ExamGecko
Home Home / Microsoft / SC-300

Microsoft SC-300 Practice Test - Questions Answers, Page 4

Question list
Search
Search

List of questions

Search

Related questions











You have an Azure Active Directory (Azure AD) tenant that uses conditional access policies.

You plan to use third-party security information and event management (SIEM) to analyze conditional access usage.

You need to download the Azure AD log that contains conditional access policy data.

What should you export from Azure AD?

A.

sign-ins in JSON format

A.

sign-ins in JSON format

Answers
B.

sign-ins in CSV format

B.

sign-ins in CSV format

Answers
C.

audit logs in JSON format

C.

audit logs in JSON format

Answers
D.

audit logs in CSV format

D.

audit logs in CSV format

Answers
Suggested answer: C

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/active-directory/reports-monitoring/concept-audit-logs

You have an Azure Active Directory (Azure AD) tenant.

You need to review the Azure AD sign-ins log to investigate sign ins that occurred in the past.

For how long does Azure AD store events in the sign-in log?

A.

14 days

A.

14 days

Answers
B.

30 days

B.

30 days

Answers
C.

90 days

C.

90 days

Answers
D.

365 days

D.

365 days

Answers
Suggested answer: B

You have an Azure Active Directory (Azure AD) tenant that contains the objects shown in the following table.

Which objects can you add as eligible in Azure Privileged identity Management (PIM) for an Azure AD role?

A.

User1 only

A.

User1 only

Answers
B.

User1 and Identity1 only

B.

User1 and Identity1 only

Answers
C.

User1. Guest1, and Identity

C.

User1. Guest1, and Identity

Answers
D.

User1 and Guest1 only

D.

User1 and Guest1 only

Answers
Suggested answer: D

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pimdeployment-plan

You have a Microsoft 365 tenant.

You need to ensure that you tan view Azure Active Directory (Azure AD) audit log information by using Azure Monitor.

What should you do first?

A.

Run the Get-AzureADAuditDirectoryLogs cmdlet.

A.

Run the Get-AzureADAuditDirectoryLogs cmdlet.

Answers
B.

Create an Azure AD workbook.

B.

Create an Azure AD workbook.

Answers
C.

Run the Set-AzureADTenantDetail cmdlet.

C.

Run the Set-AzureADTenantDetail cmdlet.

Answers
D.

Modify the Diagnostics settings for Azure AD.

D.

Modify the Diagnostics settings for Azure AD.

Answers
Suggested answer: A

You have an Azure Active Directory (Azure AD) tenant.

For the tenant. Users can register applications Is set to No.

A user named Admin1 must deploy a new cloud app named App1.

You need to ensure that Admin1 can register App1 in Azure AD. The solution must use the principle of least privilege.

Which role should you assign to Admin1?

A.

Application developer in Azure AD

A.

Application developer in Azure AD

Answers
B.

App Configuration Data Owner for Subscription1

B.

App Configuration Data Owner for Subscription1

Answers
C.

Managed Application Contributor for Subscription1

C.

Managed Application Contributor for Subscription1

Answers
D.

Cloud application administrator in Azure AD

D.

Cloud application administrator in Azure AD

Answers
Suggested answer: A

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/active-directory/roles/delegate-app-roles

Your company requires that users request access before they can access corporate applications.

You register a new enterprise application named MyApp1 in Azure Active Dilatory (Azure AD) and configure single sign-on (SSO) for MyApp1.

Which settings should you configure next for MyApp1?

A.

Self-service

A.

Self-service

Answers
B.

Provisioning

B.

Provisioning

Answers
C.

Roles and administrators

C.

Roles and administrators

Answers
D.

Application proxy

D.

Application proxy

Answers
Suggested answer: A

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/manage-self-service-access

You have an Azure Active Directory (Azure AD) tenant.

You create an enterprise application collection named HR Apps that has the following settings:

• Applications: Appl. App?, App3

• Owners: Admin 1

• Users and groups: HRUsers

AH three apps have the following Properties settings:

• Enabled for users to sign in: Yes

• User assignment required: Yes

• Visible to users: Yes Users report that when they go to the My Apps portal, they only sue App1 and App2-You need to ensure that the users can also see App3. What should you do from App3?

What should you do from App3?

A.

From Users and groups, add HRUsers.

A.

From Users and groups, add HRUsers.

Answers
B.

Prom Properties, change User assignment required to No.

B.

Prom Properties, change User assignment required to No.

Answers
C.

From Permissions, review the User consent permissions.

C.

From Permissions, review the User consent permissions.

Answers
D.

From Single sign on, configure a sign-on method.

D.

From Single sign on, configure a sign-on method.

Answers
Suggested answer: A

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/assign-user-or-group-accessportal

https://docs.microsoft.com/en-us/azure/active-directory/user-help/my-applications-portalworkspaces

You have a Microsoft 365 tenant.

The Azure Active Directory (Azure AD) tenant contains the groups shown in the following table.

In Azure AD. you add a new enterprise application named Appl. Which groups can you assign to App1?

A.

Group1 and Group

A.

Group1 and Group

Answers
B.

Group2 only

B.

Group2 only

Answers
C.

Group3 only

C.

Group3 only

Answers
D.

Group1 only

D.

Group1 only

Answers
E.

Group1 and Group4

E.

Group1 and Group4

Answers
Suggested answer: A

You configure a new Microsoft 36S tenant to use a default domain name of contosso.com.

You need to ensure that you can control access to Microsoft 365 resource-, by using conditional access policy.

What should you do first?

A.

Disable the User consent settings.

A.

Disable the User consent settings.

Answers
B.

Disable Security defaults.

B.

Disable Security defaults.

Answers
C.

Configure a multi-factor authentication (Ml A) registration policy1.

C.

Configure a multi-factor authentication (Ml A) registration policy1.

Answers
D.

Configure password protection for Windows Server Active Directory.

D.

Configure password protection for Windows Server Active Directory.

Answers
Suggested answer: B

You have an Azure Active Directory (Azure AD) tenant named conto.so.com that has Azure AD Identity Protection enabled. You need to Implement a sign-in risk remediation policy without blocking access.

What should you do first?

A.

Configure access reviews in Azure AD.

A.

Configure access reviews in Azure AD.

Answers
B.

Enforce Azure AD Password Protection.

B.

Enforce Azure AD Password Protection.

Answers
C.

implement multi-factor authentication (MFA) for all users.

C.

implement multi-factor authentication (MFA) for all users.

Answers
D.

Configure self-service password reset (SSPR) for all users.

D.

Configure self-service password reset (SSPR) for all users.

Answers
Suggested answer: C

Explanation:

MFA and SSPR are both required. However, MFA is required first.

Reference:

https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/howto-identityprotection-remediate-unblock

https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-sspr-deployment

Total 290 questions
Go to page: of 29