Microsoft

SC-300 Free Practice Questions — Page 5

Question 23

You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1 and a Microsoft Teams team named Team1. The subscription contains five security groups named Group1, Group2, Group3, Group4, and Group5. You need to implement access packages for Site1 and Team1. The solution must meet the following requirements: • Members of Group3 must be able to request access to Site1 only. • Members of Group1 must be able to request access to Site1 and Team1. • Members of Group4 must be able to request access to Site1 and Team1. • Only members of Group2 must be able to approve access package requests from Group1 members. • Only members of Group5 must be able to approve access package requests from Group3 and Group4 members. What is the minimum number of access packages you should create?

A. 2
B. 3
C. 4
D. 5
Show Answer
Correct Answer: A
Explanation:
In Microsoft Entra Entitlement Management, a single access package can contain multiple assignment policies as long as the resources are the same. You need one package for the resource set Site1 + Team1 and one package for Site1 only. Access package 1 (Site1 + Team1): - Policy 1: Requesters = Group1, Approvers = Group2 - Policy 2: Requesters = Group4, Approvers = Group5 Access package 2 (Site1 only): - Policy 1: Requesters = Group3, Approvers = Group5 This satisfies all requester and approver requirements with the minimum number of access packages.

Question 24

You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1. You need to be notified if a user downloads more than 50 files in one minute from Site1. Which type of policy should you create in the Microsoft Defender for Cloud Apps?

A. session policy
B. activity policy
C. file policy
D. app discovery policy
Show Answer
Correct Answer: B
Explanation:
An activity policy in Microsoft Defender for Cloud Apps is designed to monitor and alert on specific user actions recorded in activity logs, such as file downloads. It can be configured to detect repeated activities (e.g., more than 50 file downloads within one minute) for a specific app like SharePoint Online and even scoped to a particular site. Other policy types do not monitor real-time user activity patterns in this way.

Question 25

SIMULATION - Use the following login credentials as needed: To enter your username, place your cursor in the Sign in box and click on the username below. To enter your password, place your cursor in the Enter password box and click on the password below. Microsoft 365 Username: Microsoft 365 Password: =1122334455667788 If the Microsoft 365 portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab. The following information is for technical support purposes only: Lab Instance: 99999999 - You need to lock out accounts for five minutes when they have 10 failed sign-in attempts. To complete this task, sign in to the appropriate admin center.

Show Answer
Correct Answer: Microsoft Entra admin center Protection > Authentication methods > Password protection Lockout threshold: 10 Lockout duration (seconds): 300
Explanation:
Configure Microsoft Entra smart lockout so that an account is locked after 10 failed sign-in attempts and remains locked for 300 seconds (5 minutes). This setting is managed under Password protection in the Entra admin center.

Question 26

SIMULATION - Use the following login credentials as needed: To enter your username, place your cursor in the Sign in box and click on the username below. To enter your password, place your cursor in the Enter password box and click on the password below. Microsoft 365 Username: Microsoft 365 Password: =1122334455667788 If the Microsoft 365 portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab. The following information is for technical support purposes only: Lab Instance: 99999999 - You need to implement additional security checks before the members of the sg-Executive can access any company apps. The members must meet one of the following conditions: • Connect by using a device that is marked as compliant by Microsoft Intune. • Connect by using client apps that are protected by app protection policies. To complete this task, sign in to the appropriate admin center.

Show Answer
Correct Answer: Create a Conditional Access policy Users: sg-Executive Cloud apps: All cloud apps Conditions: Client apps → Mobile apps and desktop clients Access controls (Grant): Require device to be marked as compliant Require app protection policy Require one of the selected controls Enable policy
Explanation:
Conditional Access enforces extra security before app access. Targeting the sg-Executive group and all cloud apps ensures full coverage. Limiting to mobile and desktop clients applies the checks to relevant sign-ins. Grant controls are configured so access is allowed only if the user signs in from an Intune-compliant device or uses apps protected by app protection policies, with the policy enabled to take effect.

Question 27

SIMULATION - Use the following login credentials as needed: To enter your username, place your cursor in the Sign in box and click on the username below. To enter your password, place your cursor in the Enter password box and click on the password below. Microsoft 365 Username: Microsoft 365 Password: =1122334455667788 If the Microsoft 365 portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab. The following information is for technical support purposes only: Lab Instance: 99999999 - You need to deploy multi factor authentication (MFA). The solution must meet the following requirements: • Require MFA registration only for members of the sg-Finance group. • Exclude Debra Berger from having to register for MFA. • Implement the solution without using a Conditional Access policy. To complete this task, sign in to the appropriate admin center.

Show Answer
Correct Answer: Microsoft Entra admin center Protection > Identity Protection > MFA registration policy Assignments: Include sg-Finance Assignments: Exclude Debra Berger Policy enforcement: On
Explanation:
The Microsoft Entra MFA registration policy allows enforcing MFA registration for specific users or groups without using Conditional Access. Including the sg-Finance group targets only required users, excluding Debra Berger meets the exception requirement, and enabling the policy enforces MFA registration.

Question 28

SIMULATION - Use the following login credentials as needed: To enter your username, place your cursor in the Sign in box and click on the username below. To enter your password, place your cursor in the Enter password box and click on the password below. Microsoft 365 Username: Microsoft 365 Password: =1122334455667788 If the Microsoft 365 portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab. The following information is for technical support purposes only: Lab Instance: 99999999 - You need to ensure that users in the sg-Legal group must reauthenticate every 12 hours when they access any cloud apps managed by the tenant. To complete this task, sign in to the appropriate admin center.

Show Answer
Correct Answer: Microsoft Entra admin center Protection → Conditional Access → New policy Users: sg-Legal Cloud apps: All cloud apps Session: Sign-in frequency = 12 hours Enable policy
Explanation:
A Conditional Access policy with a session control for sign-in frequency enforces periodic reauthentication. Targeting the sg-Legal group and all cloud apps, and setting the sign-in frequency to 12 hours ensures users must reauthenticate every 12 hours across the tenant.

Question 29

HOTSPOT - You have an Azure subscription that uses Microsoft Entra Permissions Management. You have an Amazon Web Services (AWS) account. You plan to connect Permissions Management to AWS. You need to create a Permissions Management app in Azure. How should you complete the PowerShell command? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-300 question 29
Show Answer
Correct Answer: New-AzureADApplication -IdentifierUris
Explanation:
Creating the Permissions Management app requires a new Azure AD application and setting its application ID URI (api://...) using the IdentifierUris parameter.

Question 30

HOTSPOT - You have a Microsoft Entra tenant that contains the users shown in the following table. You add the following assignment for the User Administrator role: • Scope type: Directory • Selected members: Group1 • Assignment type: Active • Assignments starts: August 15, 2022 • Assignment ends: December 15, 2022 You add the following assignment for the Exchange Administrator role: • Scope type: Directory • Selected members: Group2 • Assignment type: Eligible • Assignments starts: October 15, 2022 • Assignment ends: January 15, 2023 For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-300 question 30 Illustration for SC-300 question 30
Show Answer
Correct Answer: Yes No Yes
Explanation:
Admin1 is an active User Administrator via Group1 during Nov 15, 2022, so can reset passwords for non-privileged users like Admin2. Admin2 only has an eligible Exchange Administrator role on Oct 15, 2022 and must activate it before administering Exchange Online. Admin3 is an active User Administrator via Group1 on Sep 1, 2022 and can reset the password of Admin1, who has no privileged role at that time.

Question 31

HOTSPOT - You have a Microsoft Entra tenant that contains a user named User1. An administrator deletes User1. You need to identify the following: • What is the maximum number of days for which you have the option to restore the User1 account? • Which is the least privileged role that can be used to restore User1? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-300 question 31
Show Answer
Correct Answer: 30 days User Administrator
Explanation:
Deleted Microsoft Entra user accounts can be restored from the recycle bin for up to 30 days after deletion. The least privileged role that can restore deleted users is the User Administrator role.

Question 32

DRAG DROP - Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that runs Windows Server and hosts a shared folder named Share1. The domain contains 500 devices that run Windows 11. You have a Microsoft 365 E5 subscription that syncs with the domain. From Global Secure Access, you enable the Private access profile and deploy the Global Secure Access client to all the devices. You need to ensure that the devices can connect to Share1 remotely by using Global Secure Access. Which three actions should you perform in sequence? To answer move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Illustration for SC-300 question 32
Show Answer
Correct Answer: Install a connector on Server1. Create an enterprise application. Create an application segment.
Explanation:
The connector establishes secure connectivity from Microsoft Global Secure Access to the on-premises server. An enterprise application is then defined to represent the resource. Finally, an application segment specifies the server IP and ports (SMB) so traffic to Share1 is routed through Global Secure Access.

$19

Get all 397 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.