Summer Sale Limited Time 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple75

Pass the Microsoft Certified: Identity and Access Administrator Associate SC-300 Questions and answers with Dumpstech

Exam SC-300 Premium Access

View all detail and faqs for the SC-300 exam

Practice at least 50% of the questions to maximize your chances of passing.
Viewing page 9 out of 11 pages
Viewing questions 81-90 out of questions
Questions # 81:

You have a Microsoft 365 tenant.

The Azure Active Directory (Azure AD) tenant syncs to an on-premises Active Directory domain. The domain

contains the servers shown in the following table.

Question # 81

The domain controllers are prevented from communicating to the internet.

You implement Azure AD Password Protection on Server1 and Server2.

You deploy a new server named Server4 that runs Windows Server 2019.

You need to ensure that Azure AD Password Protection will continue to work if a single server fails.

What should you implement on Server4?

Options:

A.

Azure AD Connect

B.

Azure AD Application Proxy

C.

Password Change Notification Service (PCNS)

D.

the Azure AD Password Protection proxy service

Questions # 82:

Your network contains an on-premises Active Directory Domain services (AD DS) domain that syncs with an Azure AD tenant. The AD DS domain contains the organizational units (OUs) shown in the following table.

Question # 82

You need to create a break-glass account named BreakGlass.

Where should you create BreakGlass, and which role should you assign to BreakGlass? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 82

Options:

Questions # 83:

You have a Microsoft 365 E5 subscription that contains three users named User1, User2, and User3.

You have two Azure AD roles that have the Activation settings shown in the following table.

Question # 83

The Azure AD roles have the Assignment settings shown in the following table.

Question # 83

The Azure AD roles have the eligible users shown in the following table.

Question # 83

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Question # 83

Options:

Questions # 84:

You have three Azure subscriptions that are linked to a single Microsoft Entra tenant.

You need to evaluate and remediate the risks associated with highly privileged accounts. The solution must minimize administrative effort.

What should you use?

Options:

A.

Microsoft Entra Verified ID

B.

Privileged Identify Management (PIM)

C.

Global Secure Access

D.

Microsoft Entra Permissions Management

Questions # 85:

You have a Microsoft Entra tenant.

You discover that a large number of new apps were added to the tenant.

You need to implement an approval process for new enterprise applications. What should you do?

Options:

A.

From the Microsoft Defender portal, create a Cloud Discovery anomaly detection policy.

B.

From the Microsoft Entra admin center, configure the Admin consent settings.

C.

From the Microsoft Defender portal, configure an app connector.

D.

From the Microsoft Entra admin center, configure an access review.

Questions # 86:

You have a Microsoft 365 tenant.

In Azure Active Directory (Azure AD), you configure the terms of use.

You need to ensure that only users who accept the terms of use can access the resources in the tenant. Other

users must be denied access.

What should you configure?

Options:

A.

an access policy in Microsoft Cloud App Security.

B.

Terms and conditions in Microsoft Endpoint Manager.

C.

a conditional access policy in Azure AD

D.

a compliance policy in Microsoft Endpoint Manager

Questions # 87:

Your network contains an Active Directory forest named contoso.com that is linked to an Azure Active Directory

(Azure AD) tenant named contoso.com by using Azure AD Connect.

You need to prevent the synchronization of users who have the extensionAttribute15 attribute set to

NoSync.

What should you do in Azure AD Connect?

Options:

A.

Create an inbound synchronization rule for the Windows Azure Active Directory connector.

B.

Configure a Full Import run profile.

C.

Create an inbound synchronization rule for the Active Directory Domain Services connector.

D.

Configure an Export run profile.

Questions # 88:

You have a Microsoft 365 E5 subscription.

You create an access review named Review1. Review1 requires that every six months, Microsoft 365 group owners review guest user access to their groups.

You need to ensure that if the group owners fail to review the membership of Review1, guest users ate removed automatically.

Which settings should you configure for Review1?

Options:

A.

Reviewers

B.

Advanced settings

C.

General

D.

Upon completion settings

Questions # 89:

You have a hybrid Microsoft 365 subscription that contains the users show in the following table.

Question # 89

You plan to deploy an on-premises app1. App1 will be registered in Azure AD and will use Azure AD Application Proxy.

You need to delegate the installation of the Application Proxy connector and ensure that User1 can register App1 in Azure AD. The solution must use the principle of least privilege.

Which user should perform the installation, and which role should you assign to Users1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 89

Options:

Questions # 90:

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have an Azure Active Directory (Azure AD) tenant that syncs to an Active Directory forest.

You discover that when a user account is disabled in Active Directory, the disabled user can still authenticate to Azure AD for up to 30 minutes.

You need to ensure that when a user account is disabled in Active Directory, the user account is immediately prevented from authenticating to Azure AD.

Solution: You configure password writeback.

Does this meet the goal?

Options:

A.

Yes

B.

No

Viewing page 9 out of 11 pages
Viewing questions 81-90 out of questions