ExamGecko
Home Home / Microsoft / SC-300

Microsoft SC-300 Practice Test - Questions Answers, Page 17

Question list
Search
Search

List of questions

Search

Related questions











You have an Azure subscription that contains a user named User1. You need to meet the following requirements:

• Prevent User1 from being added as an owner of newly registered apps.

• Ensure that User1 can manage the application proxy settings.

• Ensure that User2 can register apps.

• Use the principle of least privilege.

Which role should you assign to User1?

A.

Application developer

A.

Application developer

Answers
B.

Cloud application administrator

B.

Cloud application administrator

Answers
C.

Service support administrator

C.

Service support administrator

Answers
D.

Application administrator

D.

Application administrator

Answers
Suggested answer: D

Your company purchases 2 new Microsoft 365 ES subscription and an app named App.

You need to create a Microsoft Defender for Cloud Apps access policy for App1.

What should you do you first? (Choose Correct Answer based on Microsoft Identity and Access Administrator at microsoft.com)

A.

Configure a Token configuration for App1.

A.

Configure a Token configuration for App1.

Answers
B.

Add an API permission for App.

B.

Add an API permission for App.

Answers
C.

Configure a Conditional Access policy to use app-enforced restrictions.

C.

Configure a Conditional Access policy to use app-enforced restrictions.

Answers
D.

Configure a Conditional Access policy to use Conditional Access App Control.

D.

Configure a Conditional Access policy to use Conditional Access App Control.

Answers
Suggested answer: C

Explanation:

https://learn.microsoft.com/en-us/defender-cloud-apps/access-policy-aad

To create a Microsoft Defender for Cloud Apps access policy for App1, you should configure a Conditional Access policy to use app-enforced restrictions. This will allow you to control access to your cloud apps based on conditions such as user, device, location, and app state. You can also use app-enforced restrictions to control access to your cloud apps based on the state of the app, such as whether it’s running on a managed or unmanaged device.

You have an Azure AD tenant named contoso.com that contains the resources shown in the following table.

You create a user named Admin 1.

You need to ensure that Admin can enable Security defaults for contoso.com.

What should you do first?

A.

Configure Identity Governance.

A.

Configure Identity Governance.

Answers
B.

Delete Package1.

B.

Delete Package1.

Answers
C.

Delete CAPolicy1.

C.

Delete CAPolicy1.

Answers
D.

Assign Admin1 the Authentication administrator role for Au1

D.

Assign Admin1 the Authentication administrator role for Au1

Answers
Suggested answer: D

Explanation:

To enable Security defaults for contoso.com, you should first sign in to the Azure portal as a security administrator, Conditional Access administrator, or global administrator. Then, browse to Azure Active Directory > Properties and select Manage security defaults. Set the Enable security defaults toggle to Yes and select Save.

After that, you can assign Admin1 the Identity Administrator role for Au1 to enable them to manage security defaults for the tenant.

https://practical365.com/what-are-azure-ad-security-defaults-and-should-you-use-them/

HOTSPOT

You have an Azure AD tenant that contains a user named User1. User1 is assigned the User Administrator role.

You need to configure External collaboration settings for the tenant to meet the following requirements:

*Guest users must be prevented from querying staff email addresses.

*Guest users must be able to access the tenant only if they are invited by User1.

Which three settings should you configure? To answer, select the appropriate settings in the answer area.


Question 164
Correct answer: Question 164

Explanation:

Box1 = User access is restricted to properties and memberships of their own directory objects (most restrictive). This setting ensures that guest users are prevented from querying staff email addresses and can access the tenant only if they are invited by User1.

Box2 = Only users assigned to specific admin roles can invite guest users. This setting ensures that guest users can access the tenant only if they are invited by User1.

Box3 = This setting enables guest users to sign up for the tenant only if they are invited by User1.

HOTSPOT

You have an Azure subscription.

Azure AD logs are sent to a Log Analytics workspace.

You need to query the logs and graphically display the number of sign-ins per user.

How should you complete the query? To answer, select the appropriate options in the answer area.


Question 165
Correct answer: Question 165

Explanation:

Box 1 =

SigninLogs

| where ResultType == 0

| summarize login_count = count() by identity

| render piechart

This query retrieves the sign-in logs, filters the successful sign-ins, summarizes the count of sign-ins

per user, and renders the result as a pie chart.

Box 2 = Render

You have an Azure AD tenant that contains the users shown in the following table.

The User settings for enterprise applications have the following configuration.

• Users can consent to apps accessing company data on their behalf:

• Users can consent to apps accessing company data for the groups they

• Users can request admin consent to apps they are unable to consent to: Yes

• Who can review admin consent requests: Admin2, User2

User1 attempts to add an app that requires consent to access company data.

Which user can provide consent?

A.

User1

A.

User1

Answers
B.

User2

B.

User2

Answers
C.

Admin1

C.

Admin1

Answers
D.

Admin2

D.

Admin2

Answers
Suggested answer: C

HOTSPOT

You have an Azure AD tenant named contoso.com that has Email one-time passcode for guests set to Yes.

You invite the guest users shown in the following table.

Which users will receive a one-time passcode, and how long will the passcode be valid? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Question 167
Correct answer: Question 167

HOTSPOT

You have an Azure AD tenant that contains the users shown in the following table.

User2 reports that he can only configure multi-factor authenticating (MFA) to use the Microsoft Authenticator app.

You need to ensure that User2 can configure alternate MFA methods.

Which configuration is required, and which user should perform the configuration? To answer, select the appropriate options in the answer area.


Question 168
Correct answer: Question 168

Your network contains an on-premises Active Directory domain that syncs to an Azure AD tenant.

Users sign in to computers that run Windows 10 and are joined to the domain.

You plan to implement Azure AD Seamless Single Sign-On (Azure AD Seamless SSO).

You need to configure the Windows 10 computers to support Azure AD Seamless SSO.

What should you do?

A.

Modify the Local intranet zone settings

A.

Modify the Local intranet zone settings

Answers
B.

Configure Sign-in options from the Settings app.

B.

Configure Sign-in options from the Settings app.

Answers
C.

Enable Enterprise State Roaming.

C.

Enable Enterprise State Roaming.

Answers
D.

Install the Azure AD Connect Authentication Agent.

D.

Install the Azure AD Connect Authentication Agent.

Answers
Suggested answer: B

HOTSPOT

You have an Azure AD tenant and an Azure web app named App1.

You need to provide guest users with self-service sign-up for App1. The solution must meet the following requirements:

• Guest users must be able to sign up by using a one-time password.

• The users must provide their first name, last name, city, and email address during the sign-up process.

What should you configure in the Azure Active Directory admin center for each requirement? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


Question 170
Correct answer: Question 170
Total 290 questions
Go to page: of 29