A governance lead is selecting Microsoft Entra ID Governance capabilities to make sure the right people keep the right access over time without standing privilege. Which TWO capabilities best support these governance goals? Select TWO.
- AMicrosoft Defender for Cloud secure score that rates the security posture of Azure workloads
- BAccess reviews that have reviewers periodically recertify who should retain access Correct
- CMicrosoft Sentinel data connectors that ingest logs into a cloud-native SIEM
- DMicrosoft Purview sensitivity labels that classify and protect documents and emails
- EPrivileged Identity Management that grants eligible roles just in time with activation Correct
Why A is wrong: Secure score measures workload security posture in Defender for Cloud and is not an Entra identity governance capability.
Why B is correct: Access reviews recurrently confirm that group, app and role access is still appropriate, a core governance capability.
Why C is wrong: Sentinel connectors feed a SIEM for detection and response; they are not part of Entra identity governance.
Why D is wrong: Sensitivity labels are a Purview information protection control over data, not an Entra access governance capability.
Why E is correct: PIM removes standing privilege by making roles eligible and activated only when needed, directly serving governance goals.