nerdexam
Microsoft

SC-200 · Question #187

You have an Azure subscription that contains a user named User1. User1 is assigned an Azure Active Directory Premium Plan 2 license. You need to identify whether the identity of User1 was…

The correct answer is A. the risk detections report. The risk detections report in Azure AD Identity Protection (available with AAD Premium P2) logs individual risk events - such as leaked credentials, impossible travel, or anonymous IP sign-ins - with timestamps and severity. It is the appropriate report to determine whether…

Submitted by dimitri_ru· Apr 18, 2026Manage security threats

Question

You have an Azure subscription that contains a user named User1. User1 is assigned an Azure Active Directory Premium Plan 2 license. You need to identify whether the identity of User1 was compromised during the last 90 days. What should you use?

Options

  • Athe risk detections report
  • Bthe risky users report
  • CIdentity Secure Score recommendations
  • Dthe risky sign-ins report

How the community answered

(29 responses)
  • A
    93% (27)
  • B
    3% (1)
  • D
    3% (1)

Explanation

The risk detections report in Azure AD Identity Protection (available with AAD Premium P2) logs individual risk events - such as leaked credentials, impossible travel, or anonymous IP sign-ins - with timestamps and severity. It is the appropriate report to determine whether User1 experienced specific compromise indicators within the last 90 days. The risky users report (B) shows current risk state but not granular per-event history. The risky sign-ins report (D) focuses on authentication events, not broader identity compromise indicators. Identity Secure Score (C) provides posture recommendations, not user-specific incident history.

Topics

#Identity Protection#Risk Detections#Compromised Identities

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice