Describe authentication capabilities of Microsoft Entra ID
Objective entra.authentication sits in Describe capabilities of Microsoft Entra, which carries 28% of the SCI Fundamentals exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.
Objective title verbatim from the official objectives. Microsoft Azure exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
A compliance officer asks how Microsoft Entra ID Protection builds its risk intelligence for detecting compromised sign-ins. Which set of experience sources feeds this capability?
The concept
Microsoft Entra ID Protection derives its threat detection from learnings gathered across Microsoft's own large-scale identity ecosystems, not from a single product's telemetry.
Why this answer
The source states that Microsoft Entra ID Protection uses the learnings Microsoft acquired from organizations using Microsoft Entra ID, the consumer space with Microsoft Accounts, and gaming with Xbox to protect users.
- AThis describes signal sharing among Defender XDR's own suite products, not the origin of Entra ID Protection's risk intelligence.
- BOn premises Active Directory signals are the basis for Defender for Identity, a separate identity protection component from Entra ID Protection.
- CRole assignments and deny assignments belong to Azure RBAC's access evaluation process, unrelated to identity risk detection.
- Correct: this matches the stated learnings behind Microsoft Entra ID Protection.
Now you: objective entra.authentication questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
A security team wants to detect risky sign-ins and compromised identities using cloud signals drawn from Microsoft Entra ID and consumer account activity, rather than relying on their on-premises Active Directory logs. Which component should they enable?
Sample question 2 of 3
A security team wants a cloud-based capability that uses sign-in and risk signal learnings from Microsoft Entra ID, consumer Microsoft Accounts, and Xbox to help protect user identities. Which capability should they use?
Sample question 3 of 3
An organisation wants a sign-in method that cannot be replayed by an attacker who intercepts it remotely. Which property of passkeys delivers that?
Full SCI Fundamentals question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.