Microsoft SC-300 Practice Test - Questions Answers, Page 27
List of questions
Related questions
HOTSPOT
You have a Microsoft Entra tenant named contoso.com that contains an administrative unit named AU1 and two users named User1 and User2. User1 is a member of AU1.
You need to perform the following role assignments:
* User1: Security Administrator
* User2: User Administrator
For which scopes can each user be assigned the role? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
You have an Azure subscription, a Google Cloud Platform (GCP) account, and an Amazon Web Services (AWS) account.
You need to recommend a solution to assess the risks associated with privilege assignments across all the platforms. The solution must minimize administrative effort
What should you include in the recommendation?
Microsoft Sentinel
Microsoft Defender for Cloud Apps
Microsoft Entra ID Protection
Microsoft Entra Permissions Management
SIMULATION 1
You need to deploy multi factor authentication (MFA). The solution must meet the following requirements:
* Require MFA registration only for members of the Sg-Finance group.
* Exclude Debra Berger from having to register for MFA.
* Implement the solution without using a Conditional Access policy.
See the Explanation for the complete step by step solution
SIMULATION 2
You need to implement a process to review guest users who have access to the Salesforce app. The review must meet the following requirements:
* The reviews must occur monthly.
* The manager of each guest user must review the access.
* If the reviews are NOT completed within five days, access must be removed.
* If the guest user does not have a manager, Megan Bowen must review the access.
See the Explanation for the complete step by step solution
SIMULATION 3
You need to add the Linkedln application as a resource to the Sales and Marketing access package. The solution must NOT remove any other resources from the access package.
See the Explanation for the complete step by step solution
SIMULATION 4
You need to ensure that all users can consent to apps that require permission to read their user profile. Users must be prevented from consenting to apps that require any other permissions.
See the Explanation for the complete step by step solution
SIMULATION 5
You need to assign a Windows 10/11 Enterprise E3 license to the Sg-Retail group.
See the Explanation for the complete step by step solution
SIMULATION 6
You need to implement additional security checks before the members of the Sg-Executive can access any company apps. The members must meet one of the following conditions:
* Connect by using a device that is marked as compliant by Microsoft Intune.
* Connect by using client apps that are protected by app protection policies.
See the Explanation for the complete step by step solution
SIMULATION 7
You need to lock out accounts for five minutes when they have 10 failed sign-in attempts.
See the Explanation for the complete step by step solution
SIMULATION 8
You need to prevent all users from using legacy authentication protocols when authenticating to Microsoft Entra ID.
See the Explanation for the complete step by step solution
Question