TechNuggets Academy

Describe the capabilities of Microsoft Entra

Free Microsoft Certified: Security, Compliance, and Identity Fundamentals practice — 6 questions on Describe the capabilities of Microsoft Entra, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Describe the capabilities of Microsoft Entra
A company wants to eliminate standing administrative access. Global Administrators should have no privileges by default, and must submit a justification and receive approval to activate the role for a maximum of 8 hours only when performing administrative tasks. Which Microsoft Entra capability meets this requirement?
PIM provides just-in-time, time-bound privileged role activation that requires justification and can require approval, enforcing zero standing access to admin roles like Global Administrator.
Question 2 of 6 · Describe the capabilities of Microsoft Entra
A project team needs external partners to request access to a specific set of resources (a group, a SharePoint site, and an application) through a single request, with access automatically expiring after 90 days unless renewed. Which Microsoft Entra ID Governance feature should be used?
Entitlement management lets you bundle multiple resources (groups, apps, SharePoint sites) into an access package that external users can request, with configurable expiration and renewal policies.
Question 3 of 6 · Describe the capabilities of Microsoft Entra
An organization wants sign-ins detected as medium or high risk by Microsoft Entra ID Protection to automatically require the user to perform multi-factor authentication before being granted access, without an administrator manually intervening. How should this be configured?
Identity Protection risk detections can be consumed by Conditional Access sign-in risk policies, which can be scoped to trigger MFA specifically when risk is medium or high, automating the response.
Question 4 of 6 · Describe the capabilities of Microsoft Entra
Which statement correctly differentiates Windows Hello for Business from a FIDO2 security key in Microsoft Entra ID passwordless authentication?
Windows Hello for Business provisions a device-bound credential tied to the specific Windows device's TPM, whereas a FIDO2 security key is an external, portable authenticator a user can carry and use to sign in on different compatible devices.
Question 5 of 6 · Describe the capabilities of Microsoft Entra
A company grants guest users from a partner organization access to an internal Microsoft Teams site for the duration of a joint project. Compliance requires that every guest's continued access be formally reviewed and re-approved by the project owner every 3 months, with automatic removal if not approved. Which Microsoft Entra feature satisfies this requirement?
Access reviews let you schedule recurring reviews (e.g., every 3 months) of guest user access to resources like Teams/groups, requiring reviewer approval and automatically removing access if not confirmed.
Question 6 of 6 · Describe the capabilities of Microsoft Entra
A university wants to issue digital, tamper-evident diplomas that graduates can store in a digital wallet and present to employers, who can then cryptographically verify authenticity without contacting the university's student records system directly. Which Microsoft Entra capability is designed for this scenario?
Microsoft Entra Verified ID issues decentralized, cryptographically verifiable credentials (such as diplomas) that holders store in a digital wallet and present to relying parties, who can verify authenticity without querying the issuing organization's live systems.
Ready for the real thing?

The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.

undefined $34.99 with code FREETEST33 — valid through Oct 6.

Get my $34.99 deal →