正解:A
In Azure AD Identity Protection, a sign-in risk policy can trigger Conditional Access controls (like MFA) when risky sign-ins are detected.
According to the SC-300 training module "Implement and manage user risk policies", a sign-in risk is associated with a specific authentication attempt, for instance, when a user connects from an anonymous IP address, TOR network, or unfamiliar location. To enforce MFA only when such sign-in conditions are detected, administrators must use a sign-in risk policy.
Microsoft states: "Sign-in risk policies can enforce MFA or block access when sign-in risk meets the configured threshold, such as sign-ins from anonymous IPs."