SC-300 Exam Questions
433 real SC-300 exam questions with expert-verified answers and explanations. Page 5 of 9.
- Question #214Implement access management for apps
A user named User1 receives an error message when attempting to access the Microsoft Defender for Cloud Apps portal. You need to identify the cause of the error. The solution must...
Sign-in logsTroubleshooting accessAzure AD logsApplication access - Question #215Implement authentication and access management
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Cloud Apps and Yammer. You need prevent users from signing in to Yammer from high-risk locations. What sho...
access policyDefender for Cloud Appslocation-based access controlYammer - Question #216Implement authentication and access management
You have an Azure Active Directory (Azure AD) tenant. You configure self-service password reset (SSPR) by using the following settings: - Require users to register when signing in:...
SSPRauthentication methodsexternal email verificationself-service password reset - Question #217Implement access management for apps
You have an Azure AD tenant. You configure User consent settings to allow users to provide consent to apps from verified publishers. You need to ensure that the users can only prov...
permission classificationsuser consentlow-impact permissionsverified publishers - Question #218Implement access management for apps
Hotspot Question You have a Microsoft 365 E5 subscription that contains a user named User1. You configure app governance integration. User1 needs to view the App governance dashboa...
app governanceCloud Application AdministratorMicrosoft 365 Defender portalleast privilege - Question #219Implement access management for apps
You have an Azure subscription. You are evaluating enterprise software as a service (SaaS) apps. You need to ensure that the apps support automatic provisioning of Azure AD users....
SCIM 2.0automatic user provisioningSaaS appsprovisioning protocol - Question #220Plan and implement identity governance
You have a Microsoft 365 E5 subscription that contains a user named User1. You need to ensure that User1 can create access reviews for Azure AD roles. The solution must use the pri...
access reviewsPIMleast privilegeAzure AD roles - Question #221Plan and implement identity governance
Hotspot Question You have a Microsoft 365 E5 subscription that contains three users named User1, User2, and User3. You have two Azure AD roles that have the Activation settings sho...
PIM activation settingsrole assignmentjustificationapproval workflow - Question #222Implement access management for apps
Hotspot Question You have a hybrid Microsoft 365 subscription that contains the users shown in the following table. You plan to deploy an on-premises app named App1. App1 will be r...
Application Proxyleast privilegeapp registrationAzure AD roles - Question #223Implement and manage user identities
Hotspot Question You have a Microsoft 365 E5 subscription that contains the users shown in the following table. The users are assigned the roles shown in the following table. For w...
password resetrole permissionsUser AdministratorPrivileged Role Administrator - Question #224Implement access management for apps
You have a Microsoft 365 E5 subscription that contains a user named User1. User is eligible for the Application administrator role. User1 needs to configure a new connector group f...
Azure AD RolesRole ManagementApplication ProxyAdmin Portals - Question #225Implement access management for apps
You have an Azure subscription that contains a registered app named App1. You need to review the sign-in activity for App1. The solution must meet the following requirements: - Ide...
Sign-in monitoringApplication usageReportingAzure AD monitoring - Question #226Implement identity management solution
Your company has an Azure AD tenant that contains a user named User1. The company has two departments named marketing and finance. You need to grant permissions to User1 to manage...
Administrative UnitsDelegated AdministrationAzure ADUser Management - Question #227Plan and implement identity governance
You have an Azure AD tenant that contains an access package named Package1 and a user named User1. Package1 is configured as shown in the following exhibit. You need to ensure that...
access packagesentitlement managementleast privilegereview frequency - Question #228Implement authentication and access management
Hotspot Question You have an Azure subscription. Azure AD logs are sent to a Log Analytics workspace. You need to query the logs and graphically display the number of sign-ins per...
Log AnalyticsKQLsign-in logsdata visualization - Question #229Implement access management for apps
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Cloud Apps. You need to identify which users access Facebook from their devices and browsers. The solution...
Defender for Cloud Appsshadow ITapp discoveryunsanction apps - Question #230Plan and implement identity governance
You have an Azure subscription that uses Azure AD Privileged Identity Management (PIM). You need to identify users that are eligible for the Cloud Application Administrator role. W...
Azure AD PIMPrivileged Access GroupsRole AssignmentIdentity Governance - Question #231Implement and manage user identities
Hotspot Question You have a Microsoft 365 E5 subscription. You need to create a dynamic user group that will include all the users that do NOT have a department defined in their us...
dynamic groupsmembership rulesnull valuesuser attributes - Question #232Implement and manage user identities
You have 2,500 users who are assigned Microsoft Office 365 Enterprise E3 licenses. The licenses are assigned to individual users. From the Groups blade in the Azure Active Director...
Azure AD User LicensingGroup-Based LicensingLicense ManagementAdministrative Effort - Question #233Implement and manage user identities
You have an Azure AD tenant that contains the users shown in the following table. You need to compare the role permissions of each user. The solution must minimize administrative e...
role permissionsMicrosoft Entraadmin centerleast privilege - Question #234Implement and manage user identities
You have a Microsoft Exchange organization that uses an SMTP address space of contoso.com. Several users use their contoso.com email address for self-service sign-up to Azure AD. Y...
self-service sign-upPowerShelltenant managementpermission grant policy - Question #235Implement authentication and access management
You have an Azure AD tenant that has multi-factor authentication (MFA) enforced and self- service password reset (SSPR) enabled. You enable combined registration in interrupt mode....
MFASSPRcombined registrationauthentication methods - Question #236Implement authentication and access management solution
You have a Microsoft 365 tenant. All users have mobile phones and Windows 10 laptops. The users frequently work from remote locations that do not have Wi-Fi access or mobile phone...
Multi-factor authenticationWindows Hello for BusinessAuthentication methodsRemote access - Question #237Implement authentication and access management
You have a Microsoft 365 tenant. You currently allow email clients that use Basic authentication to connect to Microsoft Exchange Online. You need to ensure that users can connect...
Conditional AccessModern authenticationBasic authenticationExchange Online - Question #238Implement authentication and access management
You plan to deploy a new Azure AD tenant. Which multifactor authentication (MFA) method will be enabled by default for the tenant?
MFAMicrosoft Authenticatorsecurity defaultsauthentication methods - Question #239Implement authentication and access management
You have a Microsoft 365 E5 subscription that contains three users named User1, User2, and User3 and a Microsoft SharePoint Online site named Site1. The subscription contains the d...
Conditional Accessapp enforced restrictionsunmanaged devicesSharePoint - Question #240Implement authentication and access management
You have an Azure AD tenant named contoso.com that contains the resources shown in the following table. You create a user named Admin1. You need to ensure that Admin1 can enable Se...
Security defaultsConditional Accessprerequisitetenant configuration - Question #241Implement access management for apps
You have an Azure AD tenant and a .NET web app named App1. You need to register App1 for Azure AD authentication. What should you configure for App1?
Azure AD App RegistrationWeb App AuthenticationRedirect URIMicrosoft Entra ID - Question #242Implement authentication and access management solution
You have a Microsoft 365 tenant. All users have mobile phones and Windows 10 laptops. The users frequently work from remote locations that do not have Wi-Fi access or mobile phone...
Multi-factor authenticationWindows Hello for BusinessAuthentication methodsRemote access - Question #243Implement access management for apps
You have an Azure AD tenant. You discover that a large number of new apps were added to the tenant. You need to implement an approval process for new enterprise applications. What...
Admin consentEnterprise applicationsApplication governanceConsent workflow - Question #244Implement access management for apps
You have a Microsoft 365 E5 subscription. You purchase the app governance add-on license. You need to enable app governance integration. Which portal should you use?
App governanceMicrosoft 365 DefenderCloud App SecuritySecurity portal - Question #245Implement access management for apps
Your company purchases a new Microsoft 365 E5 subscription and an app named App1. You need to create a Microsoft Defender for Cloud Apps access policy for App1. What should you do...
Microsoft Defender for Cloud AppsConditional AccessConditional Access App ControlSession Control - Question #246Implement access management for apps
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
multi-cloudDefender for Cloud AppsAWSGoogle Workspace - Question #247Implement access management for apps
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
multi-cloudDefender for Cloud AppsAWSGoogle Workspace - Question #248Implement access management for apps
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
multi-cloudDefender for Cloud AppsAWSGoogle Workspace - Question #249Implement access management for apps
Your company purchases a Microsoft 365 E5 subscription. A user named User1 is assigned the Security Administrator role. You need to ensure that User1 can create Microsoft Defender...
Defender for Cloud Appssession policiesConditional Access App Controlprerequisites - Question #250Implement identity management solution
You have an Azure AD Premium P2 tenant. You create a Log Analytics workspace. You need to ensure that you can view Azure AD audit log information by using Azure Monitor. What shoul...
Azure AD LogsAzure MonitorLog AnalyticsDiagnostic Settings - Question #251Implement access management for apps
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Cloud Apps. You need to identify which users access Facebook from their devices and browsers. The solution...
Defender for Cloud AppsCloud App DiscoveryUnsanctioned AppsApp Monitoring - Question #252Implement and manage user identities
You have a Microsoft 365 subscription that contains the users shown in the following table. From the tenant, you configure a naming policy for groups. Which users are affected by t...
group naming policyAzure AD groupsMicrosoft 365 groupsGlobal Administrator exemption - Question #253Implement and Manage Identity Synchronization with Azure AD Connect - covering authentication methods (PHS, PTA, Federation), SSPR with Password Writeback, and OU/Domain filtering to control which on-premises objects are synchronized to Azure AD.
Hotspot Question Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with Azure AD and contains the users shown in the following table....
Azure AD ConnectSelf-Service Password Reset (SSPR)Password Hash SynchronizationOU Filtering - Question #254Implement authentication and access management
Hotspot Question You have an Azure subscription that contains the resources shown in the following table. You need to configure access to Vault1. The solution must meet the followi...
Key Vault RBACKey Vault Crypto OfficerKey Vault Certificate Userleast privilege - Question #255Implement and manage identity and access in Azure AD - specifically configuring Conditional Access policies and understanding default policy template behaviors to protect against identity risks while maintaining administrative access.
Drag and Drop Question You have an Azure AD tenant that contains a user named Admin1. Admin1 uses the Require password change for high-risk users policy template to create a new Co...
Conditional AccessAzure AD Identity ProtectionRisk-based policiesPolicy templates - Question #256Implement and manage identity and access in Microsoft Entra ID - specifically configuring and troubleshooting Conditional Access policies including device filter conditions, grant controls, and policy scoping for Microsoft 365 services.
Hotspot Question You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1 and the users shown in the following table. The users have th...
Conditional AccessSharePoint OnlineDevice FiltersMFA - Question #257Implement and Manage Identity and Access - specifically configuring managed identities for Azure resources and managing Azure AD group membership using PowerShell
Drag and Drop Question You have an Azure subscription that is linked to an Azure AD tenant named contoso.com. The subscription contains a group named Group1 and a virtual machine n...
Managed IdentityAzure PowerShellAzure AD GroupsVirtual Machines - Question #258Implement and manage user identities
Hotspot Question You have an Azure AD tenant. You need to configure the following External Identities features: - B2B collaboration - Monthly active users (MAU)-based pricing Which...
B2B collaborationExternal IdentitiesMAU pricingAzure AD External Identities - Question #259Implement and manage user identities
You have an Azure AD tenant that contains the external user shown in the following exhibit. You update the email address of the user. You need to ensure that the user can authentic...
B2B guest usersredemption statusexternal user authenticationExternal Identities - Question #260Implement and manage user identities
You have an Azure AD tenant. You need to ensure that only users from specific external domains can be invited as guests to the tenant. Which settings should you configure?
Azure AD guest invitationsExternal collaborationB2B collaborationGuest user management - Question #261Plan and implement identity governance
You have an Azure AD tenant that contains a user named User1 and a Microsoft 365 group named Group1. User1 is the owner of Group1. You need to ensure that User1 is notified every t...
access reviewsguest membershipMicrosoft 365 groupsperiodic review - Question #262Implement access management for apps
You have an Azure AD tenant. You deploy a new enterprise application named App1. When users attempt to provide App1 with access to the tenant, the attempt fails. You need to ensure...
admin consententerprise applicationsconsent workflowapp permissions - Question #263Implement authentication and access management
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some q...
MFAMicrosoft Authenticatorauthentication methodsMicrosoft 365