AZ-500 · Question #40
Hotspot Question You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains the users shown in the following table. You create and enforce an Azure AD Identity Protection…
The correct answer is If User1 signs in from an unfamiliar location, he must change his password. = Yes; If User2 signs in from an anonymous IP address, she must change her password. = No; If User3 signs in from a computer containing malware that is communicating with known bot servers, he must change his password. = No. The user risk policy applies to Group1 members but excludes Group2 members. User1 is in Group1 (not Group2), so when signing in from an unfamiliar location (which triggers medium or above risk), the policy applies and requires a password change - hence 'Yes'. User2 is in both…
Question
Exhibits
Answer Area
- If User1 signs in from an unfamiliar location, he must change his password.Yes
- If User2 signs in from an anonymous IP address, she must change her password.No
- If User3 signs in from a computer containing malware that is communicating with known bot servers, he must change his password.No
Explanation
The user risk policy applies to Group1 members but excludes Group2 members. User1 is in Group1 (not Group2), so when signing in from an unfamiliar location (which triggers medium or above risk), the policy applies and requires a password change - hence 'Yes'. User2 is in both Group1 and Group2, but since Group2 is explicitly excluded, the policy does NOT apply to User2, so no password change is required despite the anonymous IP risk. User3 is not in Group1 at all, so the policy's inclusion assignment never covers User3, meaning the malware-linked sign-in risk does not trigger the policy's password change requirement.
Topics
Community Discussion
No community discussion yet for this question.



