Big Halloween Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Microsoft SC-300 Practice Exam with Questions & Answers | Set: 4

Questions 31

You implement the planned changes for SSPR.

What occurs when User3 attempts to use SSPR? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

SC-300 Question 31

Options:
Microsoft SC-300 Premium Access
Questions 32

You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Cloud Apps.

You need to identify which users access Facebook from their devices and browsers. The solution must minimize administrative effort.

What should you do first?

Options:
A.

From the Microsoft Defender for Cloud Apps portal, unsanctioned Facebook.

B.

Create an app configuration policy in Microsoft Endpoint Manager.

C.

Create a Defender for Cloud Apps access policy.

D.

Create a Conditional Access policy.

Questions 33

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have an Azure Active Directory (Azure AD) tenant that syncs to an Active Directory forest.

You discover that when a user account is disabled in Active Directory, the disabled user can still authenticate to Azure AD for up to 30 minutes.

You need to ensure that when a user account is disabled in Active Directory, the user account is immediately prevented from authenticating to Azure AD.

Solution: You configure password writeback.

Does this meet the goal?

Options:
A.

Yes

B.

No

Questions 34

You have a Microsoft Entra tenant.

You need to configure continuous access evaluation for app sign-ins and assign the configuration to users that are assigned the Application Administrator role.

What should you configure?

Options:
A.

a Conditional Access policy

B.

the Admin consent settings

C.

a sign-in risk policy

D.

an access review

Questions 35

You have three Azure subscriptions that are linked to a single Microsoft Entra tenant.

You need to evaluate and remediate the risks associated with highly privileged accounts. The solution must minimize administrative effort.

What should you use?

Options:
A.

Microsoft Entra Verified ID

B.

Privileged Identify Management (PIM)

C.

Global Secure Access

D.

Microsoft Entra Permissions Management

Questions 36

You need to implement the planned changes for litware.com. What should you configure?

Options:
A.

Azure AD Connect cloud sync between the Azure AD tenant and litware.com

B.

Azure AD Connect to include the litware.com domain

C.

staging mode in Azure AD Connect for the litware.com domain

Questions 37

You need to resolve the issue of the sales department users. What should you configure for the Azure AD tenant?

Options:
A.

the User settings

B.

the Device settings

C.

the Access reviews settings

D.

Security defaults

Questions 38

You have an Azure subscription named Sub1 that contains a resource group named RG1. RG1 contains an Azure Cosmos DB database named DB1 and an Azure Kubernetes Service (AKS) cluster named AKS1. AKS1 uses a managed identity.

You need to ensure that AKS1 can access DB1. The solution must meet the following requirements:

• Ensure that AKS1 uses the managed identity to access DB1.

• Follow the principle of least privilege.

Which role should you assign to the managed identity of AKS1.

Options:
A.

For R61, assign the Azure Cosmos DB Data Reader Role role.

B.

For Sub1. assign the Owner role.

C.

For RG1, assign the Reader role.

D.

For DB1, assign the Azure Cosmos DB Account Reader Role role.

Questions 39

You have an Azure Active Directory (Azure AD) tenant named contoso.com.

All users who run applications registered in Azure AD are subject to conditional access policies.

You need to prevent the users from using legacy authentication.

What should you include in the conditional access policies to filter out legacy authentication attempts?

Options:
A.

a cloud apps or actions condition

B.

a user risk condition

C.

a client apps condition

D.

a sign-in risk condition

Questions 40

You have an Azure Active Directory (Azure Azure) tenant that contains the objects shown in the following table.

• A device named Device1

• Users named User1, User2, User3, User4, and User5

• Five groups named Group1, Group2, Group3, Ciroup4, and Group5

The groups are configured as shown in the following table.

SC-300 Question 40

How many licenses are used if you assign the Microsoft Office 365 Enterprise E5 license to Group1?

Options:
A.

0

B.

2

C.

3

D.

4

Exam Code: SC-300
Certification Provider: Microsoft
Exam Name: Microsoft Identity and Access Administrator
Last Update: Oct 31, 2025
Questions: 341