This is the free Microsoft SC-300 practice question bank —
200 of 397 total questions, each with a full explanation, free to
read with no signup required. Updated 2026-04-24.
Every answer is verified against official Microsoft documentation —
see our methodology.
Question 1
You have a Microsoft Entra tenant.
You have 500 devices that run either Windows 11, macOS, iOS, or Android and are enrolled in Microsoft Intune.
You plan to deploy the Global Secure Access client.
From the Microsoft Entra admin center, you download the Global Secure Access client for each operating system.
You need to deploy the client to the macOS devices by using Intune.
Which file extension should you use when uploading the client to Intune?
A. .ipa
B. .apk
C. .intunewin
D. .pkg
Show Answer
Correct Answer: D
Explanation: For macOS app deployment through Microsoft Intune, the supported installer format is a macOS package (.pkg). The Global Secure Access client downloaded for macOS is provided as a .pkg file and should be uploaded to Intune as such. The other extensions correspond to iOS (.ipa), Android (.apk), or Windows app packaging (.intunewin).
Question 1
You have a Microsoft Entra tenant.
You need to configure protected actions to require privileged users to use phishing-resistant multifactor authentication (MFA).
What should you do first?
A. Create an access package.
B. Configure an authentication strength for the tenant.
C. Add an authentication context.
D. Create a Conditional Access policy.
Show Answer
Correct Answer: C
Explanation: Protected actions in Microsoft Entra are enforced by combining Conditional Access with authentication contexts. Before you can target protected actions and require phishing-resistant MFA, you must first create (add) an authentication context. Conditional Access policies and authentication strengths are applied afterward using that context, so adding the authentication context is the initial required step.
Question 2
You have on-premises Linux devices.
You have a Microsoft 365 E5 subscription.
You plan to configure Global Secure Access Internet Access.
You need to ensure that the devices can connect to Global Secure Access.
What should you do?
A. Configure the Adaptive Access settings.
B. Install the Azure Connected Machine agent on the devices.
C. Create a remote network.
D. Deploy a private network connector.
Show Answer
Correct Answer: C
Explanation: Global Secure Access requires a supported client to onboard devices directly. There is no Global Secure Access client for Linux, so Linux devices cannot connect individually. To enable connectivity from on-premises Linux devices, you must configure a Remote Network, which uses an IPsec tunnel from your on-premises network to Global Secure Access, allowing all devices on that network to access Internet Access features.
Question 2
You have a Microsoft 365 tenant.
All users have mobile phones and Windows 11 laptops.
The users frequently work from remote locations that do not have Wi-Fi access or mobile phone connectivity. While working from the remote locations, the users connect their laptop to a wired network that has internet access.
You plan to implement multi-factor authentication (MFA).
Which MFA authentication method can the users use from the remote location?
A. email В. Windows Hello for Business
C. voice
D. an app password
Show Answer
Correct Answer: B
Explanation: From the remote location, users have no Wi‑Fi or mobile phone connectivity, but their Windows 11 laptops do have wired internet access. MFA methods that rely on phones or mobile networks (email, voice calls, app passwords) are therefore not usable. Windows Hello for Business works directly on the Windows 11 device using TPM‑backed keys unlocked by PIN or biometrics and only requires internet connectivity from the laptop to validate with Microsoft Entra ID, making it the only viable option.
Question 3
You have an Azure subscription that contains a user named User1 and an Azure key vault named Vault1.
You need to ensure that User1 can read the metadata of certificates, keys, and secrets stored in Vault1. The solution must follow the principle of least privilege.
Which role should you assign to User1?
A. Key Vault Secrets User
B. Key Vault Crypto User
C. Key Vault Reader
D. Key Vault Crypto Officer
Show Answer
Correct Answer: C
Explanation: Key Vault Reader allows viewing the key vault and reading metadata for keys, secrets, and certificates without granting access to their values or cryptographic operations, which satisfies the requirement with least privilege.
Question 3
HOTSPOT
-
You have a Microsoft Entra tenant that contains two remote networks named RemoteNetwork1 and RemoteNetwork2 and the users shown in the following table.
You have the devices shown in the following table.
You have a Conditional Access policy that has the following settings:
o Name: CAPolicy1
o Assignments
- Users: Group1, Group2
- Target resources: All internet resources with Global Secure Access
o Access controls
- Grant: Require multifactor authentication
o Enable policy: On
Global Secure Access traffic forwarding is configured as shown in the following exhibit.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Explanation: CAPolicy1 targets users in Group1 and Group2 accessing all internet resources via Global Secure Access. RemoteNetwork1 is assigned to the Microsoft traffic profile, so traffic from RemoteNetwork1 is evaluated by the policy regardless of client deployment. User1 and User2 are members of Group1 and access resources through RemoteNetwork1, so MFA is required. User3 is in Group2, but RemoteNetwork2 is not assigned to the traffic forwarding profile, so the policy does not apply.
Question 4
You have a Microsoft 365 E5 subscription.
You create an access review named Review1. Review1 requires that every six months, Microsoft 365 group owners review guest user access to their groups.
You need to ensure that if the group owners fail to review the membership of Review1, guest users are removed automatically.
Which settings should you configure for Review1?
A. Reviewers
B. General
C. Advanced settings
D. Upon completion settings
Show Answer
Correct Answer: D
Explanation: To ensure that guest users are automatically removed when group owners fail to complete the access review, you must configure the **Upon completion settings** of the access review. These settings control what happens if reviewers do not respond by the review deadline, including options to automatically remove access for users who are not reviewed.
Question 4
HOTSPOT
-
You have a Microsoft Entra tenant named contoso.com that contains a user named User1.
User1 has the devices shown in the following table:
On November 5, 2025, you create and enforce terms of use in contoso.com that has the following settings:
• Name: Terms1
• Display name: Contoso terms of use
• Require users to expand the terms of use: On
• Require users to consent on every device: On
• Expire consents: On
• Expire starting on: December 10, 2025
• Frequency: Monthly
On November 15, 2025, User1 accepts Terms1 on Device3.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
No
No
Explanation: The terms of use are configured as per-device consent, which requires each registered device to accept separately.
• Device1 is registered and has not accepted yet, so User1 can accept on November 20.
• Device2 is not registered in Microsoft Entra ID, so per-device terms of use cannot be accepted on December 11.
• Device3 already accepted on November 15 and the consent does not expire until December 10, so no new acceptance is possible on December 7.
Question 5
You have a Microsoft 365 subscription.
You need to ensure that users can grant enterprise applications access to their profile. The solution must ensure that the users can consent only to the User.Read and profile delegated permissions.
What should you configure first?
A. Identity Protection settings
B. Permission classifications
C. Admin consent settings
D. Security defaults
Show Answer
Correct Answer: B
Explanation: To allow users to consent only to specific delegated permissions, you must first configure Permission classifications in Microsoft Entra ID. By classifying User.Read and profile as low‑impact permissions, you can then restrict user consent settings so users are allowed to consent only to those classified permissions. Other options do not provide permission‑level control over user consent.
Question 5
You have a Microsoft Entra tenant.
You need to use Microsoft Entra workbooks to monitor identity activity.
To what should you set Destination details in the Diagnostic settings?
A. Archive to a storage account
B. Send to partner solution
C. Stream to an event hub
D. Send to Log Analytics workspace
Show Answer
Correct Answer: D
Explanation: Microsoft Entra workbooks are Azure Workbooks that query identity logs using Kusto Query Language (KQL). These logs (such as SignInLogs and AuditLogs) must be sent via Diagnostic settings to a Log Analytics workspace, which is the required data source for Entra workbooks.
$19
Get all 397 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.