SC-300 · Question #91
You need to implement password restrictions to meet the authentication requirements. You install the Azure AD password Protection DC agent on DC1. What should you do next? To answer, select the…
The correct answer is Configure the Azure AD Password Protection proxy service on:: DC1; Configure the password list:: In Azure AD. This hotspot question tests knowledge of Azure AD Connect authentication methods, Azure AD Application Proxy, Microsoft Cloud App Security, and Azure Sentinel configurations within a hybrid identity environment at Litware, Inc. Candidates must evaluate specific statements about…
Question
Exhibit
Answer Area
- Configure the Azure AD Password Protection proxy service on:DC1DC1SERVER1SERVER2
- Configure the password list:In Azure ADIn Azure ADOn DC1On SERVER1On SERVER2
How the community answered
(1 responses)- DC1|In Azure AD100% (1)
Explanation
This hotspot question tests knowledge of Azure AD Connect authentication methods, Azure AD Application Proxy, Microsoft Cloud App Security, and Azure Sentinel configurations within a hybrid identity environment at Litware, Inc. Candidates must evaluate specific statements about the environment and determine whether each is True/False or Yes/No based on the described configuration.
Approach. To answer hotspot questions in this case study correctly, you must carefully cross-reference each statement against the environmental details provided. Key facts to anchor answers include: (1) Azure AD Connect uses pass-through authentication with password hash synchronization DISABLED - meaning leaked credential detection in Azure AD Identity Protection will NOT work, since it requires password hash sync; (2) Fabrikam users access Litware resources via guest accounts (B2B), so they are subject to Litware's Conditional Access policies for guest users; (3) All built-in anomaly detection policies in Microsoft Cloud App Security are enabled, meaning behaviors like impossible travel and activity from anonymous IPs are actively monitored; (4) Azure AD Application Proxy is implemented, enabling on-premises apps to be published securely without a VPN for external users. Each hotspot row must be evaluated by matching the stated condition precisely to these environmental constraints.
Concept tested. Hybrid identity architecture evaluation including Azure AD Connect authentication modes (pass-through authentication vs. password hash sync), implications for Identity Protection features, Azure AD B2B guest access, Microsoft Cloud App Security anomaly detection policies, and Azure AD Application Proxy capabilities in a real-world enterprise scenario.
Reference. Microsoft Documentation: Azure AD Connect authentication methods - https://docs.microsoft.com/en-us/azure/active-directory/hybrid/choose-ad-authn; Azure AD Identity Protection leaked credentials detection requires password hash sync - https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/concept-identity-protection-risks
Topics
Community Discussion
No community discussion yet for this question.
