SC-300 Exam Questions
433 real SC-300 exam questions with expert-verified answers and explanations. Page 1 of 9.
- Question #1Implement and Manage Hybrid Identity
You need to sync the ADatum users. The solution must meet the technical requirements. What should you do?
Entra Connectsynchronization optionshybrid identityActive Directory sync - Question #2Manage Azure Active Directory Applications
You need to meet the planned changes and technical requirements for App1. What should you implement?
app registrationAzure ADenterprise applicationsIntune - Question #3Monitor and Maintain Azure Active Directory
You need to implement the technical requirements for auditing. What should you configure in Azure AD?
diagnostic settingsAzure AD monitoringaudit logsAzure Sentinel - Question #5Plan and implement identity governance
You need to implement the planned changes and technical requirements for the marketing department. What should you do? To answer, select the appropriate options in the answer area....
Azure AD Identity GovernanceAccess PackagesEntitlement ManagementExternal Collaboration - Question #6Implement Authentication and Authorization Solutions
You need to meet the authentication requirements for leaked credentials. What should you do?
password hash synchronizationAzure AD Connectleaked credentialsauthentication methods - Question #7Monitor and Maintain Azure Active Directory
You need to configure the detection of multi-staged attacks to meet the monitoring requirements. What should you do?
Azure Sentineldata connectorsSIEMthreat detection - Question #8Implement and manage user identities
You need to configure the assignment of Azure AD licenses to the Litware users. The solution must meet the licensing requirements. What should you do? To answer, select the appropr...
Azure AD ConnectDirectory ExtensionsGroup-based LicensingDynamic Groups - Question #9Plan and implement identity governance
You need to identify which roles to use for managing role assignments. The solution must meet the delegation requirements. What should you do? To answer, select the appropriate opt...
Azure AD RolesAzure RBACPrivileged Identity Management (PIM)Least Privilege - Question #10Implement Access Management for Apps and Infrastructure
You need to implement on-premises application and SharePoint Online restrictions to meet the authentication requirements and the access requirements. What should you do? To answer,...
Azure AD Application ProxySharePoint Onlineconditional accesssession controls - Question #11Implement and Manage Hybrid Identity
Your network contains an on-premises Active Directory domain that syncs to an Azure Active Directory (Azure AD) tenant. Users sign in to computers that run Windows 10 and are joine...
Seamless SSOIntranet Zone settingsWindows 10hybrid identity - Question #12Manage Azure Identities and Governance
You have an Azure Active Directory (Azure AD) tenant that contains the following objects: - A device named Device1 - Users named User1, User2, User3, User4, and User5 - Groups name...
group-based licensingAzure AD groupsMicrosoft 365 licensinglicense assignment - Question #13Manage Azure Identities and Governance
You have a Microsoft Exchange organization that uses an SMTP address space of contoso.com. Several users use their contoso.com email address for self-service sign-up to Azure Activ...
self-service sign-upPowerShellSet-MsolCompanySettingstenant settings - Question #14Implement and Manage External Identities
You have a Microsoft 365 tenant that uses the domain named fabrikam.com. The Guest invite settings for Azure Active Directory (Azure AD) are configured as shown in the exhibit. (Cl...
guest accessemail passcodeSharePoint sharingexternal identities - Question #15Manage Azure Identities and Governance
You have 2,500 users who are assigned Microsoft Office 365 Enterprise E3 licenses. The licenses are assigned to individual users. From the Groups blade in the Azure Active Director...
license managementgroup-based licensingE3 E5 migrationAzure AD admin center - Question #16Implement and manage user identities
You have an Azure Active Directory (Azure AD) tenant named contoso.com. You plan to bulk invite Azure AD business-to-business (B2B) collaboration users. Which two parameters must y...
Azure AD B2BGuest usersBulk invite - Question #17Implement and manage user identities
You have an Azure Active Directory (Azure AD) tenant that contains the objects shown in the following table. Which objects can you add as members to Group3?
Azure AD groupsGroup membershipUser identities - Question #18Implement and manage user identities
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Azure AD ConnectAccount synchronizationUser lifecycle management - Question #19Implement and manage user identities
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Azure AD ConnectAccount synchronizationUser lifecycle management - Question #20Implement identity management solution
You have an Azure Active Directory (Azure AD) tenant that contains a user named SecAdmin1. SecAdmin1 is assigned the Security administrator role. SecAdmin1 reports that she cannot...
Azure AD rolesLeast privilegePassword managementHelpdesk administrator - Question #21Implement authentication and access management solution
You configure Azure Active Directory (Azure AD) Password Protection as shown in the exhibit. (Click the Exhibit tab.) You are evaluating the following passwords: - Pr0jectlitw@re -...
Azure AD Password ProtectionBanned passwordsPassword policies - Question #22Implement authentication and access management solution
You have a Microsoft 365 tenant. All users have mobile phones and laptops. The users frequently work from remote locations that do not have Wi-Fi access or mobile phone connectivit...
Multi-factor authentication (MFA)Microsoft AuthenticatorMFA methodsOffline authentication - Question #23Implement authentication and access management solution
You configure a new Microsoft 365 tenant to use a default domain name of contoso.com. You need to ensure that you can control access to Microsoft 365 resources by using conditional...
Conditional AccessSecurity DefaultsAzure AD administration - Question #24Implement authentication and access management solution
Your company has a Microsoft 365 tenant. The company has a call center that contains 300 users. In the call center, the users share desktop computers and might use a different comp...
Multi-factor authentication (MFA)FIDO2 security keysShared workstationsPasswordless authentication - Question #25Implement authentication and access management solution
You have an Azure Active Directory (Azure AD) tenant named contoso.com. All users who run applications registered in Azure AD are subject to conditional access policies. You need t...
Conditional AccessLegacy authenticationClient apps conditionAuthentication security - Question #26Plan and implement identity governance
You have an Azure Active Directory (Azure AD) tenant. You open the risk detections report. Which risk detection type is classified as a user risk?
Azure AD Identity ProtectionUser riskSign-in riskRisk detection - Question #27Implement access management for apps
You have a Microsoft 365 tenant. All users have computers that run Windows 10. Most computers are company-owned and joined to Azure Active Directory (Azure AD). Some computers are...
Conditional AccessSession controlsDevice stateSharePoint OnlineData exfiltration prevention - Question #28Implement authentication and access management solution
You have an Azure Active Directory (Azure AD) tenant that syncs to an Active Directory domain. The on-premises network contains a VPN server that authenticates to the on-premises A...
Multi-factor authentication (MFA)NPS Extension for Azure MFAVPN authenticationHybrid identity - Question #29Implement authentication and access management solution
You have a Microsoft 365 tenant. The Azure Active Directory (Azure AD) tenant syncs to an on-premises Active Directory domain. The domain contains the servers shown in the followin...
Azure AD Password ProtectionHybrid identityHigh availabilityPassword security - Question #30Implement access management for apps
You have an Azure Active Directory (Azure AD) tenant. You create an enterprise application collection named HR Apps that has the following settings: - Applications: App1, App2, App...
Enterprise applicationsUser assignmentMy Apps portalAzure AD apps - Question #31Implement access management for apps
You have a Microsoft 365 tenant. The Azure Active Directory (Azure AD) tenant syncs to an on-premises Active Directory domain. Users connect to the internet by using a hardware fir...
Cloud App Security (MCAS)Cloud App DiscoveryShadow ITApp governance - Question #32Plan and implement identity governance
You have a Microsoft 365 tenant. The Azure Active Directory (Azure AD) tenant syncs to an on-premises Active Directory domain. You plan to create an emergency-access administrative...
Emergency access accountsBreak-glass accountsGlobal administratorAzure AD securityMonitoring - Question #33Implement authentication and access management solution
You have a Microsoft 365 tenant. In Azure Active Directory (Azure AD), you configure the terms of use. You need to ensure that only users who accept the terms of use can access the...
Terms of UseConditional AccessResource accessCompliance - Question #34Plan and implement identity governance
You have an Azure Active Directory (Azure AD) tenant that contains the groups shown in the following table. For which groups can you create an access review?
Access reviewsAzure AD groupsIdentity governance - Question #35Plan and implement identity governance
You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table. User1 is the owner of Group1. You create an access review that has the fo...
Access reviewsSelf-reviewIdentity governanceGroup membership - Question #36Implement Access Management for Apps and Infrastructure
Your company recently implemented Azure Active Directory (Azure AD) Privileged Identity Management (PIM). While you review the roles in PIM, you discover that all 15 users in the I...
Privileged Identity Managementeligible assignmentsPIM role configurationSecurity administrator - Question #37Plan and implement identity governance
You have a Microsoft 365 tenant. The Sign-ins activity report shows that an external contractor signed in to the Exchange admin center. You need to review access to the Exchange ad...
access reviewsguest usersexternal usersExchange admin center - Question #38Plan and implement identity governance
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
access reviewsIT administratorsreview scopeidentity governance - Question #39Plan and implement identity governance
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
access reviewsIT administratorsreview scopeidentity governance - Question #40Plan and implement identity governance
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
access reviewsIT administratorsreview scopeidentity governance - Question #41Implement and manage user identities
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Azure AD Connecthybrid identityuser account syncActive Directory - Question #42Implement authentication and access management
Note: This question is part of series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some que...
Multi-Factor Authentication (MFA)Azure AD GroupsUser AuthenticationConditional Access - Question #43Implement access management for apps
Hotspot Question You have a Microsoft 365 tenant named contoso.com. Guest user access is enabled. Users are invited to collaborate with contoso.com as shown in the following table....
Guest user invitationsCollaboration restrictionsAzure AD external identitiesB2B access control - Question #44Manage Azure Active Directory identities and governance - specifically performing an IT Pro (internal) admin takeover of an unmanaged Azure AD tenant created through self-service sign-up, aligning with Microsoft 365 identity management and hybrid identity scenarios.
Drag and Drop Question You have an on-premises Microsoft Exchange organization that uses an SMTP address space of contoso.com. You discover that users use their email address for s...
Azure AD Tenant TakeoverSelf-Service Sign-UpMicrosoft 365 AdministrationUnmanaged Tenant Management - Question #45Manage Azure Active Directory identities - specifically understanding the membership rules and restrictions for different Azure AD group types (Microsoft 365 groups, Security groups, Dynamic groups), which is tested under the 'Manage identities and governance' domain of AZ-104 or SC-300 certifications.
Hotspot Question You have an Azure Active Directory (Azure AD) tenant that contains a user named User1 and the groups shown in the following table. In the tenant, you create the gr...
Azure Active DirectoryGroup TypesMicrosoft 365 GroupsGroup Membership - Question #46Implement and manage user identities
Hotspot Question You have an Azure Active Directory (Azure AD) tenant that contains an administrative unit named Department1. Department1 has the users shown in the Users exhibit....
Azure ADAdministrative UnitsRBACDelegated administration - Question #47Implement authentication and access management
Hotspot Question You have an Azure Active Directory (Azure AD) tenant that has Security defaults disabled. You are creating a conditional access policy as shown in the following ex...
conditional accesspolicy configurationsecurity defaultsnamed users - Question #48Implement access management for apps
Hotspot Question You have a Microsoft 365 tenant. Sometimes, users use external, third-party applications that require limited access to the Microsoft 365 data of the respective us...
Defender for Cloud AppsOAuth app policyapp permissionsemail access - Question #49Implement and manage hybrid identity - specifically publishing on-premises applications to Azure AD users using Azure AD Application Proxy (AZ-104 / AZ-500 / MS-100 domain: Identity and Access Management)
Hotspot Question You have an on-premises datacenter that contains the hosts shown in the following table. You have an Azure Active Directory (Azure AD) tenant that syncs to the Act...
Azure AD Application ProxyHybrid IdentityApplication PublishingNetwork Security / Firewall Rules - Question #50Implement access management for apps
Hotspot Question You have an Azure Active Directory (Azure AD) tenant that has the default App registrations settings. The tenant contains the users shown in the following table. Y...
app registrationuser assignmentRBAC rolesapplication permissions - Question #51Implement access management for apps
Hotspot Question You have a custom cloud app named App1 that is registered in Azure Active Directory (Azure AD). App1 is configured as shown in the following exhibit. Use the drop-...
enterprise app configurationuser assignment requiredapp visibilitysign-in settings