New Year Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Microsoft SC-300 Practice Exam with Questions & Answers

Questions 1

You need to configure app registration in Azure AD to meet the delegation requirements.

What should you do? To answer, select the appropriate options in the answer area.

NOTE:Each correct selection is worth one point.

SC-300 Question 1

Options:
Microsoft SC-300 Premium Access
Questions 2

You have a Microsoft 365 tenant

You currently allow email clients that use Basic authentication to connect to Microsoft Exchange Online.

You need to ensure that users can connect to Exchange Online only from email clients that use Modern authentication protocols.

What should you implement?

Options:
A.

a Microsoft Defender for Cloud Apps OAuth policy

B.

a Microsoft Intune app protection policy

C.

a Microsoft Intune compliance policy

D.

a Microsoft Entra conditional access policy

Questions 3

You have a Microsoft 365 tenant.

The Azure Active Directory (Azure AD) tenant syncs to an on-premises Active Directory domain. The domain

contains the servers shown in the following table.

SC-300 Question 3

The domain controllers are prevented from communicating to the internet.

You implement Azure AD Password Protection on Server1 and Server2.

You deploy a new server named Server4 that runs Windows Server 2019.

You need to ensure that Azure AD Password Protection will continue to work if a single server fails.

What should you implement on Server4?

Options:
A.

Azure AD Connect

B.

Azure AD Application Proxy

C.

Password Change Notification Service (PCNS)

D.

the Azure AD Password Protection proxy service

Questions 4

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it as a result these questions will not appear in the review screen.

You have a Microsoft 365 E5 subscription.

You create a user named User1.

You need to ensure that User1 can update the status of identity Secure Score improvement actions.

Solution: You assign the User Administrator role to User1.

Does this meet the goal?

Options:
A.

Yes

B.

No

Questions 5

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have a Microsoft 365 tenant.

All users must use the Microsoft Authenticator app for multi-factor authentication (MFA) whenaccessing Microsoft 365 services.

Some users report that they received an MFA prompt on their Microsoft Authenticator app without initiating a sign-in request.

You need to block the users automatically when they report an MFA request that they did not initiate.

Solution: From the Azure portal, you configure the Notifications settings for multi-factor authentication (MFA).

Does this meet the goal?

Options:
A.

Yes

B.

No

Questions 6

You need to meet the authentication requirements for leaked credentials.

What should you do?

Options:
A.

Enable federation with PingFederate in Azure AD Connect.

B.

Configure Azure AD Password Protection.

C.

Enable password hash synchronization in Azure AD Connect.

D.

Configure an authentication method policy in Azure AD.

Questions 7

You have a Microsoft 365 E5 subscription.

You plan to deploy a third-party software as a service (SaaS) app named App1.

You need to onboard App1 to Microsoft Defender for Cloud Apps. The solution must ensure that you can implement session control policies.

What should you do first?

Options:
A.

From the Microsoft Defender portal, configure Cloud discovery.

B.

From the Microsoft Entra admin center, configure a traffic forwarding profile.

C.

From the Microsoft Entra admin center, configure single sign-on (SSO) for App1.

D.

From the Microsoft Defender portal, create an OAuth app policy.

Questions 8

You have multiple on-premises devices that run either Windows or Linux.

You have a Microsoft 365 E5 subscription.

You configure Microsoft Entra Internet Access.

You need to ensure that all the on-premises devices route internet traffic through Global Secure Access for security policy evaluation.

What should you do in the Microsoft Entra admin center?

Options:
A.

Deploy the Global Secure Access client.

B.

Create a remote network.

C.

Create a named location.

D.

Create an access package.

Questions 9

You have a Microsoft 365 E5 subscription. You need to perform the following tasks:

• Identify the locations and IP addresses used by Azure AD users to sign in

• Review the Azure AD security settings and identify improvement recommendations.

• Identify changes to Azure AD users or service principle.

What should you use for each task? To answer, drag the appropriate resources to the correct requirements. Each resource may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

SC-300 Question 9

Options:
Questions 10

You have a Microsoft Entra tenant that contains a user named User1.

An administrator deletes User1. You need to identify the following:

• What is the maximum number of days for which you have the option to restore the User1 account?

• Which is the least privileged role that can be used to restore User1?

To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

SC-300 Question 10

Options:
Exam Code: SC-300
Certification Provider: Microsoft
Exam Name: Microsoft Identity and Access Administrator
Last Update: Dec 15, 2025
Questions: 343