nerdexam
Microsoft

SC-300 · Question #358

You have a Microsoft Entra tenant. You open the risk detections report. Which risk detection type is classified as a user risk?

The correct answer is D. Microsoft Entra threat intelligence. Microsoft Entra Threat Intelligence as a User Risk "Microsoft Entra threat intelligence" is classified as a user risk because it detects risk based on Microsoft's internal and external threat intelligence sources that indicate a user account has been compromised - this risk is…

Submitted by andreas_gr· Mar 6, 2026Implement and manage user identities

Question

You have a Microsoft Entra tenant. You open the risk detections report. Which risk detection type is classified as a user risk?

Options

  • Apassword spray
  • Banonymous IP address
  • Cunfamiliar sign-in properties
  • DMicrosoft Entra threat intelligence

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    6% (2)
  • C
    3% (1)
  • D
    87% (27)

Explanation

Microsoft Entra Threat Intelligence as a User Risk

"Microsoft Entra threat intelligence" is classified as a user risk because it detects risk based on Microsoft's internal and external threat intelligence sources that indicate a user account has been compromised - this risk is tied to the user identity itself, not a specific sign-in event. Options A (password spray), B (anonymous IP address), and C (unfamiliar sign-in properties) are all classified as sign-in risks, meaning they are associated with suspicious characteristics of a specific authentication attempt rather than the overall user account state. Note that while "Microsoft Entra threat intelligence" also exists as a sign-in risk detection type, when it appears in the context of user risk, it specifically flags users whose credentials are suspected to be compromised based on threat intel data.

Memory Tip: Think of it this way - sign-in risks are about how or where someone is logging in (anonymous IP, unfamiliar location, password spray targeting a session), while user risks are about who the user is and whether their identity/credentials are compromised. "Threat intelligence" at the user level = compromised identity = user risk.

Topics

#Microsoft Entra ID Protection#User Risk#Risk Detection#Threat Intelligence

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice