nerdexam
Microsoft

SC-300 · Question #393

Drag and Drop Question Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that runs Windows Server and hosts a shared…

The correct answer is Install a connector on Server1.; Create an enterprise application.; Create an application segment. To enable Global Secure Access (Microsoft Entra Private Access) for an on-premises shared folder, you must first install a Microsoft Entra Private Network Connector on Server1 (or a server with access to it) to establish the outbound tunnel back to Microsoft's network. Next…

Submitted by parkjh· Mar 6, 2026Implement and manage Microsoft Entra Internet Access and Microsoft Entra Private Access (Global Secure Access) - typically found in SC-100, MS-102, or SC-200 certification tracks covering Microsoft 365 security and identity.

Question

Drag and Drop Question Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that runs Windows Server and hosts a shared folder named Share1. The domain contains 500 devices that run Windows 11. You have a Microsoft 365 E5 subscription that syncs with the domain. From Global Secure Access, you enable the Private access profile and deploy the Global Secure Access client to all the devices. You need to ensure that the devices can connect to Share1 remotely by using Global Secure Access. Which three actions should you perform in sequence? To answer move the appropriate actions from the list of actions to the answer area and arrange them in the correct order. Answer:

Answer Area

Drag items

Create an enterprise application.Create an application segment.Allow internet inbound traffic on TCP 443 to Server1.Install a connector on Server1.Create an app protection policy.

Correct arrangement

  • Install a connector on Server1.
  • Create an enterprise application.
  • Create an application segment.

Explanation

To enable Global Secure Access (Microsoft Entra Private Access) for an on-premises shared folder, you must first install a Microsoft Entra Private Network Connector on Server1 (or a server with access to it) to establish the outbound tunnel back to Microsoft's network. Next, you create an Enterprise Application in Entra ID to represent the private resource. Finally, you create an Application Segment within that enterprise application to define the specific FQDN/IP and port (e.g., SMB port 445) for Share1, which tells Global Secure Access which traffic to route through the connector. This sequence follows the required dependency order: connector → enterprise app → application segment.

Topics

#Microsoft Entra Private Access#Global Secure Access#Private Network Connector#Zero Trust Networking

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice