
Explanation:

According to the Microsoft SC-300: Identity and Access Administrator Study Guide and official documentation for Azure AD Identity Protection, the ability to configure and view risk-based policies depends on the administrative roles assigned in Azure AD.
* User Risk Policy Configuration:The user risk policy determines how Azure AD responds when a user' s sign-in is determined to be risky. According to the Microsoft Learn documentation:
"Only users assigned the Global Administrator, Security Administrator, or Conditional Access Administrator roles can create and manage risk policies in Azure AD Identity Protection." In the scenario, User3 is the Security Administrator, which gives full rights to configure both sign-in risk and user risk policies. Although User1 (Conditional Access Administrator) can manage Conditional Access policies, only Security Administrator or Global Administrator can configure the user risk policy in Identity Protection. Therefore, User3 only can perform this configuration.
* Viewing Risky Users Report:Viewing Identity Protection reports, including risky users, risky sign-ins
, and risk detections, can be done by users with the following roles:
"Security Reader, Security Operator, Security Administrator, and Global Administrator can view Identity Protection reports." This means both User3 (Security Administrator) and User4 (Security Operator) can access and view these reports.