- Answer: A
Azure AD Identity Protection has sign-in risk policies (to allow MFA requirements) and user risk policies (to allow password resets) that enable automated responses to risky sign-ins. Since the administrator needs the solution to require MFA conditionally, you'd recommend the Azure AD Identity Protection Sign-in risk policy.
More information: https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/howto-sign-in-risk-policy.
- Answer: B
From the Security & Compliance Center, you can configure alerts based on user activities, including when someone adds a site collection administrator. Review the table in Chapter 8, Managing Security Reports and Alerts, to become more familiar with all the possible alerts you can set up based on activities in Microsoft 365.
More information: https://docs.microsoft.com/en-us/office365/securitycompliance...