SC-300 · Question #127
Hotspot Question You have an Azure Active Directory (Azure AD) tenant that has multi-factor authentication (MFA) enabled. The account lockout settings are configured as shown in the following…
The correct answer is A user account will be locked out if the user enters the wrong [...] three times.: authentication method; If a user account is locked, the user can sign in again successfully after [...] minutes.: 60. This question assesses understanding of Azure Active Directory (Azure AD) Multi-Factor Authentication (MFA) account lockout settings based on the provided exhibit. Statement 1: A user account will be locked out if the user enters the wrong [...] three times. (Answer…
Question
Hotspot Question You have an Azure Active Directory (Azure AD) tenant that has multi-factor authentication (MFA) enabled. The account lockout settings are configured as shown in the following exhibit. Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic. NOTE: Each correct selection is worth one point. Answer:
Exhibit
Answer Area
- A user account will be locked out if the user enters the wrong [...] three times.authentication methodauthentication methodPINauthenticator app code
- If a user account is locked, the user can sign in again successfully after [...] minutes.603060
Explanation
This question assesses understanding of Azure Active Directory (Azure AD) Multi-Factor Authentication (MFA) account lockout settings based on the provided exhibit.
Statement 1: A user account will be locked out if the user enters the wrong [...] three times. (Answer: authentication method)
The exhibit's 'Account lockout' settings clearly state: 'Number of MFA denials to trigger account lockout: 3'. The note associated with these settings specifies that this feature applies to 'denied authentication attempts'. An MFA denial occurs when a user fails to correctly provide their chosen multi-factor authentication 'authentication method' (e.g., wrong PIN, incorrect app approval). Therefore, entering the wrong authentication method three times will lead to an account lockout.
Statement 2: If a user account is locked, the user can sign in again successfully after [...] minutes. (Answer: 60)
When a user account is locked due to too many MFA denials, the ability to 'sign in again successfully' depends on the lockout counter being reset. The exhibit shows 'Minutes until account lockout counter is reset: 60'. This setting dictates that after the last failed attempt, the system waits 60 minutes before clearing the count of failed MFA denials. Once the counter is reset, the user can then make new attempts to sign in. While there is also a 'Minutes until account is automatically unblocked: 30' setting, the 'Minutes until account lockout counter is reset' is the critical duration that allows for a successful sign-in by clearing the history of failed attempts.
Topics
Community Discussion
No community discussion yet for this question.
