Microsoft SC-300 Practice Test - Questions Answers, Page 26
List of questions
Related questions
You have a Microsoft Entra tenant that contains a terms of use (ToU) named Terms1. You create a Conditional Access policy named Policy1 to deploy Terms1. You need to configure Policy1 to require users to accept Terms1. Which settings should you configure for Policy1?
Conditions
Session
Grant
Target resources
Your on-premises network contains an Active Directory Domain Services (AD DS) domain and a certification authority (CA) named CAT.
You have a Microsoft Entra tenant.
You need to implement Microsoft Entra certificate-based authentication. The solution must ensure that users can sign in by using certificates issued by CAT
What should you do first?
Enable auto-enrollment for CAT.
Deploy an Azure key vault.
Add CA1 as a Certificate Authority to the Microsoft Entra tenant.
Deploy Windows Hello for Business.
You have an Azure subscription that contains a virtual machine named VM1 and an Azure key vault named Vault1. VM1 has a system-assigned managed identity. You need to ensure that VM1 can retrieve the values of secrets stored in Vault 1. The solution must minimize administrative effort. What should you do first?
Configure the Resource access settings for Vault1.
Configure the permissions model for Vault1
Add a user-assigned managed identity to VM1.
Assign an Azure role to VM1.
You have an Azure subscription.
You are evaluating enterprise software as a service (SaaS) apps.
You need to ensure that the apps support automatic provisioning of Microsoft Entra users.
Which specification should the apps support?
WS-Fed
SCIM 2.0
LDAP3
OAuth 2.0
You have an Azure subscription that contains a storage account named storage1 and a web app named WebApp1. WebApp1 uses a system-assigned managed identity.
You need to ensure that WebApp1 can read and write files to storage1 by using the system-assigned managed identity.
What should you configure for storage1 in the Azure portal?
the File share settings
the Access control (1AM) settings
a shared access signature (SAS)
data protection
access keys
You have a Microsoft Entra tenant.
You need to ensure that only users from specific external domains can be invited as guests to the tenant.
Which settings should you configure?
Cross-tenant access settings
External collaboration settings
Linked subscriptions
All identity providers
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Cloud Apps.
You plan to increase app security for the subscription.
You need to identify which apps do NOT require user authentication
What should you do in the Microsoft 365 Defender portal?
Create a discovered app query.
Create a snapshot Cloud Discovery report.
Create an OAuth policy and review alerts.
Review the cloud app catalog.
HOTSPOT
You have a Microsoft Entra tenant that contains the users shown in the following table.
You add the following assignment for the User Administrator role:
* Scope type: Directory
* Selected members: Group1
* Assignment type: Active
* Assignments starts August 15. 2022
* Assignment ends: December 15, 2022
You add the following assignment for the Exchange Administrator role:
* Scope type: Directory
* Selected members: Group2
* Assignment type: Eligible
* Assignments starts: October 15, 2022
* Assignment ends: January 15. 2023
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
HOTSPOT
Your network contains an on-premises Active Directory domain named contoso.com. The domain contains the objects shown in the following table.
You install Microsoft Entra Connect. You configure the Domain and OU filtering settings as shown in the Domain and OU Filtering exhibit. (Click the Domain and OU Filtering tab.)
You configure the Filter users and devices settings as shown in the Filter Users and Devices exhibit. (Click the Filter Users and Devices tab.)
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
DRAG DROP
Your network contains an on-premises Active Directory domain named contoso.com that syncs with a Microsoft Entra tenant by using Microsoft Entra Connect. The domain contains the users shown in the following table.
From Active Directory Users and Computers, you add the following user
* Name: User3
* UPN: [email protected]
* Proxy addresses: smtp: [email protected], smtp: [email protected]
From Active Directory Users and Computers, you update the proxyAddresses attribute for each user as shown in the following table.
You trigger a manual synchronization.
Which sync status will Microsoft Entra Connect sync return for each user? To answer, drag the appropriate status to the correct users. Each status may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Question