service principal flagged with suspicious workload-identity activity without changing adjacent controls. The target condition is: diagnosis of workload remediation versus managed-identity eligibility. General network connectivity outside the identity path is already verified. Which action best satisfies the requirement?

  1. Use a user-risk Conditional Access/ID Protection remediation that requires secure password change when supported and appropriate.
  2. Use a sign-in-risk policy/Conditional Access control that requires the configured remediation for risky authentication events.
  3. Use risk detections, risky-user or risky-sign-in records, and remediation state to distinguish registration eligibility from mfa enforcement.
  4. Select secure password reset or administrative containment in Microsoft Entra ID Protection and verify the resulting behavior.
  5. Use risk detections, risky-user or risky-sign-in records, and remediation state to diagnose workload remediation versus managed-identity eligibility.

Correct Answer: E

 

Correct Answer

Answer E is correct because This action directly provides diagnosis of workload remediation versus managed-identity eligibility. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is evaluation of passwordless user-risk remediation requirements. The scenario instead requires diagnosis of workload remediation versus managed-identity eligibility, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is a clear distinction between transient sign-in risk and compromised account. The scenario instead requires diagnosis of workload remediation versus managed-identity eligibility, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is a clear distinction between registration eligibility and MFA enforcement. The scenario instead requires diagnosis of workload remediation versus managed-identity eligibility, so this option would solve an adjacent identity problem rather than the documented gap.

Answer D is incorrect because This action is appropriate when the requirement is the appropriate secure password reset or administrative containment. The scenario instead requires diagnosis of workload remediation versus managed-identity eligibility, so this option would solve an adjacent identity problem rather than the documented gap.

 

Question 28

An audit of a service principal flagged with suspicious workload-identity activity identifies this control gap: reassess workload risk after verified response. Resource permissions outside the identity control are already correct. Which action best satisfies the requirement?

  1. Resolve investigation when risk persists after remediation in Microsoft Entra ID Protection without broadening unrelated access.
  2. Move the legacy user-risk configuration to Conditional Access before the documented retirement date, preserving equivalent scope and remediation.
  3. Use risk detections, risky-user or risky-sign-in records, and remediation state to diagnose block caused by missing remediation prerequisites.
  4. Recheck the risky workload identity or service-principal risk state after the verified containment or credential response and close the issue only from updated risk evidence.
  5. Target the registration campaign to users who have not registered the required method while excluding the documented exception cohort.

Correct Answer: D

 

Correct Answer

Answer D is correct because This action directly resolves reassess workload risk after verified response at the evidence or control boundary described by the scenario, rather than substituting a neighboring identity workflow.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is resolution of investigation when risk persists after remediation. The scenario instead requires reassess workload risk after verified response, so this option would solve an adjacent identity problem rather than the documented gap.

Answer B is incorrect because This action is appropriate when the requirement is a controlled migration of legacy user-risk policy before dated retirement. The scenario instead requires reassess workload risk after verified response, so this option would solve an adjacent identity problem rather than the documented gap.

Answer C is incorrect because This action is appropriate when the requirement is diagnosis of block caused by missing remediation prerequisites. The scenario instead requires reassess workload risk after verified response, so this option would solve an adjacent identity problem rather than the documented gap.

Answer E is incorrect because This action is appropriate when the requirement is targeting of unregistered users without disrupting excluded cohort. The scenario instead requires reassess workload risk after verified response, so this option would solve an adjacent identity problem rather than the documented gap.

img