正解:D
SC-300 distinguishes user risk from sign-in risk. The text defines: "User risk is the probability that an identity is compromised," and lists its core detections, including "Leaked credentials detected on public or dark-web sources." By comparison, impossible/anomalous travel and anonymous IP are cited as sign-in risk detections:
"Sign-in risk is calculated per authentication event using detections such as impossible travel, atypical travel, and anonymous IP address." Therefore, among the options, only leaked credentials is a user risk detection type; the others are sign-in risk indicators used at authentication time. SC-300 also ties user risk to Identity Protection policies that can require password change or block access when a user's credentials are suspected to be compromised.