Pass the Microsoft Microsoft Certified: Identity and Access Administrator Associate SC-300 Questions and answers with CertsForce

Viewing page 1 out of 5 pages
Viewing questions 1-10 out of questions
Questions # 1:

You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains an Azure AD

enterprise application named App1.

A contractor uses the credentials of user1@outlook.com.

You need to ensure that you can provide the contractor with access to App1. The contractor must be able to

authenticate as user1@outlook.com.

What should you do?

Options:

A.

Run the New-AzADUser cmdlet.


B.

Configure the External collaboration settings.


C.

Add a WS-Fed identity provider.


D.

Create a guest user account in contoso.com.


Questions # 2:

You have an Azure Active Directory (Azure AD) tenant.

For the tenant. Users can register applications Is set to No.

A user named Admin1 must deploy a new cloud app named App1.

You need to ensure that Admin1 can register App1 in Azure AD. The solution must use the principle of least privilege.

Which role should you assign to Admin1?

Options:

A.

Application developer in Azure AD


B.

App Configuration Data Owner for Subscription1


C.

Managed Application Contributor for Subscription1


D.

Cloud application administrator in Azure AD


Questions # 3:

Your company has an Azure Active Directory (Azure AD) tenant named contosri.com. The company has the business partners shown in the following table.

Question # 3

users can request access by using package 1.

Users at Fabrikam and Litware use ail then respective domain names for email addresses.

You plan to create an access package named packaqe1 that will be accessible only to the Fabrikam and Litware users.

You need to configure connected organizations for Fabrikam and litware so that any of their users can request access by using package1.

What is the minimum of connected organization that you should create.

Options:

A.

1


B.

2


C.

3


D.

4


Questions # 4:

You have a Microsoft Entra tenant named contoso.com that contains an enterprise application named Appl.

A contractor uses the credentials of user1@outlook.com.

You need to ensure that you can provide the contractor with access to App1. The contractor must be able to authenticate as user1 @outlook.com.

What should you do?

Options:

A.

Run the New-Mguser cmdlet


B.

Run the New-Mglnvitation cmdlet


C.

Configure the External collaboration settings


D.

Implement Microsoft Entra Connect sync.


Questions # 5:

You need to support the planned changes and meet the technical requirements for MFA.

Which feature should you use, and how long before the users must complete the registration? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 5


Questions # 6:

You have an Azure AD tenant that contains multiple storage accounts.

You plan to deploy multiple Azure App Service apps that will require access to the storage accounts.

You need to recommend an identity solution to provide the apps with access to the storage accounts. The solution must minimize administrative effort.

Which type of identity should you recommend, and what should you recommend using to control access to the storage accounts? To answer, select the appropriate options in the answer area.

Question # 6


Questions # 7:

You have a Microsoft 365 tenant.

The Azure Active Directory (Azure AD) tenant syncs to an on-premises Active Directory domain.

Users connect to the internet by using a hardware firewall at your company. The users authenticate to the

firewall by using their Active Directory credentials.

You plan to manage access to external applications by using Azure AD.

You need to use the firewall logs to create a list of unmanaged external applications and the users who access

them.

What should you use to gather the information?

Options:

A.

Application Insights in Azure Monitor


B.

access reviews in Azure AD


C.

Cloud App Discovery in Microsoft Cloud App Security


D.

enterprise applications in Azure AD


Questions # 8:

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have an Azure Active Directory (Azure AD) tenant that syncs to an Active Directory forest.

You discover that when a user account is disabled in Active Directory, the disabled user can still authenticate to Azure AD for up to 30 minutes.

You need to ensure that when a user account is disabled in Active Directory, the user account is immediately prevented from authenticating to Azure AD.

Solution: You configure conditional access policies.

Does this meet the goal?

Options:

A.

Yes


B.

No


Questions # 9:

You have a Microsoft Entra tenant named contoso.com that contains an administrative unit named AU1 and two users named User1 and User2. User1 is a member of AU1.

You need to perform the following role assignments:

• User1: Security Administrator

• User2: User Administrator

For which scopes can each user be assigned the role? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 9


Questions # 10:

You have an on-premises datacenter that contains the hosts shown in the following table.

Question # 10

You have an Azure Active Directory (Azure AD) tenant that syncs to the Active Directory forest. Multi-factor authentication (MFA) is enforced for Azure AD.

You need to ensure that you can publish App1 to Azure AD users.

What should you configure on Server and Firewall1? To answer, select the appropriate options in the answer area.

NOTE:Each correct selection is worth one point.

Question # 10


Viewing page 1 out of 5 pages
Viewing questions 1-10 out of questions