Microsoft

SC-300 Free Practice Questions

This is the free Microsoft SC-300 practice question bank — 200 of 387 total questions, each with a full explanation, free to read with no signup required. Updated 2026-08-06.

Every answer is verified against official Microsoft documentation — see our methodology.

Question 1

Your network contains an on-premises Active Directory Domains Services (AD DS) domain named contoso.com and a web app named WebApp1. WebAppl uses Integrated Windows authentication. Remote users access WebApp1 by establishing a VPN connection to the on-premises network and using a URL of https//webapp1.contoso.com. You have a Microsoft Entra tenant that syncs with contoso.com. You perform the following actions: • Deploy Microsoft Entra Private Access. • Configure a connector group that contains a connector named Connector1. You need to ensure that the remote users can access WebApp1 by using Microsoft Entra Private Access. What should you do?

A. Enroll the remote users’ devices in Microsoft Defender for Endpoint.
B. Deploy Microsoft Entra Internet Access.
C. Create a Conditional Access policy.
D. Create an application segment.
Show Answer
Correct Answer: D
Explanation:
Microsoft Entra Private Access publishes private on-premises applications by defining application segments that map the application's FQDN/IP and ports to a connector group. To allow access to https://webapp1.contoso.com through Private Access, you must create an application segment for the web app. Microsoft Entra Internet Access is for internet/SaaS traffic, Defender enrollment is not required for basic access, and a Conditional Access policy is optional for access control but does not publish the application.

Question 2

You have a Microsoft Entra tenant named contoso.com. You have a query named Query1 that contains the following statements. You need to ensure that you can run Query1 against the Microsoft Entra activity logs. The solution must minimize administrative effort. What should you do first?

A. From Diagnostic settings in the Microsoft Entra admin center, send the logs to a Log Analytics workspace.
B. From Diagnostic settings in the Microsoft Entra admin center, stream the logs to an Azure event hub.
C. From Diagnostic settings in the Microsoft Entra admin center, archive the logs to a storage account.
D. From the Azure portal, create a data collection rule (DCR).
Show Answer
Correct Answer: A
Explanation:
To run Kusto queries against Microsoft Entra activity logs, the logs must first be sent to an Azure Monitor Log Analytics workspace via Microsoft Entra diagnostic settings. Streaming to Event Hubs or archiving to Storage does not make the logs directly queryable in Log Analytics, and creating a DCR is not the required first step for Microsoft Entra diagnostic logs.

Question 4

HOTSPOT - You have a Microsoft Entra tenant that contains the users shown in the following table. The tenant contains the identities shown in the following table. You have an attribute set named Custom1 that contains the custom security attributes shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-300 question 4 Illustration for SC-300 question 4 Illustration for SC-300 question 4 Illustration for SC-300 question 4
Show Answer
Correct Answer: No Yes No
Explanation:
Global Administrators do not automatically have permission to assign custom security attributes. Attribute Assignment Administrators can assign/update attribute values on supported objects (users and service principals), but not define attribute schema. Custom security attributes cannot be assigned to groups.

Question 5

You have a Microsoft Entra tenant. You need to configure protected actions to require privileged users to use phishing-resistant multifactor authentication (MFA). What should you do first?

A. Create an access package.
B. Configure an authentication strength for the tenant.
C. Add an authentication context.
D. Create a Conditional Access policy.
Show Answer
Correct Answer: C
Explanation:
To use protected actions with phishing-resistant MFA, you first add an authentication context. The authentication context is then referenced by a Conditional Access policy that enforces an authentication strength requiring phishing-resistant MFA. Authentication strengths and Conditional Access are configured afterward, so the initial step is to create the authentication context.

Question 6

You have a Microsoft 365 tenant. All users have mobile phones and Windows 11 laptops. The users frequently work from remote locations that do not have Wi-Fi access or mobile phone connectivity. While working from the remote locations, the users connect their laptop to a wired network that has internet access. You plan to implement multi-factor authentication (MFA). Which MFA authentication method can the users use from the remote location?

A. email В. Windows Hello for Business
C. voice
D. an app password
Show Answer
Correct Answer: B
Explanation:
Windows Hello for Business can satisfy MFA on a Windows 11 device using a device-bound credential (PIN/biometric plus TPM-backed key) and only requires the laptop's internet connection. Email is not a Microsoft Entra MFA method, voice requires phone connectivity, and app passwords are legacy credentials that do not perform MFA. Sources: https://www.brainscape.com/flashcards/sc-300-set-2-15459532/packs/21970233

Question 7

HOTSPOT - You have a Microsoft Entra tenant that contains two remote networks named RemoteNetwork1 and RemoteNetwork2 and the users shown in the following table. You have the devices shown in the following table. You have a Conditional Access policy that has the following settings: o Name: CAPolicy1 o Assignments - Users: Group1, Group2 - Target resources: All internet resources with Global Secure Access o Access controls - Grant: Require multifactor authentication o Enable policy: On Global Secure Access traffic forwarding is configured as shown in the following exhibit. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-300 question 7 Illustration for SC-300 question 7 Illustration for SC-300 question 7 Illustration for SC-300 question 7
Show Answer
Correct Answer: Yes No No
Explanation:
The Conditional Access policy targets Global Secure Access internet resources. User1's traffic is covered through the assigned remote network. User2's device does not use Global Secure Access. User3 uses a remote network that is not assigned to the Microsoft traffic profile, so the policy is not applied.

Question 8

HOTSPOT - You have a Microsoft Entra tenant named contoso.com that contains a user named User1. User1 has the devices shown in the following table: On November 5, 2025, you create and enforce terms of use in contoso.com that has the following settings: • Name: Terms1 • Display name: Contoso terms of use • Require users to expand the terms of use: On • Require users to consent on every device: On • Expire consents: On • Expire starting on: December 10, 2025 • Frequency: Monthly On November 15, 2025, User1 accepts Terms1 on Device3. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-300 question 8 Illustration for SC-300 question 8
Show Answer
Correct Answer: Yes No Yes
Explanation:
Per-device consent requires a Microsoft Entra-registered device. Device1 is registered and has not yet accepted, so acceptance is allowed. Device2 is not registered, so per-device terms cannot be accepted. Device3 already accepted on Nov 15; monthly expiration starts Dec 10, so on Dec 7 the existing consent is still valid.

Question 9

You have a Microsoft Entra tenant. You need to use Microsoft Entra workbooks to monitor identity activity. To what should you set Destination details in the Diagnostic settings?

A. Archive to a storage account
B. Send to partner solution
C. Stream to an event hub
D. Send to Log Analytics workspace
Show Answer
Correct Answer: D
Explanation:
Microsoft Entra workbooks visualize identity data by querying logs stored in an Azure Log Analytics workspace using Kusto Query Language (KQL). Therefore, Microsoft Entra diagnostic settings must be configured to send the relevant logs (such as sign-in and audit logs) to a Log Analytics workspace.

Question 10

You have 2,500 users who are assigned Microsoft 365 E3 licenses. The licenses are assigned to individual users. You assign Microsoft 365 E5 licenses to a group that includes all users. You need to remove the Microsoft 365 E3 licenses from the users by using the least amount of administrative effort. What should you use?

A. the Update-MgGroup cmdlet
B. the Set-WindowsProductKey cmdlet
C. the Set-MgUserLicense cmdlet
D. the Licenses blade in the Microsoft Entra admin center
Show Answer
Correct Answer: C
Explanation:
Set-MgUserLicense is the Microsoft Graph PowerShell cmdlet used to add or remove licenses from users. Since the existing Microsoft 365 E3 licenses were assigned directly to individual users, moving to a group-based E5 assignment does not automatically remove the direct E3 assignments. The appropriate way to remove those direct licenses in bulk via PowerShell is Set-MgUserLicense. Update-MgGroup does not manage license removal from users, Set-WindowsProductKey is unrelated, and the Entra admin center does not provide the required bulk removal workflow for individually assigned licenses.

Question 11

HOTSPOT - You have a Microsoft Entra tenant that contains the users shown in the following table. The tenant contains the administrative units shown in the following table. The tenant contains the groups shown in the following table. You perform the following actions: • Assign User1 the User Administrator role for AU2. • Assign User3 the Groups Administrator role for AU1. • Assign User5 the Authentication Administrator role for AU3. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-300 question 11 Illustration for SC-300 question 11 Illustration for SC-300 question 11 Illustration for SC-300 question 11
Show Answer
Correct Answer: Yes No No
Explanation:
A User Administrator scoped to AU2 can reset passwords for users in AU2. A Groups Administrator scoped to AU1 cannot manage a group in AU2. An Authentication Administrator cannot configure tenant authentication method policies for a group's members; that requires authentication policy administration rather than user authentication method management.

$19

Get all 387 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.