ExamGecko
Home Home / Microsoft / SC-300

Microsoft SC-300 Practice Test - Questions Answers, Page 5

Question list
Search
Search

List of questions

Search

Related questions











You have an Azure Active Directory (Azure AD) tenant that syncs to an Active Directory forest. The tenant-uses through authentication.

A corporate security policy states the following:

Domain controllers must never communicate directly to the internet.

Only required software must be- installed on servers.

The Active Directory domain contains the on-premises servers shown in the following table.

You need to ensure that users can authenticate to Azure AD if a server fails.

On which server should you install an additional pass-through authentication agent?

A.

Server2

A.

Server2

Answers
B.

Server4

B.

Server4

Answers
C.

Server1

C.

Server1

Answers
D.

Server3

D.

Server3

Answers
Suggested answer: C

You have an Azure Active Directory (Azure AD) tenant.

You configure self-service password reset (SSPR) by using the following settings:

• Require users to register when signing in: Yes

• Number of methods required to reset: 1

What is a valid authentication method available to users?

A.

home prions

A.

home prions

Answers
B.

mobile app notification

B.

mobile app notification

Answers
C.

a mobile app code

C.

a mobile app code

Answers
D.

an email to an address in your organization

D.

an email to an address in your organization

Answers
Suggested answer: C

You have a Microsoft 365 tenant.

You currently allow email clients that use Basic authentication to conned to Microsoft Exchange Online.

You need to ensure that users can connect t to Exchange only run email clients that use Modern authentication protocols.

What should you implement?

You need to ensure that use Modern authentication

A.

a compliance policy in Microsoft Endpoint Manager

A.

a compliance policy in Microsoft Endpoint Manager

Answers
B.

a conditional access policy in Azure Active Directory (Azure AD)

B.

a conditional access policy in Azure Active Directory (Azure AD)

Answers
C.

an application control profile in Microsoft Endpoint Manager

C.

an application control profile in Microsoft Endpoint Manager

Answers
D.

an OAuth policy in Microsoft Cloud App Security

D.

an OAuth policy in Microsoft Cloud App Security

Answers
Suggested answer: C

You create the Azure Active Directory (Azure AD) users shown in the following table.

On February 1, 2021, you configure the multi-factor authentication (MFA) settings as shown in the following exhibit.

The users authentication to Azure AD on their devices as shown in the following table.

On February 26, 2021, what will the multi-factor auth status be for each user?

A.


A.


Answers
B.


B.


Answers
C.


C.


Answers
D.


D.


Answers
Suggested answer: B

Your company has two divisions named Contoso East and Contoso West. The Microsoft 365 identity architecture tor both divisions is shown in the following exhibit.

You need to assign users from the Contoso East division access to Microsoft SharePoint Online sites in the Contoso West tenant. The solution must not require additional Microsoft 3G5 licenses.

What should you do?

A.

Configure The exiting Azure AD Connect server in Contoso Cast to sync the Contoso East Active Directory forest to the Contoso West tenant.

A.

Configure The exiting Azure AD Connect server in Contoso Cast to sync the Contoso East Active Directory forest to the Contoso West tenant.

Answers
B.

Configure Azure AD Application Proxy in the Contoso West tenant.

B.

Configure Azure AD Application Proxy in the Contoso West tenant.

Answers
C.

Deploy a second Azure AD Connect server to Contoso East and configure the server to sync the Contoso East Active Directory forest to the Contoso West tenant.

C.

Deploy a second Azure AD Connect server to Contoso East and configure the server to sync the Contoso East Active Directory forest to the Contoso West tenant.

Answers
D.

Invite the Contoso East users as guests in the Contoso West tenant.

D.

Invite the Contoso East users as guests in the Contoso West tenant.

Answers
Suggested answer: D

Your network contains an on-premises Active Directory domain that sync to an Azure Active Directory (Azure AD) tenant. The tenant contains the shown in the following table.

All the users work remotely.

Azure AD Connect is configured in Azure as shown in the following exhibit.

Connectivity from the on-premises domain to the internet is lost.

Which user can sign in to Azure AD?

A.

User1 only

A.

User1 only

Answers
B.

User1 and User 3 only

B.

User1 and User 3 only

Answers
C.

User1, and User2 only

C.

User1, and User2 only

Answers
D.

User1, User2, and User3

D.

User1, User2, and User3

Answers
Suggested answer: A

You have an Azure Active Directory (Azure AD) tenant named contoso.com.

You need to ensure that Azure AD External Identities pricing is based on monthly active users (MAU).

What should you configure?

A.

an access review

A.

an access review

Answers
B.

the terms or use

B.

the terms or use

Answers
C.

a linked subscription

C.

a linked subscription

Answers
D.

a user flow

D.

a user flow

Answers
Suggested answer: C

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/active-directory/external-identities/external-identitiespricing

You have an Azure Active Directory (Azure Azure) tenant that contains the objects shown in the following table.

• A device named Device1

• Users named User1, User2, User3, User4, and User5

• Five groups named Group1, Group2, Group3, Ciroup4, and Group5

The groups are configured as shown in the following table.

How many licenses are used if you assign the Microsoft Office 365 Enterprise E5 license to Group1?

A.

0

A.

0

Answers
B.

2

B.

2

Answers
C.

3

C.

3

Answers
D.

4

D.

4

Answers
Suggested answer: B

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/active-directory/enterprise-users/licensing-group-advanced

You have a Microsoft Exchange organization that uses an SMTP' address space of contoso.com.

Several users use their contoso.com email address for self-service sign up to Azure Active Directory (Azure AD).

You gain global administrator privileges to the Azure AD tenant that contains the self-signed users.

You need to prevent the users from creating user accounts in the contoso.com Azure AD tenant for self-service sign-up to Microsoft 365 services.

Which PowerShell cmdlet should you run?

A.

Set-MsolCompanySettings

A.

Set-MsolCompanySettings

Answers
B.

Set-MsolDomainFederationSettings

B.

Set-MsolDomainFederationSettings

Answers
C.

Update-MsolfederatedDomain

C.

Update-MsolfederatedDomain

Answers
D.

Set-MsolDomain

D.

Set-MsolDomain

Answers
Suggested answer: A

Explanation:

https://docs.microsoft.com/en-us/azure/active-directory/enterprise-users/directory-self-servicesignup

Your network contains an on-premises Active Directory domain that syncs to an Azure Active Directory (Azure AD) tenant- Users sign in to computers that run Windows 10 and are joined to the domain.

You plan to implement Azure AD Seamless Single Sign-On (Azure AD Seamless SSO).

You need to configure the computers for Azure AD Seamless SSO.

What should you do?

A.

Enable Enterprise State Roaming.

A.

Enable Enterprise State Roaming.

Answers
B.

Configure Sign-in options.

B.

Configure Sign-in options.

Answers
C.

Install the Azure AD Connect Authentication Agent.

C.

Install the Azure AD Connect Authentication Agent.

Answers
D.

Modify the Intranet Zone settings.

D.

Modify the Intranet Zone settings.

Answers
Suggested answer: D

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sso-quick-start

Total 290 questions
Go to page: of 29