Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Microsoft Microsoft Certified: Identity and Access Administrator Associate SC-300 Questions and answers with CertsForce

Viewing page 4 out of 5 pages
Viewing questions 31-40 out of questions
Questions # 31:

You have a Microsoft 365 E5 subscription.

You deploy a third-party web gateway named Gateway1.

You need to integrate Gateway1 with Microsoft Defender for Cloud Apps. The solution must meet the following requirements:

Ensure that data flows automatically to Defender for Cloud Apps.

Minimize administrative effort.

What should you do first?

Options:

A.

Add a data source


B.

Create an app registration


C.

Create a snapshot report


D.

Add a log collector


Expert Solution
Questions # 32:

You have a Microsoft 365 tenant.

The Azure Active Directory (Azure AD) tenant syncs to an on-premises Active Directory domain.

You plan to create an emergency-access administrative account named Emergency1. Emergency1 will be

assigned the Global administrator role in Azure AD. Emergency1 will be used in the event of Azure AD

functionality failures and on-premises infrastructure failures.

You need to reduce the likelihood that Emergency1 will be prevented from signing in during an emergency.

What should you do?

Options:

A.

Configure Azure Monitor to generate an alert if Emergency1 is modified or signs in.


B.

Require Azure AD Privileged Identity Management (PIM) activation of the Global administrator role forEmergency1.


C.

Configure a conditional access policy to restrict sign-in locations for Emergency1 to only the corporatenetwork.


D.

Configure a conditional access policy to require multi-factor authentication (MFA) for Emergency1.


Expert Solution
Questions # 33:

Your company requires that users request access before they can access corporate applications.

You register a new enterprise application named MyApp1 in Azure Active Dilatory (Azure AD) and configure single sign-on (SSO) for MyApp1.

Which settings should you configure next for MyApp1?

Options:

A.

Self-service


B.

Provisioning


C.

Roles and administrators


D.

Application proxy


Expert Solution
Questions # 34:

You have an Azure subscription. The subscription contains 50 virtual machines that run Windows Server.

You enable Microsoft Entra login for the virtual machines.

Users report that they cannot sign in to the virtual machines by using their Microsoft Entra credentials.

You need to ensure that the users can sign in to the virtual machines.

What should you do first?

Options:

A.

Ensure that the virtual machines can accesshttps://enterpriseregistration.windows.net.


B.

Revoke the primary refresh token.


C.

From the Microsoft Entra admin center, delete the device registrations of the virtual machines.


D.

Enable SSH client support for OpenSSH.


Expert Solution
Questions # 35:

You have an Azure Active Directory (Azure AD) tenant that syncs to an Active Directory domain.

The on-premises network contains a VPN server that authenticates to the on-premises Active Directory

domain. The VPN server does NOT support Azure Multi-Factor Authentication (MFA).

You need to recommend a solution to provide Azure MFA for VPN connections.

What should you include in the recommendation?

Options:

A.

Azure AD Application Proxy


B.

an Azure AD Password Protection proxy


C.

Network Policy Server (NPS)


D.

a pass-through authentication proxy


Expert Solution
Questions # 36:

You need to create the LWGroup1 group to meet the management requirements.

How should you complete the dynamic membership rule? To answer, drag the appropriate values to the correct targets. Each value may be used once, more than once, or not at all. You many need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Question # 36


Expert Solution
Questions # 37:

You need to configure the MFA settings for users who connect from the Boston office. The solution must meet the authentication requirements and the access requirements.

What should you configure?

Options:

A.

named locations that have a private IP address range


B.

named locations that have a public IP address range


C.

trusted IPs that have a public IP address range


D.

trusted IPs that have a private IP address range


Expert Solution
Questions # 38:

You need to track application access assignments by using Identity Governance. The solution must meet the delegation requirements.

What should you do first?

Options:

A.

Modify the User consent settings for the enterprise applications.


B.

Create a catalog.


C.

Create a program.


D.

Modify the Admin consent requests settings for the enterprise applications.


Expert Solution
Questions # 39:

You need to configure app registration in Azure AD to meet the delegation requirements.

What should you do? To answer, select the appropriate options in the answer area.

NOTE:Each correct selection is worth one point.

Question # 39


Expert Solution
Questions # 40:

You need to configure the detection of multi-staged attacks to meet the monitoring requirements.

What should you do?

Options:

A.

Customize the Azure Sentinel rule logic.


B.

Create a workbook.


C.

Add Azure Sentinel data connectors.


D.

Add an Azure Sentinel playbook.


Expert Solution
Viewing page 4 out of 5 pages
Viewing questions 31-40 out of questions