SC-300 · Question #445
Hotspot Question You have a Microsoft Entra tenant that contains two remote networks named RemoteNetwork1 and RemoteNetwork2 and the users shown in the following table. You have the devices shown in…
The correct answer is When User1 signs in to Microsoft Exchange Online, the user will be prompted for multifactor authentication (MFA). = Yes; When User2 signs in to Microsoft SharePoint Online, the user will be prompted for multifactor authentication (MFA). = No; When User3 signs in to Microsoft Exchange Online, the user will be prompted for multifactor authentication (MFA). = No. Here's the breakdown: 1. User1 and Microsoft Exchange Online (Yes): User1 is a member of Group1, which is targeted by CAPolicy1. The resource, Microsoft Exchange Online, is part of "All internet resources with Global Secure Access" targeted by the policy. User1 is on Device1…
Question
Hotspot Question You have a Microsoft Entra tenant that contains two remote networks named RemoteNetwork1 and RemoteNetwork2 and the users shown in the following table. You have the devices shown in the following table. You have a Conditional Access policy that has the following settings:
Name: CAPolicy1 Assignments
- Users: Group1, Group2
- Target resources: All internet resources with Global Secure
Access Access controls
- Grant: Require multifactor authentication
Enable policy: On Global Secure Access traffic forwarding is configured as shown in the following exhibit. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Answer:
Exhibits
Answer Area
- When User1 signs in to Microsoft Exchange Online, the user will be prompted for multifactor authentication (MFA).Yes
- When User2 signs in to Microsoft SharePoint Online, the user will be prompted for multifactor authentication (MFA).No
- When User3 signs in to Microsoft Exchange Online, the user will be prompted for multifactor authentication (MFA).No
Explanation
Here's the breakdown:
-
User1 and Microsoft Exchange Online (Yes):
- User1 is a member of Group1, which is targeted by CAPolicy1.
- The resource, Microsoft Exchange Online, is part of "All internet resources with Global Secure Access" targeted by the policy.
- User1 is on Device1, which has the Global Secure Access client deployed and is connected to RemoteNetwork1.
- The exhibit confirms that RemoteNetwork1 is configured for Global Secure Access traffic forwarding for Microsoft services.
- Since all conditions for CAPolicy1 are met, User1 will be prompted for multifactor authentication.
-
User2 and Microsoft SharePoint Online (No):
- User2 is a member of Group1, which is targeted by CAPolicy1.
- The resource, Microsoft SharePoint Online, is part of "All internet resources with Global Secure Access" targeted by the policy.
- User2 is on Device2, but Device2 explicitly states the Global Secure Access client is Not deployed.
- The Conditional Access policy targets resources with Global Secure Access. As the client is not deployed, traffic from User2 on Device2 will not be routed through Global Secure Access. Therefore, the policy's condition for the target resource is not met.
- MFA will not be prompted by this policy.
-
User3 and Microsoft Exchange Online (No):
- User3 is a member of Group2, which is targeted by CAPolicy1.
- The resource, Microsoft Exchange Online, is part of "All internet resources with Global Secure Access" targeted by the policy.
- User3 is on Device3, which has the Global Secure Access client deployed and is connected to RemoteNetwork2.
- However, the exhibit for "Global Secure Access traffic forwarding" only shows RemoteNetwork1 assigned for forwarding. There is no information indicating that RemoteNetwork2 is configured to forward traffic via Global Secure Access.
- Since the policy targets resources with Global Secure Access, and RemoteNetwork2 is not shown to be forwarding traffic through GSA, the policy's condition for the target resource is not met.
- MFA will not be prompted by this policy.
Community Discussion
No community discussion yet for this question.

