Microsoft

SC-300 Free Practice Questions — Page 6

Question 33

HOTSPOT - You have a Microsoft 365 E5 subscription that contains two groups named Group1 and Group2 and the users shown in the following table. The subscription contains a Conditional Access policy that has the following settings: • Name: Policy1 • Assignments o Include - Users and Groups: Group1 - Directory roles: Global Administrator o Exclude - Users and Groups: Group2 o Target resources - Include - All cloud apps - Access controls - Grant - Require multifactor authentication For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-300 question 33 Illustration for SC-300 question 33
Show Answer
Correct Answer: User1: Yes User2: No User3: No
Explanation:
Policy includes Group1 and the Global Administrator role, but excludes Group2. Exclusions override inclusions in Conditional Access. User1 is only in Group1 → MFA required. User2 is in Group1 and Group2 → excluded → no MFA. User3 is a Global Administrator but is in Group2 → excluded → no MFA.

Question 34

HOTSPOT - You have an Azure subscription that contains a resource group named RG1. RG1 contains two virtual machines named VM1 and VM2 that have Microsoft Entra ID login enabled. The subscription contains the users shown in the following table. Which users can sign in to VM1, and which users can sign in to VM2? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-300 question 34 Illustration for SC-300 question 34
Show Answer
Correct Answer: VM1: User1 and User3 only VM2: User1 only
Explanation:
VM sign-in requires Virtual Machine User Login or Virtual Machine Administrator Login. User1 has VM User Login at subscription scope, so can sign in to all VMs. User3 has VM Administrator Login scoped to VM1 only. User2 is Virtual Machine Contributor, which allows management but not OS sign-in.

Question 35

HOTSPOT - You have a Microsoft 365 E5 subscription that contains a Microsoft Teams team named Team1 and two Microsoft 365 groups named Group1 and Group2. The subscription contains the users shown in the following table. You create an access package that has the following settings: • Name: Package1 • Resource roles: o Team1: Owner • Users who can request access: For users in your directory o Specific Users and Groups: Group1 • Require approval: Yes o Require requestor justification: No o How many stages: 1 o First Approver: Team1, User3 o Require approver justification: Yes • Enable new requests: Yes • Expiration: o Access package assignments expire: 7 days o Users can request specific timeline: Yes For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-300 question 35 Illustration for SC-300 question 35
Show Answer
Correct Answer: Yes No No
Explanation:
Only members of Group1 can request the access package, so User1 is eligible while User2 is not. Although User3 is listed as an approver, approvers cannot approve their own access package requests, regardless of being a Global Administrator.

Question 36

You have an Azure subscription that is linked to a Microsoft Entra tenant. The tenant contains the groups shown in the following table. Which groups can you manage by using Privileged Identity Management (PIM)?

A. Group2 only
B. Group1 and Group2 only
C. Group2 and Group4 only
D. Group1, Group2, and Group3 only
E. Group1, Group2, Group3, and Group4
Show Answer
Correct Answer: A
Explanation:
Privileged Identity Management (PIM) for Groups supports managing Microsoft Entra security groups. From the typical group types shown in such questions, Group2 represents a standard security group that can be managed by PIM. Other groups (such as Microsoft 365 groups or unsupported group configurations like dynamic groups) cannot be managed by PIM for Groups. Although role‑assignable security groups can also work with PIM, they are not consistently represented as a correct option set here. From the given choices, the only fully correct answer is Group2 only.

Question 37

HOTSPOT - You have a Microsoft Entra tenant that contains a user named User1. You have an Azure subscription named Sub1. User1 is assigned the Owner role for Sub1. You need to ensure that User1 can onboard Sub1 to Permissions Management. The solution must follow the principle of least privilege. Which role should you assign for Sub1, and which role should you assign to User1 for the tenant? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-300 question 37
Show Answer
Correct Answer: Sub1: User Access Administrator Tenant: Permissions Management Administrator
Explanation:
Onboarding a subscription to Permissions Management requires the ability to manage role assignments at the subscription scope (User Access Administrator is sufficient and least-privileged). At the tenant scope, the Permissions Management Administrator role allows onboarding and managing the service without granting broader global admin privileges.

Question 38

HOTSPOT - You have a Microsoft 365 subscription. You configure a Global Secure Access security profile named SecurityProfile1. You need to create a Conditional Access policy named CAPolicy1 that will use SecurityProfile1. Which two settings should you configure to ensure that CAPolicy1 uses SecurityProfile1? To answer, select the appropriate settings in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-300 question 38
Show Answer
Correct Answer: Target resources Session
Explanation:
To use a Global Secure Access security profile in a Conditional Access policy, you must scope the policy to the appropriate Target resources and then configure the Global Secure Access security profile under Session controls. The security profile is applied via Session, not Grant controls.

Question 40

HOTSPOT - You have two Microsoft Entra tenants named contoso.com and fabrikam.com. Contoso.com contains the users shown in the following table. Contoso.com contains the groups shown in the following table. You configure cross-tenant synchronization from contoso.com to fabrikam.com and enable cross-tenant synchronization for User3 and Group2. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-300 question 40 Illustration for SC-300 question 40 Illustration for SC-300 question 40
Show Answer
Correct Answer: User1: No User2: Yes User3: No
Explanation:
Cross-tenant synchronization only provisions users that are directly assigned or are direct members of an assigned group. Nested group membership isn’t evaluated. User2 is a direct member of Group1, which is nested in the assigned Group2, so only User2 is directly in scope. User1 is only an indirect (nested) member. Guest users aren’t synchronized from the source tenant.

Question 41

HOTSPOT - You have an Azure subscription named Sub1 that contains two storage accounts named storage1 and storage2 and the blob containers shown in the following table. Sub1 contains the users shown in the following table. Condition1 has the following definition: NOTE: Each correct selection is worth one point.

Illustration for SC-300 question 41 Illustration for SC-300 question 41 Illustration for SC-300 question 41 Illustration for SC-300 question 41
Show Answer
Correct Answer: User1 can read the contents of blob2: No User1 can read the contents of blob3: Yes User2 can read the contents of blob1: Yes
Explanation:
Condition1 denies read unless the container name equals cont1, so User1 cannot read blob2 (cont2) but can read blob3 (cont1 in storage2). User2 is Storage Blob Data Owner on storage1, and Condition2 restricts writes only, not reads, so reading blob1 is allowed.

Question 42

You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1. You need to enable Microsoft Defender for Cloud Apps session control for Site1. Which type of policy should you create first?

A. access
B. app governance
C. session
D. Conditional Access
Show Answer
Correct Answer: D
Explanation:
Microsoft Defender for Cloud Apps session control is enabled through Microsoft Entra ID Conditional Access. You must first create a Conditional Access policy that targets SharePoint Online and enables **Use Conditional Access App Control** under Session controls. Only after this is in place can Defender for Cloud Apps apply and enforce session policies for the site.

Question 43

You have an Azure subscription that contains two virtual machines named VM1 and VM2 and an Azure SQL managed instance named SQL1. You need to ensure that VM1 and VM2 can retrieve data from SQL1. The solution must minimize administrative effort. What should you create first?

A. a certificate
B. a shared access signature (SAS) token
C. a managed identity
D. a Microsoft Entra user account
Show Answer
Correct Answer: C
Explanation:
To allow VM1 and VM2 to access Azure SQL Managed Instance with minimal administrative effort, you should use managed identities. Managed identities provide automatic credential management and integrate directly with Microsoft Entra ID, enabling the VMs to authenticate to SQL1 without storing secrets, certificates, or passwords. Certificates require lifecycle management, SAS tokens are for Azure Storage rather than SQL, and Entra ID user accounts are intended for human access rather than service-to-service authentication.

$19

Get all 397 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.