For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAzure Solutions Architect Expert (AZ-305)Azure Solutions Architect Expert AZ-305 Practice Exam 2Question 06
    Medium1 markMultiple Choice
    Domain 1.2: Authentication and AuthorizationDomain 1PIMConditional AccessGovernance

    AZ-305 · Question 06 · Domain 1.2: Authentication and Authorization

    You are designing an identity governance solution for a large enterprise using Microsoft Entra ID (Azure AD).

    The security team requires that any user attempting to access the Azure Portal to perform administrative tasks must:

    1. Be prompted for Multi-Factor Authentication (MFA).
    2. Provide a business justification.
    3. Have their access automatically revoked after 4 hours.

    Which combination of services should you implement?

    Answer options:

    A.

    Conditional Access and Azure AD Identity Protection

    B.

    Privileged Identity Management (PIM) and Conditional Access

    C.

    Azure AD Access Reviews and Conditional Access

    D.

    Azure AD B2B and Privileged Identity Management (PIM)

    How to approach this question

    Match the requirements to the specific capabilities of Entra ID features: time-bound/justification = PIM; MFA enforcement = Conditional Access.

    Full Answer

    B.Privileged Identity Management (PIM) and Conditional Access✓ Correct
    Privileged Identity Management (PIM) and Conditional Access
    Privileged Identity Management (PIM) provides Just-In-Time (JIT) privileged access to Azure AD and Azure resources. It supports requiring a justification and setting a maximum activation duration (e.g., 4 hours). Conditional Access is used to enforce Multi-Factor Authentication (MFA) when the user attempts to access the Azure Portal.

    Common mistakes

    Confusing Identity Protection with PIM. Identity Protection is for risk-based policies (e.g., leaked credentials), not JIT access.
    Question 05All questionsQuestion 07

    Practice the full Azure Solutions Architect Expert AZ-305 Practice Exam 2

    55 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01Fabrikam Inc. is a global financial services company with 200 Azure subscriptions managed via a c...HardQ02A healthcare organization has 500 on-premises Windows Server VMs and 300 Azure VMs. They are impl...HardQ03You are designing a security monitoring solution using Microsoft Sentinel. The compliance depar...EasyQ04Your company has a microservices application deployed across multiple Azure App Service instances...MediumQ05A defense contractor is migrating to Microsoft 365 and Azure. They have a strict security policy ...Hard
    View all 55 questions →