● MS Microsoft Identity and Access Administrator Associate (SC-300) Exam Materials
● Over 5 Students Passed Microsoft Identity and Access Administrator Associate (SC-300) Using This Dump – Join Them Today!
● Over 150 Verified Questions for Microsoft Identity and Access Administrator Associate Dump (SC-300Dump)
● 100% Score in the Real Microsoft Identity and Access Administrator Associate Exam (SC-300Exam) at the Pearson VUE Testing Center
● Over 150 Verified Questions for Microsoft Identity and Access Administrator Associate Dump (SC-300Dump)
● 100% Score in the Real Microsoft Identity and Access Administrator Associate Exam (SC-300Exam) at the Pearson VUE Testing Center
Question #1
Question #2
You configure a new Microsoft 365 tenant to use a default domain name of contoso.com.
You need to ensure that you can control access to Microsoft 365 resources by using conditional access policies.
What should you do first?
(Choose one answer)
- A. Configure password protection for the Microsoft Entra tenant.
- B. Disable the User consent settings.
- C. Disable Security defaults.
- D. Configure the Multifactor authentication registration policy.
Question #3
You have a Microsoft Entra tenant named contoso.com that uses Microsoft Entra ID Protection.
You need to implement a sign-in risk condition in a conditional access policy without blocking user access.
What should you do first?
(Choose one answer)
- A. Implement multifactor authentication (MFA) for all users.
- B. Enforce Microsoft Entra Password Protection.
- C. Configure Microsoft Entra Access Reviews.
- D. Configure self-service password reset (SSPR) for all users.
Question #4
You have a Microsoft Entra tenant.
You have 500 devices that run either Windows 11, macOS, iOS, or Android and are enrolled in Microsoft Intune.
You plan to deploy the Global Secure Access client.
From the Microsoft Entra admin center, you download the Global Secure Access client for each operating system.
You need to deploy the client to the macOS devices by using Intune.
Which file extension should you use when uploading the client to Intune?
(Choose one answer)
- A. .pkg
- B. .ipa
- C. .apk
- D. .intunewin
Question #5
You have a Microsoft Entra tenant that contains the users shown in the following table.
Admin4 creates a Conditional Access policy named Policy1 by using the Require multifactor authentication for Azure management template.
Which users will be required to use multifactor authentication (MFA) the next time they sign in?
(Choose one answer)
- A. Admin2 and Admin3 only
- B. Admin1 and Admin4 only
- C. Admin1, Admin2, and Admin3 only
- D. Admin1, Admin2, Admin3, and Admin4
Question #6
You have an Azure subscription. The subscription contains a virtual machine named VM1 that runs Linux.
You need to configure enhanced security for VM1. The solution must meet the following requirements:
Ensure that users can sign in to VM1 by using their Microsoft Entra credentials.
Ensure that users authenticate by using multifactor authentication.
Prevent users from signing in to VM1 by using passwords.
Which two authentication methods can you include in the solution? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
(Choose two answers)
- A. Temporary Access Pass
- B. SMS
- C. Windows Hello for Business
- D. the Microsoft Authenticator app
- E. Passkey (FIDO2)
Question #7
You have a Microsoft Entra tenant.
You open the risk detections report.
Which risk detection type is classified as a user risk?
(Choose one answer)
- A. password spray
- B. atypical travel
- C. Microsoft Entra threat intelligence
- D. impossible travel
Question #8
You have an Active Directory forest that syncs to a Microsoft Entra tenant. The tenant uses pass-through authentication.
A corporate security policy states the following:
Domain controllers must never communicate directly to the Internet.
Only required software must be installed on servers.
The Active Directory domain contains the on-premises servers shown in the following table.
You need to ensure that users can authenticate to the Microsoft Entra tenant if a server fails.
On which server should you install an additional pass-through authentication agent?
(Choose one answer)
- A. Server1
- B. Server2
- C. Server3
- D. Server4
Question #9
You have a Microsoft Entra tenant.
You need to implement smart lockout with a lockout threshold of 10 failed sign-ins.
What should you configure in the Microsoft Entra admin center?
(Choose one answer)
- A. Authentication strengths
- B. Sign-in risk policy
- C. User risk policy
- D. Password protection
Question #10
Your company has a marketing department.
You have a Microsoft Entra tenant that contains a dynamic group named Group1. Group1 has the following membership rule.
(user.userType -eq "Member") and (user.department -eq "Marketing")
You have a Conditional Access policy named CAPolicy1 that enforces multifactor authentication (MFA). CAPolicy1 is applied to Group1.
You discover that CAPolicy1 is NOT applied to guest users in the marketing department.
You need to ensure that CAPolicy1 applies to the guest users in Group1. The solution must NOT affect other users in the tenant.
What should you do?
(Choose one answer)
- A. From the Microsoft Entra admin center, configure the Guest user access settings.
- B. Change the assignments of CAPolicy1.
- C. Modify the membership rule of Group1.
- D. From the Microsoft Entra admin center, configure the External collaboration settings.
You have a Microsoft 365 subscription.
You need to create a Conditional Access policy that will use a Global Secure Access security profile. The solution must ensure that users are prevented from accessing websites that include the word gambling in the URL.
What should you do first? (Choose one answer)