SC-300 · Question #149
You need to support the planned changes and meet the technical requirements for MFA. Which feature should you use, and how long before the users must complete the registration? To answer, select the…
The correct answer is Object type: An administrative unit; Role: Authentication administrator. This hotspot question tests knowledge of Azure AD Connect authentication methods, Azure AD Application Proxy, Microsoft Cloud App Security, and Azure Sentinel within a hybrid enterprise environment at Litware, Inc. Candidates must evaluate specific statements about the…
Question
Answer Area
- Object typeAn administrative unitAn administrative unitA custom administrator roleA dynamic groupA Microsoft 365 group
- RoleAuthentication administratorAuthentication administratorGroups administratorHelpdesk administratorPassword administrator
Explanation
This hotspot question tests knowledge of Azure AD Connect authentication methods, Azure AD Application Proxy, Microsoft Cloud App Security, and Azure Sentinel within a hybrid enterprise environment at Litware, Inc. Candidates must evaluate specific statements about the environment and determine whether each is True/False or Yes/No based on the described configuration.
Approach. To answer hotspot questions about this case study correctly, you must carefully cross-reference each statement against the environment details provided. Key facts to apply: (1) Azure AD Connect uses pass-through authentication with password hash synchronization DISABLED - meaning cloud-only features requiring password hash sync (like leaked credential detection in Identity Protection) will NOT work. (2) Guest accounts from fabrikam.com access litware.com resources, so B2B collaboration is in use. (3) All built-in anomaly detection policies in Microsoft Cloud App Security are enabled, covering behaviors like impossible travel and suspicious inbox rules. (4) Azure Sentinel is present in the subscription, enabling SIEM/SOAR capabilities. For each hotspot row, match the statement to these specific constraints - for example, any feature requiring password hash sync will be unavailable, and any feature covered by E5 licenses or enabled MCAS policies will be available.
Concept tested. Hybrid identity configuration trade-offs (pass-through authentication vs. password hash sync), Azure AD B2B guest access, Microsoft Cloud App Security anomaly detection, and Azure Sentinel capabilities in a Microsoft 365 E5 enterprise environment.
Reference. Microsoft Docs: Azure AD Connect authentication methods - https://docs.microsoft.com/en-us/azure/active-directory/hybrid/choose-ad-authn; Microsoft Cloud App Security anomaly detection policies - https://docs.microsoft.com/en-us/cloud-app-security/anomaly-detection-policy
Topics
Community Discussion
No community discussion yet for this question.