Microsoft

SC-300 Free Practice Questions — Page 5

Question 43

HOTSPOT - You have a Microsoft Entra tenant that contains the users shown in the following table. The tenant contains the Microsoft 365 groups shown in the following table. You create an access review named Access1 that has the following settings: • Select what to review: Teams + Groups • Review scope: All Microsoft groups with guest users • Scope: Guest users only • Select reviewers: Users review their own access For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-300 question 43 Illustration for SC-300 question 43 Illustration for SC-300 question 43
Show Answer
Correct Answer: No No No
Explanation:
The review targets only guest users in Microsoft 365 groups with guest users. Self-review applies only to included guest users. Dynamic groups are excluded from this review scope, and member users are not included because the scope is guest users only.

Question 44

HOTSPOT - You have two Microsoft Entra tenants named contoso.com and fabrikam.com. Contoso.com contains the users shown in the following table. You configure cross-tenant synchronization from contoso.com to fabrikam.com by using the following settings: • Users and groups: Group1 • Provisioning Mode: Automatic • Attribute Mappings o Source Object Scope: Filter1, Filter2 Filter1 is configured as shown in the following table. Filter2 is configured as shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-300 question 44 Illustration for SC-300 question 44 Illustration for SC-300 question 44 Illustration for SC-300 question 44
Show Answer
Correct Answer: Yes No Yes
Explanation:
Only members of Group1 are in scope. Multiple clauses within a filter use AND logic; multiple filters use OR logic. User1 matches Filter1 (IT and job title present). User2 is not in Group1. User3 matches Filter2 because city 'Montreal' includes 'M'.

Question 45

HOTSPOT - Your network contains an on-premises Active Directory Domain Services (AD DS) domain named contoso.com. Contoso.com contains the identities shown in the following table. You have a Microsoft Entra tenant that contains a user named User1. You deploy Microsoft Entra Cloud Sync and configure a scoping filter by using the following string: CN=Group1,OU=OU1,DC=contoso,DC=com. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-300 question 45 Illustration for SC-300 question 45
Show Answer
Correct Answer: Yes No Yes
Explanation:
A Cloud Sync group scoping filter includes members of the specified group. User1 is a direct member of Group1 and is in scope. User2 is only a member of Group2 (nested membership under Group1 is not used for scoping), so User2 is out of scope. The scoped group object (Group1) is also synchronized.

Question 47

You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1 and a Microsoft Teams team named Team1. The subscription contains five security groups named Group1, Group2, Group3, Group4, and Group5. You need to implement access packages for Site1 and Team1. The solution must meet the following requirements: • Members of Group3 must be able to request access to Site1 only. • Members of Group1 must be able to request access to Site1 and Team1. • Members of Group4 must be able to request access to Site1 and Team1. • Only members of Group2 must be able to approve access package requests from Group1 members. • Only members of Group5 must be able to approve access package requests from Group3 and Group4 members. What is the minimum number of access packages you should create?

A. 2
B. 3
C. 4
D. 5
Show Answer
Correct Answer: A
Explanation:
The minimum is two access packages because access packages can contain multiple assignment policies. One package contains Site1 only for Group3 with Group5 as approver. A second package contains Site1 and Team1 with two policies: one allowing Group1 to request with Group2 as approver, and another allowing Group4 to request with Group5 as approver. This satisfies the different resource sets and distinct approval requirements with the fewest packages. Sources: https://learn.microsoft.com/en-us/previous-versions/microsoft-365/solutions/groups-teams-access-governance

Question 48

You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1. You need to be notified if a user downloads more than 50 files in one minute from Site1. Which type of policy should you create in the Microsoft Defender for Cloud Apps?

A. session policy
B. activity policy
C. file policy
D. app discovery policy
Show Answer
Correct Answer: B
Explanation:
Activity policies monitor user and admin activities in connected cloud apps and can generate alerts based on activity thresholds and repeated actions, such as a user downloading more than a specified number of files within a defined time window. Session policies govern real-time session control, file policies inspect stored files, and app discovery policies analyze discovered cloud app usage from network logs.

Question 49

SIMULATION - Use the following login credentials as needed: To enter your username, place your cursor in the Sign in box and click on the username below. To enter your password, place your cursor in the Enter password box and click on the password below. Microsoft 365 Username: Microsoft 365 Password: =1122334455667788 If the Microsoft 365 portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab. The following information is for technical support purposes only: Lab Instance: 99999999 - You need to lock out accounts for five minutes when they have 10 failed sign-in attempts. To complete this task, sign in to the appropriate admin center.

Show Answer
Correct Answer: Microsoft Entra admin center → Protection → Authentication methods → Password protection. Set Lockout threshold = 10. Set Lockout duration in seconds = 300 (5 minutes). Save the changes.
Explanation:
The smart lockout settings are configured under Password protection in the Microsoft Entra admin center. A 5-minute lockout equals 300 seconds, with a threshold of 10 failed sign-in attempts.

Question 50

SIMULATION - Use the following login credentials as needed: To enter your username, place your cursor in the Sign in box and click on the username below. To enter your password, place your cursor in the Enter password box and click on the password below. Microsoft 365 Username: Microsoft 365 Password: =1122334455667788 If the Microsoft 365 portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab. The following information is for technical support purposes only: Lab Instance: 99999999 - You need to implement additional security checks before the members of the sg-Executive can access any company apps. The members must meet one of the following conditions: • Connect by using a device that is marked as compliant by Microsoft Intune. • Connect by using client apps that are protected by app protection policies. To complete this task, sign in to the appropriate admin center.

Show Answer
Correct Answer: Microsoft Entra admin center → Protection → Conditional Access → New policy Users: sg-Executive Target resources: All cloud apps Conditions: Client apps → Mobile apps and desktop clients Grant: Require device to be marked as compliant OR Require app protection policy (set 'Require one of the selected controls') Enable policy.
Explanation:
Create a Conditional Access policy targeting the executive group and all cloud apps. Limit to mobile/desktop client apps and configure grant controls so access is allowed if either the device is compliant or the app is protected by an app protection policy.

Question 51

SIMULATION - Use the following login credentials as needed: To enter your username, place your cursor in the Sign in box and click on the username below. To enter your password, place your cursor in the Enter password box and click on the password below. Microsoft 365 Username: Microsoft 365 Password: =1122334455667788 If the Microsoft 365 portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab. The following information is for technical support purposes only: Lab Instance: 99999999 - You need to deploy multi factor authentication (MFA). The solution must meet the following requirements: • Require MFA registration only for members of the sg-Finance group. • Exclude Debra Berger from having to register for MFA. • Implement the solution without using a Conditional Access policy. To complete this task, sign in to the appropriate admin center.

Show Answer
Correct Answer: Microsoft Entra admin center → Protection → Identity Protection → Multifactor authentication registration policy Include: sg-Finance Exclude: Debra Berger Policy enforcement: Enabled
Explanation:
Use the MFA registration policy (not Conditional Access). Scope the policy to the sg-Finance group, exclude Debra Berger, and enable enforcement so only the targeted group must register for MFA.

Question 52

SIMULATION - Use the following login credentials as needed: To enter your username, place your cursor in the Sign in box and click on the username below. To enter your password, place your cursor in the Enter password box and click on the password below. Microsoft 365 Username: Microsoft 365 Password: =1122334455667788 If the Microsoft 365 portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab. The following information is for technical support purposes only: Lab Instance: 99999999 - You need to ensure that users in the sg-Legal group must reauthenticate every 12 hours when they access any cloud apps managed by the tenant. To complete this task, sign in to the appropriate admin center.

Show Answer
Correct Answer: Microsoft Entra admin center Protection → Conditional Access → New policy Assignments: Users = sg-Legal Target resources: All cloud apps Access controls → Session: Sign-in frequency = Every 12 hours Enable policy: On
Explanation:
Use a Conditional Access policy targeting the sg-Legal group and all cloud apps, configuring the session sign-in frequency to 12 hours so users must reauthenticate every 12 hours.

Question 53

You have a Microsoft Entra tenant that contains an access package named Package1 and a user named User1. Package1 is configured as shown in the following exhibit. You need to ensure that User1 can modify the review frequency of Package1. The solution must use the principle of least privilege. Which role should you assign to User1?

A. Privileged Role Administrator
B. External Identity Provider Administrator
C. Identity Governance Administrator
D. Security Administrator
Show Answer
Correct Answer: C
Explanation:
Modifying the review frequency of an access package is an identity governance management task. The Identity Governance Administrator role has permissions to manage entitlement management, including access packages and their access reviews, while the other listed roles do not provide the least-privileged access for this task.

$19

Get all 387 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.