SC-300 · Question #348
You have a Microsoft Entra tenant. You open the risk detections report. Which risk detection type is classified as a user risk?
The correct answer is D. leaked credentials. Leaked credentials (D) is classified as a user risk because it directly indicates that a user's username and password have been found exposed (e.g., on the dark web), meaning the user account itself is compromised - regardless of any specific sign-in event. Why the others are…
Question
You have a Microsoft Entra tenant. You open the risk detections report. Which risk detection type is classified as a user risk?
Options
- Aimpossible travel
- Banonymous IP address
- Catypical travel
- Dleaked credentials
How the community answered
(42 responses)- A5% (2)
- C5% (2)
- D90% (38)
Explanation
Leaked credentials (D) is classified as a user risk because it directly indicates that a user's username and password have been found exposed (e.g., on the dark web), meaning the user account itself is compromised - regardless of any specific sign-in event.
Why the others are wrong: Impossible travel (A), anonymous IP address (B), and atypical travel (C) are all classified as sign-in risks because they are detected based on suspicious characteristics of a specific sign-in attempt (location, IP, behavior during login), not the user's overall account integrity.
Memory tip: Think of it this way - user risks = something permanently wrong with the user's credentials, while sign-in risks = something suspicious about a specific login event. Leaked credentials stick to the user like a scarlet letter, whereas risky sign-in behaviors are tied to a single login moment. If you remember "leaked = long-term user problem," you'll never confuse it with sign-in risks again.
Topics
Community Discussion
No community discussion yet for this question.