nerdexam
Microsoft

SC-300 · Question #426

Hotspot Question You have a Microsoft 365 E5 subscription that contains two attribute sets named Set1 and Set2. The subscription contains the users shown in the following table. You have the custom…

The correct answer is User1 can read the contents of blob3. = No; User1 can read the contents of blob2. = Yes; User2 can read the contents of blob1. = Yes. User3 has the Attribute Assignment Reader role (implied by the scenario context), which grants read access to custom security attribute values across all users, making statement 3 'Yes'. User1 cannot modify Secure1's configuration because modifying attribute definitions…

Submitted by jian89· Mar 6, 2026Manage identities and governance in Microsoft 365 - specifically implementing and managing custom security attributes and delegated administrative roles in Microsoft Entra ID (Azure Active Directory)

Question

Hotspot Question You have a Microsoft 365 E5 subscription that contains two attribute sets named Set1 and Set2. The subscription contains the users shown in the following table. You have the custom security attributes shown in the following table. You assign User2 the Attribute Definition Administrator role for Set1. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Answer:

Exhibits

SC-300 question #426 exhibit 1
SC-300 question #426 exhibit 2

Answer Area

  • User1 can read the contents of blob3.No
  • User1 can read the contents of blob2.Yes
  • User2 can read the contents of blob1.Yes

How the community answered

(2 responses)
  • Yes|No|Yes
    50% (1)
  • Yes|Yes|No
    50% (1)

Explanation

User3 has the Attribute Assignment Reader role (implied by the scenario context), which grants read access to custom security attribute values across all users, making statement 3 'Yes'. User1 cannot modify Secure1's configuration because modifying attribute definitions requires the Attribute Definition Administrator role scoped to Set1 (where Secure1 resides), and User1 lacks this role. User2 is assigned the Attribute Definition Administrator role scoped only to Set1, which allows managing attribute definitions in Set1 but does NOT grant the ability to view attribute values - viewing values requires the Attribute Assignment Reader or Attribute Assignment Administrator role; additionally, Secure2 belongs to Set2, outside User2's scope entirely.

Topics

#Custom Security Attributes#Azure AD RBAC#Attribute Definition Administrator#Microsoft Entra ID Governance

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice