SC-300 Exam Questions
433 real SC-300 exam questions with expert-verified answers and explanations. Page 2 of 9.
- Question #52Implement access management for apps
Hotspot Question You have an Azure Active Directory (Azure AD) tenant that contains Azure AD Privileged Identity Management (PIM) role settings for the User administrator role as s...
Azure AD PIMApplication access controlRole-based assignmentOffice 365 app launcher - Question #54Plan and implement identity governance
You need to meet the planned changes for the User administrator role. What should you do?
PIM role settingsprivileged identity managementActive assignmentsleast privilege - Question #56Implement authentication and access management
You need to configure the MFA settings for users who connect from the Boston office. The solution must meet the authentication requirements and the access requirements. What should...
named locationsconditional accesspublic IP rangeVPN - Question #57Implement and manage user identities
You need to create the LWGroup1 group to meet the management requirements. How should you complete the dynamic membership rule? To answer, select the appropriate options in the ans...
Azure AD Dynamic GroupsUser ManagementUser PropertiesGroup Membership Rules - Question #58Implement access management for apps
You need to configure app registration in Azure AD to meet the delegation requirements. What should you do? To answer, select the appropriate options in the answer area. NOTE: Each...
App registrationAzure AD rolesLeast privilegeDelegation - Question #59Implement and manage user identities
You have an Azure Active Directory (Azure AD) tenant that contains the following objects. - A device named Devie1 - Users named User1, User2, User3, User4, and User5 - Five groups...
group-based licensingnested groupslicense assignmentAzure AD groups - Question #60Implement and manage user identities
You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains an Azure AD enterprise application named App1. A contractor uses the credentials of user1@outlo...
guest usersB2B collaborationexternal contractoridentity federation - Question #61Implement identity management solution
Your network contains an Active Directory forest named contoso.com that is linked to an Azure Active Directory (Azure AD) tenant named contoso.com by using Azure AD Connect. You ne...
Azure AD Connectsync rulesattribute filteringinbound synchronization - Question #62Implement identity management solution
Your network contains an on-premises Active Directory domain that syncs to an Azure Active Directory (Azure AD) tenant. The tenant contains the users shown in the following table....
pass-through authenticationpassword hash synchybrid identityconnectivity failure - Question #63Implement and manage user identities
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Azure AD Connecthybrid identityuser account syncActive Directory - Question #64Implement access management for apps
You have an Azure Active Directory (Azure AD) tenant. For the tenant, Users can register applications is set to No. A user named Admin1 must deploy a new cloud app named App1. You...
app registrationApplication developer roleleast privilegeRBAC - Question #65Implement authentication and access management
You have an Azure Active Directory (Azure AD) tenant named contoso.com that has Azure AD Identity Protection enabled. You need to implement a sign-in risk remediation policy withou...
sign-in risk policyIdentity ProtectionMFArisk remediation - Question #66Plan and implement identity governance
You have an Azure Active Directory (Azure AD) tenant named contoso.com. You implement entitlement management to provide resource access to users at a company named Fabrikam, Inc. F...
entitlement managementexternal user lifecycleaccess packagesidentity governance settings - Question #67Implement and manage user identities
You have an Azure Active Directory (Azure AD) tenant. You need to review the Azure AD sign-in logs to investigate sign-ins that occurred in the past. For how long does Azure AD sto...
sign-in logsaudit logslog retentionAzure AD monitoring - Question #68Plan and implement identity governance
You have an Azure subscription that contains the resources shown in the following table. For which resources can you create an access review?
access reviewsAzure AD groupsAzure rolesenterprise apps - Question #69Implement authentication and access management
You have an Azure Active Directory (Azure AD) tenant that uses conditional access policies. You plan to use third-party security information and event management (SIEM) to analyze...
audit logsconditional accessSIEM integrationAzure AD logs - Question #70Plan and implement identity governance
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
access reviewsreview scopeidentity governancegroup management - Question #71Implement and manage threat protection using Microsoft 365 Defender and Microsoft Cloud App Security - specifically configuring real-time session monitoring via Conditional Access App Control (CAAC)
Drag and Drop Question You have a Microsoft 365 E5 tenant. You purchase a cloud app named App1. You need to enable real-time session-level monitoring of App1 by using Microsoft Clo...
Microsoft Cloud App SecurityConditional Access App ControlSession PoliciesAzure AD Enterprise Applications - Question #72Manage identity and access in Microsoft Entra ID (Azure AD) - specifically configuring and managing enterprise application self-service access, approval workflows, and group ownership within a Microsoft 365 tenant.
Hotspot Question You have a Microsoft 365 tenant that contains a group named Group1 as shown in the Group1 exhibit. (Click the Group1 tab.) You create an enterprise application nam...
Azure AD Enterprise ApplicationsSelf-Service App AssignmentApp Provisioning and AccessMicrosoft 365 Identity Management - Question #73Implement authentication and access management
Hotspot Question You have a Microsoft 365 tenant and an Active Directory domain named adatum.com. You deploy Azure AD Connect by using the Express Settings. You need to configure s...
SSPRpassword writebackauthentication methodsAzure AD Connect - Question #74Plan and implement identity governance
You need to track application access assignments by using Identity Governance. The solution must meet the delegation requirements. What should you do first?
identity governanceentitlement managementprogramsaccess packages - Question #75Implement and manage user identities
You have an Azure Active Directory (Azure AD) tenant named contoso.com. You need to ensure that Azure AD External Identities pricing is based on monthly active users (MAU). What sh...
External IdentitiesMAU billinglinked subscriptionB2B - Question #76Implement authentication and access management
You have a Microsoft 365 tenant. All users have mobile phones and laptops. The users frequently work from remote locations that do not have Wi-Fi access or mobile phone connectivit...
MFAWindows Hello for Businessoffline authenticationauthentication methods - Question #77Implement authentication and access management
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
MFAMicrosoft Authenticatorconditional accessauthentication policies - Question #78Implement authentication and access management
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
MFAMicrosoft Authenticatorper-user MFAauthentication policies - Question #79Implement authentication and access management
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
MFAMicrosoft Authenticatorsecurity defaultsauthentication methods - Question #80Implement access management for apps
Your company requires that users request access before they can access corporate applications. You register a new enterprise application named MyApp1 in Azure Active Directory (Azu...
self-service accessenterprise applicationsaccess requestsSSO - Question #81Plan and implement identity governance
You have an Azure Active Directory (Azure AD) tenant that contains the objects shown in the following table. Which objects can you add as eligible in Azure AD Privileged Identity M...
PIMeligible assignmentsAzure AD rolesmanaged identity - Question #82Implement authentication and access management
You have an Azure Active Directory (Azure AD) tenant named contoso.com that has Azure AD Identity Protection policies enforced. You create an Azure Sentinel instance and configure...
Identity ProtectionAzure Sentinelrisk alertssecurity incidents - Question #83Implement and manage user identities
Hotspot Question Your network contains an on-premises Active Directory domain named contoso.com. The domain contains the objects shown in the following table. You install Azure AD...
Azure AD ConnectOU filteringdirectory synchronizationhybrid identity - Question #84Manage Microsoft 365 users and groups / Configure and manage Microsoft 365 tenant settings including custom domain setup
Drag and Drop Question You have a new Microsoft 365 tenant that uses a domain name of contoso.onmicrosoft.com. You register the name contoso.com with a domain registrar. You need t...
Microsoft 365 Admin CenterCustom Domain ConfigurationDNS VerificationDomain Management - Question #85Implement authentication and access management
Hotspot Question You have a Microsoft 365 tenant. You need to identify users who have leaked credentials. The solution must meet the following requirements: - Identify sign-ins by...
Identity Protectionleaked credentialssign-in risk policyconditional access - Question #86Implement authentication and access management
Hotspot Question You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table. You plan to implement Azure AD Identity Protection. Whic...
Identity Protectionuser risk policyRBACrisky users report - Question #87Implement access management for apps
Hotspot Question Your company has a Microsoft 365 tenant. All users have computers that run Windows 10 and are joined to the Azure Active Directory (Azure AD) tenant. The company s...
SSOOAuthenterprise applicationsconditional access - Question #88Plan and implement identity governance
Hotspot Question You have an Azure Active Directory (Azure AD) tenant that contains the following group: Name: Group1 Members: User1, User2 Owner: User3 On January 15, 2021, you cr...
Access ReviewsAzure AD RolesReview TimelineIdentity Governance - Question #89Plan and implement identity governance
Hotspot Question Your company has an Azure Active Directory (Azure AD) tenant named contoso.com. The company has a business partner named Fabrikam, Inc. Fabrikam uses Azure AD and...
entitlement managementaccess packagesconnected organizationsexternal collaboration - Question #90Implement and manage user identities
You need to allocate licenses to the new users from ADatum. The solution must meet the technical requirements. Which type of object should you create?
dynamic groupsmembership rulesAzure AD groupsguest exclusion - Question #91Implement authentication and access management
You need to implement password restrictions to meet the authentication requirements. You install the Azure AD password Protection DC agent on DC1. What should you do next? To answe...
password protectionbanned password listAzure AD Password ProtectionDC agent - Question #92Implement authentication and access management
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
MFAMicrosoft Authenticatorauthentication methodsConditional Access - Question #93Plan and implement identity governance
Hotspot Question You have an Azure Active Directory (Azure AD) tenant that contains three users named User1, User1, and User3. You create a group named Group1. You add User2 and Us...
PIMrole settingseligible assignmentapproval workflow - Question #94Implement authentication and access management
Hotspot Question You have a Microsoft 365 tenant. You configure a conditional access policy as shown in the Conditional Access policy exhibit. (Click the Conditional Access policy...
Conditional AccessPIMrole assignmentsMFA - Question #95Implement identity management solution
As the Azure Administrator for your organization, you need to create several security groups and populate those groups based on specific profile attributes of your users. As users...
Dynamic GroupsAzure AD Group ManagementAutomated Group Membership - Question #96Implement authentication and access management solution
Your organization has implemented Azure AD Connect to help support its Hybrid cloud initiatives and has synced all on-prem AD users to Azure AD. To meet organization compliance req...
Azure AD ConnectPass-through AuthenticationHybrid identityPassword policies - Question #97Plan and implement identity governance
Your company has an Azure Active Directory (Azure AD) tenant named contosri.com. The company has the business partners shown in the following table. Users can request access by usi...
Azure AD Entitlement ManagementConnected OrganizationsIdentity GovernanceExternal Identities - Question #98Implement authentication and access management
Hotspot Question You have an Azure subscription. You need to create two custom roles named Role1 and Role2. The solution must meet the following requirements: - Users that are assi...
custom rolesRBACresource provider permissionsAzure Container Apps - Question #99Implement access management for apps
The Azure Active Directory (Azure AD) tenant contains the groups shown in the following table. In Azure AD, you add a new enterprise application named App1. Which groups can you as...
enterprise applicationsgroup assignmentAzure AD groupssecurity groups - Question #100Implement access management for apps
You have a Microsoft 365 E5 subscription. You need to create a Microsoft Defender for Cloud Apps session policy. What should you do first?
Defender for Cloud Appssession policyConditional Accessapp control - Question #101Implement authentication and access management
You have an Azure Active Directory (Azure AD) tenant. You configure self-service password reset (SSPR) by using the following settings: - Require users to register when signing in:...
SSPRauthentication methodsmobile app codeself-service password reset - Question #102Implement and manage user identities
Your organization wants to take advantage of group based licensing, allowing various licenses to be automatically assigned to users based on security groups that they are a part of...
Group-based licensingAzure AD P1LicensingMicrosoft Entra ID - Question #103Implement authentication and access management
factor authentication for all of your users. In preparation for this, you need to ensure that all users are properly registered for multi-factor Authentication. Of the choices belo...
Multi-factor AuthenticationAuthentication methodsAzure AD MFA