Microsoft SC-300 Practice Test - Questions Answers, Page 24
List of questions
Related questions
You have an Azure subscription that contains a resource group named RG1 and four users named User1, User2, User3, and User4. You plan to assign the users the following roles for RG1:
* User1: Reader
* User2: Contributor
* User3: Storage Blob Data Reader
* User4: Virtual Machine Contributor
You are evaluating the use of attribute-based access control (ABAC). Which user's role will support the use of ABAC?
User1
User2
User3
User4
You have an Azure subscription named Sub1 that contains a virtual machine named VM1.
You need to enable Microsoft Entra login for VM1 and configure VM1 to access the resources in Sub1.
Which type of identity should you assign to VM1?
system-assigned managed identity
Azure Automation account
Microsoft Entra user account
user-assigned managed identity
You have a Microsoft 365 subscription.
You plan to deploy an app named App1 that will have the following configurations:
* Will be registered in Microsoft Entra
* Will run as a service without user interaction
* Will collect audit logs associated with user sign-ins
* Will access resources by using the Microsoft Graph API
You need to ensure that App1 can access Microsoft Graph.
What should you use?
application permissions
delegated permissions
a custom role-based access control (RBAC) role
a built-in role-based access control (RBAC) role
You have a Microsoft 365 subscription that contains the users shown in the following table.
From the tenan1, you configure a naming policy for groups.
Which users are affected by the naming policy?
User2 only
User3only
User2 and User3 only
User3 and User4 only
User1, User2, and User3 only
User1, User2, User3, and User4
DRAG DROP
You have an Azure subscription that is linked to a Microsoft Entra tenant named contoso.com. The subscription contains a group named Group1 and a virtual machine named VM1.
You need to meet the following requirements:
* Enable a system-assigned managed identity for VM1.
* AddVM1 to Group1.
How should you complete the PowerShell script? To answer, drag the appropriate cmdlets to the correct targets. Each cmdlet may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
HOTSPOT
You have Microsoft Entra tenant that contains a group named Group3 and an administrative unit named Department1.
Department has the users shown in the Users exhibit. (Click the Users tab.)
Department1 has the groups shown in the Groups exhibit (Click the Groups tab.)
The User Administrator role assignments are shown in the Assignments exhibit. (Click the Assignments tab.)
The members of Group2 are shown in the Group2 exhibit. (Click the Group2 tab.)
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
You have an Azure subscription named Sub1 that contains a user named User1.
You need to ensure that User1 can purchase a Microsoft Entra Permissions Management license for Sub1. The solution must follow the principle of least privilege.
Which role should you assign to User1?
User Access Administrator
Permissions Management Administrator
Billing Administrator
Global Administrator
HOTSPOT
You have a Microsoft 365 E5 subscription.
You need to configure app consent for the subscription. The solution must meet the following requirements:
* Disable user consent to apps.
* Configure admin consent workflow for apps.
Which portal should you use for each requirement? To answer, select the appropriate options in the answer are a. NOTE Each correct selection is worth one point
You have an Azure subscription that contains a user named User1. The subscription is onboarded to Microsoft Entra Permissions Management. You need to provide User! with access to Permissions Management. The solution must meet the following requirements:
* Follow the principle of least privilege.
* Minimize administrative effort.
What should you do first?
From the Microsoft Entra admin center, create a security group.
From the Role/Policy Template subtab of Permissions Management, create a template.
From the Microsoft Entra admin center, assign a role to User1.
From the My Requests subtab of Permissions Management, create a new request.
You have an Azure subscription named Sub1 that uses Microsoft Entra Permissions Management. Sub1 contains a user named User1. User1 is granted multiple permissions across Sub1.
You need to replace all the permissions granted to User1 with read-only permissions. The solution must minimize administrative effort.
What should you do on the Remediation tab in Permissions Management?
From the Roles/Policies subtab. create a role.
From the My Requests subtab, create a new request.
From the Permissions subtab, use a quick action.
From the Role/Policy Template subtab. create a template.
Question