SC-300 Exam Questions
433 real SC-300 exam questions with expert-verified answers and explanations. Page 4 of 9.
- Question #158Implement authentication and access management
You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table. The tenant has the authentication methods shown in the following table. W...
authentication methodsnumber matchingMicrosoft AuthenticatorMFA - Question #159Implement authentication and access management
You have an Azure Active Directory (Azure AD) tenant that contains a user named User1 and the conditional access policies shown in the following table. You need to evaluate which p...
Conditional AccessWhat If toolpolicy evaluationsign-in simulation - Question #160Implement authentication and access management
You have a Microsoft 365 tenant. All users have mobile phones and Windows 10 laptops. The users frequently work from remote locations that do not have Wi-Fi access or mobile phone...
MFA methodsWindows Hello for Businessoffline authenticationpasswordless - Question #161Implement authentication and access management
You create a conditional access policy that blocks access when a user triggers a high-severity sign-in alert. You need to test the policy under the following conditions: - A user s...
Conditional AccessWhat If toolsign-in riskpolicy testing - Question #163Manage Azure Active Directory (Azure AD) identities - specifically configuring and managing external guest user authentication methods including Email One-Time Passcode under the Microsoft Entra ID / Azure AD External Identities domain (AZ-104 / SC-300).
Hotspot Question You have an Azure Active Directory (Azure AD) tenant named contoso.com that has Email one- time passcode for guests set to Yes. You invite the guest users shown in...
Azure AD B2B CollaborationEmail One-Time PasscodeGuest User AuthenticationExternal Identities - Question #164Implement access management for apps
You have an Azure Active Directory (Azure AD) tenant that contains the users shown in, the following table. The User settings for enterprise applications have the following configu...
admin consententerprise applicationsconsent policiesdelegated permissions - Question #165Implement authentication and access management
You have a Microsoft 365 subscription. The subscription contains users that use Microsoft Outlook 2016 and Outlook 2013 clients. You need to implement tenant restrictions. The solu...
tenant restrictionsmodern authenticationlegacy clientsOutlook compatibility - Question #166Plan and implement identity governance
Hotspot Question Your network contains an on-premises Active Directory domain that syncs to an Azure Active Directory (Azure AD) tenant. The tenant contains the groups shown in the...
access reviewsdirectory synchybrid identitygroup membership - Question #167Plan and implement identity governance
You have a Microsoft 365 E5 subscription that contains a web app named App1. Guest users are regularly granted access to App1. You need to ensure that the guest users that have NOT...
access reviewsguest usersapplication accesslifecycle management - Question #168Plan and implement identity governance
Hotspot Question You have an Azure Active Directory (Azure AD) ten-ant: that contains the groups shown in the following table. You create an access review for Group1 as shown in th...
Azure AD Premium P2Access ReviewsIdentity GovernanceLicensing - Question #169Plan and implement identity governance
Hotspot Question You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains a group named. All Company and has the following Identity Governance settings:...
Access PackagesIdentity GovernanceExternal User LifecycleGuest User Management - Question #170Plan and implement identity governance
You have an Azure Active Directory (Azure AD) tenant named Contoso that contains a terms of use (Toll) named Terms1 and an access package. Contoso users collaborate with an externa...
terms of useaudit logsentitlement managementaccess packages - Question #171Plan and implement identity governance
You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table. User1 is the owner of Group1. You create an access review that has the fo...
access reviewsreviewer scopeself-reviewgroup owners - Question #172Plan and automate identity governance
Hotspot Question You have a Microsoft 365 E5 subscription. You create an access review for Azure Active Directory (Azure AD) roles. You need to ensure that users who do not respond...
access reviewsauto-apply resultsreviewer non-responseAzure AD roles - Question #173Implement authentication and access management
How should the access be setup to the on-premises applications? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Answe...
Azure AD Password Protectionbanned password listproxy serviceon-premises integration - Question #174Implement and manage user identities
You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table. You have an administrative unit named Au1. Group1, User2, and User3 are m...
administrative unitsUser administrator rolescoped permissionsgroup membership scope - Question #175Implement and manage user identities
You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table. You create a dynamic user group and configure the following rule syntax....
dynamic groupsmembership rulesrule syntaxoperator precedence - Question #176Implement and manage user identities
You have an Azure AD tenant that contains a user named User1. User1 needs to manage license assignments and reset user passwords. Which role should you assign to User1?
RBAC rolesUser administratorlicense assignmentpassword reset - Question #177Implement and manage user identities
You have 2,500 users who are assigned Microsoft Office 365 Enterprise E3 licenses. The licenses are assigned to individual users. From the Groups blade in the Azure Active Director...
license managementgroup-based licensingbulk operationsPowerShell - Question #179Implement and manage user identities
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Identity Secure ScoreSecurity administratorrole assignmentimprovement actions - Question #180Implement and manage user identities
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Identity Secure ScoreSecurity administratorrole assignmentimprovement actions - Question #181Implement authentication and access management
You have a Microsoft 365 tenant. You currently allow email clients that use Basic authentication to connect to Microsoft Exchange Online. You need to ensure that users can connect...
Conditional Accessbasic authenticationmodern authenticationclient app conditions - Question #182Plan and implement workload identities
You have an Azure subscription that contains an Azure SQL database named db1. You deploy an Azure App Service web app named App1 that provides product information to users that con...
Managed IdentitiesAzure App ServiceAzure SQL DatabaseWorkload Identity - Question #183Manage Azure identities and governance - specifically managing access to Azure resources using managed identities and role-based access control (RBAC), covered under AZ-104 Objective: Manage Azure Active Directory (Entra ID) identities and secure access.
Hotspot Question You have an Azure subscription that contains the following virtual machine: - Name: V1 - Azure region: East US - System-assigned managed identity: Disabled You cre...
Managed IdentitiesAzure RBACUser-Assigned IdentityAzure Virtual Machines - Question #184Manage Azure identities and governance - specifically managing access control using role-based access control (RBAC) and managed identities in Azure subscriptions and resource groups.
Hotspot Question You have an Azure subscription that contains the key vaults shown in the following table. The subscription contains the users shown in the following table. On June...
Managed IdentitiesAzure RBACKey VaultAzure Active Directory - Question #185Implement authentication and access management
You have an Azure AD tenant. You open the risk detections report. Which risk detection type is classified as a user risk?
risk detectionsuser risksign-in riskAzure AD Identity Protection - Question #186Implement authentication and access management
You have an Azure Active Directory (Azure AD) tenant. You configure self-service password reset (SSPR) by using the following settings: - Require users to register when signing in:...
SSPRauthentication methodsmobile app codeself-service password reset - Question #187Implement authentication and access management
You create a new Microsoft 365 E5 tenant. You need to ensure that when users connect to the Microsoft 365 portal from an anonymous IP address, they are prompted to use multi-factor...
sign-in risk policyanonymous IPMFA enforcementIdentity Protection - Question #188Implement authentication and access management solution
Hotspot Question You have an Azure AD tenant that contains the users shown in the following table. You have the Azure AD Identity Protection policies shown in the following table....
Azure AD Identity ProtectionRisky UsersRisky Sign-insMFA enforcement - Question #189Implement access management for apps
You have an Azure subscription that contains a user named User1. You need to meet the following requirements: - Prevent User1 from being added as an owner of newly registered apps....
Application Administrator roleapp proxy settingsapp registrationprinciple of least privilege - Question #190Manage Azure identities and governance – specifically, managing access to Azure resources using role-based access control and integrating Azure AD authentication with Azure compute services.
Drag and Drop Question You have a Microsoft 365 E5 subscription and an Azure subscription. You need to meet the following requirements: - Ensure that users can sign in to Azure vir...
Azure RBACAzure Virtual MachinesIdentity and Access ManagementAzure AD Authentication - Question #191Implement and manage user identities
Hotspot Question Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure AD tenant. The AD DS domain contains the organization...
break-glass accountsAzure ADrole assignmentemergency access - Question #192Plan and implement identity governance
You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1. You need to ensure that users can request access to Site1. The solution must...
access packagesentitlement managementauto-approvaltime-limited access - Question #194Implement and manage threat protection using Microsoft Defender for Cloud Apps - specifically configuring Conditional Access App Control for real-time session monitoring (Microsoft SC-400 / MS-500 / Microsoft 365 Security domain)
Drag and Drop Question You have a Microsoft 365 E5 tenant. You purchase a cloud app named App1. You need to enable real-time session-level monitoring of App1 by using Microsoft Def...
Microsoft Defender for Cloud AppsConditional Access App ControlSession PoliciesAzure AD App Registration - Question #195Implement access management for apps
You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table. You add an enterprise application named App1 to Azure AD and set User1 as...
admin consent requestsconsent reviewersenterprise applicationsrole eligibility - Question #196Implement authentication and access management
You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1. You need to be notified if a user downloads more than 50 files in one minute...
activity policyDefender for Cloud Appsfile download monitoringthreshold alerts - Question #197Implement authentication and access management
You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1. Site1 hosts PDF files. You need to prevent users from printing the files dire...
session policyDefender for Cloud Appsreal-time content controlSharePoint - Question #198Implement authentication and access management
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Cloud Apps and Conditional Access policies. You need to block access to cloud apps when a user is assessed...
access policyDefender for Cloud Appsrisk-based accessConditional Access - Question #199Implement access management for apps
You have a Microsoft 365 E5 subscription. Users authorize third-party cloud apps to access their data. You need to configure an alert that will be triggered when an app requires hi...
OAuth app policyDefender for Cloud Appsthird-party app riskpermission scope - Question #200Implement access management for apps
Your company has an Azure AD tenant that contains the users shown in the following table. You have the app registrations shown in the following table. A company policy prevents cha...
app permissionsMicrosoft Graphapplication permissionscalendar access - Question #201Implement access management for apps
You have an Azure AD tenant that contains a user named User1 and a registered app named App1. User1 deletes the app registration of App1. You need to restore the app registration....
app registrationdeleted objects recoverysoft deleteretention period - Question #202Manage Azure Active Directory identities - specifically understanding group types (Security vs Microsoft 365), membership types (Assigned vs Dynamic), and which identity types (users, managed identities, service principals) can be added to each group type. This aligns with the AZ-104 or SC-300 domain covering identity and access management in Azure AD.
Hotspot Question You have an Azure AD tenant that contains the groups shown in the following exhibit. Use the drop-down menus to select the answer choice that completes each statem...
Azure AD GroupsManaged IdentitiesSecurity GroupsMicrosoft 365 Groups - Question #203Implement authentication and access management
You have an Azure AD tenant that contains two users named User1 and User2. You plan to perform the following actions: - Create a group named Group1. - Add User1 and User2 to Group1...
Azure AD GroupsRole-assignable groupsGroup typesAzure AD roles - Question #204Implement and manage identity and access in Azure AD / Monitor and maintain Azure AD (Microsoft SC-300 / MS-500)
Drag and Drop Question You have a Microsoft 365 E5 subscription. You need to perform the following tasks: - Identify the locations and IP addresses used by Azure AD users to sign i...
Azure AD MonitoringIdentity Secure ScoreSign-in LogsAudit Logs - Question #207Implement authentication and access management solution
You have the Azure resources shown in the following table. To which identities can you assign the Contributor role for RG1?
Azure RBACManaged IdentitiesAccess ManagementAzure Identities - Question #208Implement and manage user identities
You have 2,500 users who are assigned Microsoft Office 365 Enterprise E3 licenses. The licenses are assigned to individual users. From the Groups blade in the Azure Active Director...
Azure AD LicensingGroup-based LicensingLicense ManagementAdministrative Efficiency - Question #209Plan and implement identity governance
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Identity Secure Scoreimprovement actionsrole assignmentsecurity posture - Question #210Plan and implement identity governance
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
Identity Secure Scoreimprovement actionsrole assignmentsecurity posture - Question #211Implement and manage user identities
You have an Azure AD tenant that contains a user named Admin1. You need to ensure that Admin1 can perform only the following tasks: - From the Microsoft 365 admin center, create an...
Helpdesk Administratorrole assignmentservice healthsupport ticket management - Question #213Implement authentication and access management
Hotspot Question Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure AD tenant. You need to ensure that user authenticatio...
pass-through authenticationAzure AD Connecthybrid identityon-premises AD DS