ExamGecko
Home Home / Microsoft / SC-300

Microsoft SC-300 Practice Test - Questions Answers, Page 10

Question list
Search
Search

List of questions

Search

Related questions











Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have a Microsoft 365 tenant.

You have 100 IT administrators who are organized into 10 departments.

You create the access review shown in the exhibit. (Click the Exhibit tab.)

You discover that all access review requests are received by Megan Bowen.

You need to ensure that the manager of each department receives the access reviews of their respective department.

Solution: You add each manager as a fallback reviewer.

Does this meet the goal?

A.

Yes

A.

Yes

Answers
B.

No

B.

No

Answers
Suggested answer: B

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/active-directory/governance/create-access-review

HOTSPOT

Your network contains an on-premises Active Directory domain named contoso.com. The domain contains the objects shown in the following table.

You install Azure AD Connect. You configure the Domain and OU filtering settings as shown in the Domain and OU Filtering exhibit. (Click the Domain and OU Filtering tab.)

You configure the Filter users and devices settings as shown in the Filter Users and Devices exhibit.

(Click the Filter Users and Devices tab.)

For each of the following statements, select Yes if the statement is true. Otherwise, select No.


A.

B.

C.

D.

Question 92
Correct answer: Question 92

Explanation:

Only direct members of Group1 are synced. Group2 will sync as it is a direct member of Group1 but the members of Group2 will not sync.

Reference:

https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-install-custom

You have a Microsoft 365 tenant.

All users have mobile phones and laptops.

The users frequently work from remote locations that do not have Wi-Fi access or mobile phone connectivity. While working from the remote locations, the users connect their laptop to a wired network that has internet access.

You plan to implement multi-factor authentication (MFA).

Which MFA authentication method can the users use from the remote location?

A.

a notification through the Microsoft Authenticator app

A.

a notification through the Microsoft Authenticator app

Answers
B.

an app password

B.

an app password

Answers
C.

Windows Hello for Business

C.

Windows Hello for Business

Answers
D.

SMS

D.

SMS

Answers
Suggested answer: C

Explanation:

In Windows 10, Windows Hello for Business replaces passwords with strong two-factor authentication on PCs and mobile devices. This authentication consists of a new type of user credential that is tied to a device and uses a biometric or

PIN.

After an initial two-step verification of the user during enrollment, Windows Hello is set up on the user's device and Windows asks the user to set a gesture, which can be a biometric, such as a fingerprint, or a PIN. The user provides the gesture to verify their identity. Windows then uses Windows Hello to authenticate users.

Reference:

https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-authenticationmethods

https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hellooverview

You have a Microsoft Entra tenant that has a Microsoft Entra ID P1 license.You need to review the Microsoft Entra ID sign-in logs to investigate sign-ins that occurred in the past. For how long does Microsoft Entra ID store events in the sign-in logs?

A.

14 days

A.

14 days

Answers
B.

30 days

B.

30 days

Answers
C.

90 days

C.

90 days

Answers
D.

365 days

D.

365 days

Answers
Suggested answer: B

Explanation:

×End Practice TestAre you sure you want to end the test?YesNo

You have an Azure Active Directory (Azure AD) tenant named contoso.com that has Azure AD Identity Protection policies enforced.

You create an Azure Sentinel instance and configure the Azure Active Directory connector.

You need to ensure that Azure Sentinel can generate incidents based on the risk alerts raised by Azure AD Identity Protection.

What should you do first?

A.

Add an Azure Sentinel data connector.

A.

Add an Azure Sentinel data connector.

Answers
B.

Configure the Notify settings in Azure AD Identity Protection.

B.

Configure the Notify settings in Azure AD Identity Protection.

Answers
C.

Create an Azure Sentinel playbook.

C.

Create an Azure Sentinel playbook.

Answers
D.

Modify the Diagnostics settings in Azure AD.

D.

Modify the Diagnostics settings in Azure AD.

Answers
Suggested answer: A

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/sentinel/connect-azure-ad-identity-protection

You have a Microsoft 365 tenant.

All users have mobile phones and laptops.

The users frequently work from remote locations that do not have Wi-Fi access or mobile phone connectivity. While working from the remote locations, the users connect their laptop to a wired network that has internet access.

You plan to implement multi-factor authentication (MFA).

Which MFA authentication method can the users use from the remote location?

A.

a notification through the Microsoft Authenticator app

A.

a notification through the Microsoft Authenticator app

Answers
B.

email

B.

email

Answers
C.

security questions

C.

security questions

Answers
D.

a verification code from the Microsoft Authenticator app

D.

a verification code from the Microsoft Authenticator app

Answers
Suggested answer: D

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-authenticationauthenticator-app#verification-code-from-mobile-app

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You use Azure Monitor to analyze Azure Active Directory (Azure AD) activity logs.

You receive more than 100 email alerts each day for failed Azure AD user sign-in attempts.

You need to ensure that a new security administrator receives the alerts instead of you.

Solution: From Azure AD, you modify the Diagnostics settings.

Does this meet the goal?

A.

Yes

A.

Yes

Answers
B.

No

B.

No

Answers
Suggested answer: A

You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains an Azure AD enterprise application named App1.

A contractor uses the credentials of [email protected].

You need to ensure that you can provide the contractor with access to App1. The contractor must be able to authenticate as [email protected].

What should you do?

A.

Run the New-AzureADMSInvitation cmdlet.

A.

Run the New-AzureADMSInvitation cmdlet.

Answers
B.

Configure the External collaboration settings.

B.

Configure the External collaboration settings.

Answers
C.

Add a WS-Fed identity provider.

C.

Add a WS-Fed identity provider.

Answers
D.

Implement Azure AD Connect.

D.

Implement Azure AD Connect.

Answers
Suggested answer: A

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/active-directory/external-identities/b2b-quickstart-addguest-users-portal

https://docs.microsoft.com/en-us/powershell/module/azuread/newazureadmsinvitation?view=azureadps-2.0

You have 2,500 users who are assigned Microsoft Office 365 Enterprise E3 licenses. The licenses are assigned to individual users.

From the Groups blade in the Azure Active Directory admin center, you assign Microsoft 365 Enterprise E5 licenses to the users.

You need to remove the Office 365 Enterprise E3 licenses from the users by using the least amount of administrative effort.

What should you use?

A.

the Administrative units blade in the Azure Active Directory admin center

A.

the Administrative units blade in the Azure Active Directory admin center

Answers
B.

the Set-AzureAdUser cmdlet

B.

the Set-AzureAdUser cmdlet

Answers
C.

the Groups blade in the Azure Active Directory admin center

C.

the Groups blade in the Azure Active Directory admin center

Answers
D.

the Sec-MsolUserLicense cmdlet

D.

the Sec-MsolUserLicense cmdlet

Answers
Suggested answer: C

Explanation:


You have an Azure Active Directory (Azure AD) tenant that contains cloud-based enterprise apps.

You need to group related apps into categories in the My Apps portal.

What should you create?

A.

tags

A.

tags

Answers
B.

collections

B.

collections

Answers
C.

naming policies

C.

naming policies

Answers
D.

dynamic groups

D.

dynamic groups

Answers
Suggested answer: B

Explanation:

Reference:

https://support.microsoft.com/en-us/account-billing/customize-app-collections-in-the-my-appsportal-2dae6b8a-d8b0-4a16-9a5d-71ed4d6a6c1d

Total 290 questions
Go to page: of 29