nerdexam
Microsoft

AZ-500 · Question #39

Drag and Drop Question You are implementing conditional access policies. You must evaluate the existing Azure Active Directory (Azure AD) risk events and risk levels to configure and implement the…

The correct answer is Medium; High; Medium. Azure AD Identity Protection assigns specific risk levels to each risk event type based on the severity of the threat. 'Users with leaked credentials' is rated Medium because while serious, it is a known and detectable threat that allows time for remediation. 'Impossible travel…

Submitted by naveen.iyer· Mar 6, 2026Implement and manage identity and access - specifically configuring Azure AD Identity Protection risk policies and understanding risk level classifications for conditional access implementation (Microsoft SC-300 / AZ-500)

Question

Drag and Drop Question You are implementing conditional access policies. You must evaluate the existing Azure Active Directory (Azure AD) risk events and risk levels to configure and implement the policies. You need to identify the risk level of the following risk events: - Users with leaked credentials - Impossible travel to atypical locations - Sign ins from IP addresses with suspicious activity Which level should you identify for each risk event? To answer, drag the appropriate levels to the correct risk events. Each level may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point. Answer:

Exhibits

AZ-500 question #39 exhibit 1
AZ-500 question #39 exhibit 2

Answer Area

Drag items

HighLowMedium

Correct arrangement

  • Medium
  • High
  • Medium

Explanation

Azure AD Identity Protection assigns specific risk levels to each risk event type based on the severity of the threat. 'Users with leaked credentials' is rated Medium because while serious, it is a known and detectable threat that allows time for remediation. 'Impossible travel to atypical locations' is rated High because it strongly indicates account compromise since it is physically impossible for a legitimate user to sign in from two geographically distant locations in a short timeframe. 'Sign-ins from IP addresses with suspicious activity' is rated Medium because it indicates potential risk but is not as definitive as impossible travel since IP addresses can be shared or used by proxies.

Topics

#Azure AD Identity Protection#Conditional Access#Risk Events#Zero Trust Security

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice