Get SC-300 Braindumps & SC-300 Real Exam Questions
Microsoft SC-300 Actual Questions and Braindumps
NEW QUESTION # 14
You have an on-premises Microsoft Exchange organization that uses an SMTP address space of contoso.com.
You discover that users use their email address for self-service sign-up to Microsoft 365 services.
You need to gain global administrator privileges to the Azure Active Directory (Azure AD) tenant that contains the self-signed users.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
1 - Create a self-signed user account in the Azure AD tenant.
2 - Sign in to the Microsoft 365 admin center.
3 - Respond to the Become the admin message.
4 - Create a TXT record in the consoso.com DNS zone.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/enterprise-users/domains-admin-takeover
NEW QUESTION # 15
You have a Microsoft Entra tenant that uses Microsoft Entra ID Premium licenses.
You plan to configure a terms of use (ToU) for the tenant.
You need to upload the ToU document.
Which format should you use for the document?
- A. RTF
- B. PDF
- C. DOCX
- D. HTML
Answer: B
Explanation:
The Microsoft Entra Terms of Use (ToU) documentation included in the SC-300 curriculum specifies that only PDF files are supported when uploading terms of use documents.
Microsoft Entra ID Premium licenses are required to configure Terms of Use, and when administrators create a new ToU, the upload field explicitly accepts a PDF document format. The PDF ensures consistent formatting across devices and preserves the legal structure of compliance statements.
The guide states:
"The terms of use document must be a PDF file. This ensures consistency in presentation and prevents tampering." Therefore, acceptable format: PDF only - formats such as HTML, DOCX, or RTF are not supported.
NEW QUESTION # 16
SIMULATION
Task 4
You need to ensure that all users can consent to apps that require permission to read their user profile. Users must be prevented from consenting to apps that require any other permissions.
Answer:
Explanation:
See the Explanation for the complete step by step solution
Explanation:
To ensure that all users can consent to apps that require permission to read their user profile and prevent them from consenting to apps that require any other permissions, you can configure the user consent settings in the Microsoft Entra admin center. Here's how you can do it:
Sign in as a Global Administrator:
Access the Microsoft Entra admin center with Global Administrator privileges.
Navigate to user consent settings:
Go toIdentity>Applications>Enterprise applications>Consent and permissions>User consent settings1.
Configure the consent settings:
Under User consent for applications, select the option that allows users to consent to apps that only require permission to read their user profile.
Ensure that all other permissions are set to require administrator consent, thus preventing users from consenting to apps that require additional permissions1.
Save the settings:
After configuring the consent settings, select Save to apply the changes.
NEW QUESTION # 17
You have an Azure AD tenant named contoso.com that has Email one-time passcode for guests set to Yes.
You invite the guest users shown in the following table.
Which users will receive a one-time passcode, and how long will the passcode be valid? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 18
You configure Azure Active Directory (Azure AD) Password Protection as shown in the exhibit. (Click theExhibittab.)
You are evaluating the following passwords:
Pr0jectlitw@re
T@ilw1nd
C0nt0s0
Which passwords will be blocked?
- A. C0nt0s0, Pr0jectlitw@re, and T@ilw1nd
- B. C0nt0s0 and T@ilw1nd only
- C. C0nt0s0 and Pr0jectlitw@re only
- D. C0nt0s0 only
- E. Pr0jectlitw@re and T@ilw1nd only
Answer: A
Explanation:
Reference:
https://blog.enablingtechcorp.com/azure-ad-password-protection-password-evaluation
NEW QUESTION # 19
You have a Microsoft 365 E5 tenant.
You purchase a cloud app named App1.
You need to enable real-time session-level monitoring of App1 by using Microsoft Cloud app Security.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
Explanation:
Reference:
https://docs.microsoft.com/en-us/cloud-app-security/proxy-deployment-any-app
https://docs.microsoft.com/en-us/cloud-app-security/session-policy-aad
NEW QUESTION # 20
You have an Azure subscription that contains the resources shown in the following table.
You create a Microsoft Entra user named User1.
Which identities can you add to VM1 and App1? To answer, select the appropriate options in the answer area.
NOTE: Each correct answer is worth one point.
Answer:
Explanation:
Explanation:
VM1: Managed1 and Managed2 only
App1: A system-assigned managed identity and Managed2 only
Questions no: 269
Verified Answer:
* VM1: Managed1 and Managed2 only
* App1: A system-assigned managed identity and Managed2 only
Comprehensive and Detailed Explanation with all Microsoft SC-300: Identity and Access Administrator documents:
To answer this question, we must apply the principles of Managed Identities for Azure resources. Managed identities provide an automatically managed identity in Microsoft Entra ID for applications to use when connecting to resources that support Microsoft Entra authentication (like Azure Key Vault or SQL).
1. Understanding Identity Types:
* User Objects (User1): Standard user accounts are used for human sign-ins. You cannot assign a standard user object (like User1) as the identity of an Azure resource (like a VM or App Service). The resource must use a Service Principal or Managed Identity. Therefore, any option including User1 is incorrect.
* User-Assigned Managed Identities (Managed1, Managed2): These are standalone Azure resources that can be assigned to one or more Azure resources (like VMs or App Services).
* System-Assigned Managed Identities: These are enabled directly on the resource itself and share the resource's lifecycle.
2. Analysis for VM1:
* Azure Virtual Machines support User-assigned managed identities.
* You can assign multiple user-assigned identities to a single VM.
* Looking at the dropdown options for VM1:
* Options with User1 are invalid.
* This leaves Managed2 only or Managed1 and Managed2 only.
* Since both Managed1 and Managed2 are valid user-assigned identities available in the subscription, you can assign both.
* Conclusion: Select Managed1 and Managed2 only.
3. Analysis for App1:
* Azure App Services support both System-assigned and User-assigned managed identities concurrently.
* Looking at the dropdown options for App1:
* Options with User1 are invalid.
* Managed1 is not listed in the dropdown options (Managed identities must be in the same region as the resource; often this question implies a region mismatch, or simply restricts the choice).
* Managed2 is listed as a valid user-assigned option.
* A system-assigned managed identity is listed as a valid option.
* Since you can configure an App Service to use both its system-assigned identity and a user- assigned identity simultaneously, the most complete correct answer identifies all capable identities.
* Conclusion: Select A system-assigned managed identity and Managed2 only.
Reference Extract:
"Managed identities for Azure resources provide Azure services with an automatically managed identity in Azure Active Directory... There are two types of managed identities: System-assigned... and User-assigned...
You can assign a user-assigned managed identity to [Azure Virtual Machines and Azure App Service]." (Source: Microsoft Learn - What are managed identities for Azure resources?)
NEW QUESTION # 21
You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1.
You need to be notified if a user downloads more than 50 files in one minute from Site1.
Which type of policy should you create in the Microsoft Defender for Cloud Apps?
- A. session policy
- B. activity policy
- C. file policy
- D. app discovery policy
Answer: B
Explanation:
You should create an activity policy in the Microsoft Defender for Cloud Apps portal to be notified if a user downloads more than 50 files in one minute from Site1.
Activity policies allow you to monitor specific user activities, including high rates of certain actions such as file downloads, and trigger alerts based on those activities. This fits the requirement to detect and notify on a user downloading more than 50 files within a short time frame.
NEW QUESTION # 22
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Active Directory forest that syncs to an Azure Active Directory (Azure AD) tenant.
You discover that when a user account is disabled in Active Directory, the disabled user can still authenticate to Azure AD for up to 30 minutes.
You need to ensure that when a user account is disabled in Active Directory, the user account is immediately prevented from authenticating to Azure AD.
Solution: You configure Azure AD Password Protection.
Does this meet the goal?
- A. Yes
- B. No
Answer: B
Explanation:
Topic 1, Contoso, Ltd
Existing Environment
The on-premises network of Contoso contains an Active Directory domain named contos.com. The domain contains an organizational unit (OU) named Contoso_Resources. The Contoso_Resoureces OU contains all users and computers.
The Contoso.com Active Directory domain contains the users shown in the following table.
Microsoft 365/Azure Environment
Contoso has an Azure AD tenant named Contoso.com that has the following associated licenses:
Microsoft Office 365 Enterprise E5
Enterprise Mobility + Security
Windows 10 Enterprise E5
Project Plan 3
Azure AD Connect is configured between azure AD and Active Directory Domain Serverless (AD DS). Only the Contoso Resources OU is synced.
Helpdesk administrators routinely use the Microsoft 365 admin center to manage user settings.
User administrators currently use the Microsoft 365 admin center to manually assign licenses, All user have all licenses assigned besides following exception:
The users in the London office have the Microsoft 365 admin center to manually assign licenses. All user have licenses assigned besides the following exceptions:
The users in the London office have the Microsoft 365 Phone System License unassigned.
The users in the Seattle office have the Yammer Enterprise License unassigned.
Security defaults are disabled for Contoso.com.
Contoso uses Azure AD Privileged identity Management (PIM) to project administrator roles.
Problem Statements
Contoso identifies the following issues:
* Currently, all the helpdesk administrators can manage user licenses throughout the entire Microsoft 365 tenant.
* The user administrators report that it is tedious to manually configure the different license requirements for each Contoso office.
* The helpdesk administrators spend too much time provisioning internal and guest access to the required Microsoft 365 services and apps.
* Currently, the helpdesk administrators can perform tasks by using the: User administrator role without justification or approval.
* When the Logs node is selected in Azure AD, an error message appears stating that Log Analytics integration is not enabled.
Planned Changes
Contoso plans to implement the following changes.
Implement self-service password reset (SSPR). Analyze Azure audit activity logs by using Azure Monitor-Simplify license allocation for new users added to the tenant. Collaborate with the users at Fabrikam on a joint marketing campaign. Configure the User administrator role to require justification and approval to activate.
Implement a custom line-of-business Azure web app named App1. App1 will be accessible from the internet and authenticated by using Azure AD accounts.
For new users in the marketing department, implement an automated approval workflow to provide access to a Microsoft SharePoint Online site, group, and app.
Contoso plans to acquire a company named Corporation. One hundred new A Datum users will be created in an Active Directory OU named Adatum. The users will be located in London and Seattle.
Technical Requirements
Contoso identifies the following technical requirements:
* AH users must be synced from AD DS to the contoso.com Azure AD tenant.
* App1 must have a redirect URI pointed to https://contoso.com/auth-response.
* License allocation for new users must be assigned automatically based on the location of the user.
* Fabrikam users must have access to the marketing department's SharePoint site for a maximum of 90 days.
* Administrative actions performed in Azure AD must be audited. Audit logs must be retained for one year.
* The helpdesk administrators must be able to manage licenses for only the users in their respective office.
* Users must be forced to change their password if there is a probability that the users' identity was compromised.
NEW QUESTION # 23
You have an Azure subscription that contains a user named User1. The subscription is onboarded to Microsoft Entra Permissions Management. You need to provide User! with access to Permissions Management. The solution must meet the following requirements:
* Follow the principle of least privilege.
* Minimize administrative effort.
What should you do first?
- A. From the My Requests subtab of Permissions Management, create a new request.
- B. From the Microsoft Entra admin center, create a security group.
- C. From the Role/Policy Template subtab of Permissions Management, create a template.
- D. From the Microsoft Entra admin center, assign a role to User1.
Answer: D
Explanation:
When onboarding to Microsoft Entra Permissions Management (a CIEM solution), before a user can perform any functions inside Permissions Management, that user must be granted an appropriate Permissions Management role in the Entra tenant. The principle of least privilege dictates that you grant only the minimal role necessary (for example, a Permissions Management Approver, Viewer, or Controller). The SC-300 study materials and Microsoft's documentation emphasize that administrative access must begin by assigning roles within Entra ID.
Creating a security group (option A) is a useful organizational practice but doesn't itself grant the user permissions inside Permissions Management.
Creating a role/policy template (option B) is about defining permission scopes and is not a first step to allow a user access.
Creating a request in My Requests (option D) presupposes that User1 already has some entitlement to make requests (i.e. some role), which they don't yet.
Therefore, the first action is to assign a Permissions Management role to User1 from the Entra admin center, thus giving them appropriate access while adhering to least privilege.
NEW QUESTION # 24
You have an Azure Active Directory (Azure AD) tenant that has Security defaults disabled.
You are creating a conditional access policy as shown in the following exhibit.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/howto-conditional-access-policy-all-u
NEW QUESTION # 25
You have an AzureAD tenant that contains the users shown in the following table.
You have the locations shown in the following table.
The tenantcontainsa named location that Das the following configurations:
* Name: location1
* Mark as trusted location: Enabled
* IPv4 range: 10.10.0.0/16
MFA has a trusted iPad dress range of 193.17.17.0/24.
You have a Conditional Access policy that has the following settings:
* Name: CAPolicy1
* Assignments
o Users or workload identities: Group 1
o Cloud apps or actions: All cloud apps
* Conditions
* Locations All trusted locations
* Access controls
o Gant
* Grant access: Require multi-factor authentication
Session: 0 controls selected
* Enable policy: On
For each of the following statements select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
NEW QUESTION # 26
You use Azure Monitor to analyze Azure Active Directory (Azure AD) activity logs.
Yon receive more than 100 email alerts each day for tailed Azure Al) user sign-in attempts.
You need to ensure that a new security administrator receives the alerts instead of you.
Solution: From Azure monitor, you create a data collection rule.
Does this meet the goal?
- A. No
- B. Yes
Answer: B
NEW QUESTION # 27
Drag and Drop Question
You have a Microsoft 365 E5 subscription.
You need to perform the following tasks:
- Identify the locations and IP addresses used by Azure AD users to
sign in.
- Review the Azure AD security settings and identify improvement
recommendations.
- Identify changes to Azure AD users or service principals.
What should you use for each task? To answer, drag the appropriate resources to the correct requirements. Each resource may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 28
You have a Microsoft 365 tenant that has 5,000 users. One hundred of the users are executives. The executives have a dedicated support team.
You need to ensure that the support team can reset passwords and manage multi-factor authentication (MFA) settings for only the executives. The solution must use the principle of least privilege.
Which object type and Azure Active Directory (Azure AD) role should you use? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
NEW QUESTION # 29
You have an Azure AD tenant.
You need to bulk create 25 new user accounts by uploading a template file.
Which properties are required in the template file?
- A. Option B
- B. Option A
- C. Option D
- D. Option C
Answer: A
NEW QUESTION # 30
Your company has a Microsoft 365 tenant.
All users have computers that run Windows 10 and are joined to the Azure Active Directory (Azure AD) tenant.
The company subscribes to a third-party cloud service named Service1. Service1 supports Azure AD authentication and authorization based on OAuth. Service1 is published to the Azure AD gallery.
You need to recommend a solution to ensure that the users can connect to Service1 without being prompted for authentication. The solution must ensure that the users can access Service1 only from Azure AD-joined computers. The solution must minimize administrative effort.
What should you recommend for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/develop/active-directory-how-applications-are-added
https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/require-managed-devices
NEW QUESTION # 31
You have a Microsoft 365 E5 subscription.
You need to create a dynamic user group that will include all the users that do NOT have a department defined in their user profile.
How should you complete the membership rule? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
NEW QUESTION # 32
You need to configure app registration in Azure AD to meet the delegation requirements.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/roles/delegate-app-roles
NEW QUESTION # 33
......
SC-300 Dumps To Pass Microsoft Exam in 24 Hours - UpdateDumps: https://prepaway.updatedumps.com/Microsoft/SC-300-updated-exam-dumps.html