SC-300 Practice Questions
Prepare for SC-300 with more than an answer.
Unlock the full exam and previous versions
- v1Version 1 263 questions Current
- MS-500Legacy Microsoft 365 Security Administration 218 questions Locked
- Exam fee
- $165 USD
- Level
- Associate
- Valid for
- 1 year
Domains covered on the exam 4
- Implement and manage user identities25%
- Implement authentication and access management30%
- Plan and implement workload identities25%
- Plan and automate identity governance20%
- 1
You need to create a break-glass account for emergency access to your Microsoft Entra tenant. Which of the following is NOT a Microsoft recommended best practice for securing this type of account?
Show answer details
Correct answer: C
This is NOT a best practice. While the break-glass account needs the Global Administrator role, it should NOT be managed by PIM. The purpose of a break-glass account is to provide access when other systems, including PIM or MFA, might be unavailable. Therefore, the role should be permanently assigned, but the account itself must be excluded from all Conditional Access policies and PIM management. The question asks what is NOT a best practice, and the recommendation is to have the role permanently assigned, not managed by PIM.
- 2
You are configuring a dynamic group for all marketing managers in your organization. The rule needs to include users whose 'department' attribute is 'Marketing' AND whose 'jobTitle' attribute starts with 'Manager'. What is the correct syntax for this dynamic membership rule?
Show answer details
Correct answer: B
This syntax is correct. It uses the '-eq' operator for an exact match on the department and the '-startsWith' operator to match job titles that begin with 'Manager'. Both conditions are combined with the '-and' logical operator to ensure users must meet both criteria to be included in the group.
- 3
A company has discovered that several applications with high-risk permissions have been granted consent by users. The security team wants to prevent this from happening in the future. They want to disable user consent entirely and force all permission requests to be reviewed by an administrator. What is the most direct way to configure this in the Microsoft Entra admin center?
Show answer details
Correct answer: A
This is the most direct and correct method. Navigating to the 'User consent settings' under 'Consent and permissions' allows an administrator to control the tenant-wide policy for user consent. Selecting 'Do not allow user consent' achieves the goal of disabling it for all applications. You can then configure the admin consent workflow to handle the requests.
- 4
You are creating a custom Azure role to grant a junior administrator the ability to start, stop, and restart virtual machines within a specific resource group, but not modify any other settings. Which three actions should be included in the role's
actionspermissions? (Select THREE)Show answer details
Correct answer: A, C, E
This action explicitly grants the permission to start a virtual machine.
The 'deallocate' action is equivalent to stopping a virtual machine in a way that de-provisions the compute resources. This is the correct action for stopping a VM.
This action explicitly grants the permission to restart a virtual machine.
- 5
An administrator is using the Microsoft Graph PowerShell SDK to manage users. The administrator needs to find a user with the User Principal Name '[email protected]' and update their 'jobTitle' to 'Senior Analyst'. Which PowerShell command should be used?
Show answer details
Correct answer: C
This is the correct syntax for the Microsoft Graph PowerShell SDK. The
Update-MgUsercmdlet is used to modify existing user properties. It identifies the user by theirUserId, which can be the User Principal Name (UPN) or the object ID. The properties to be updated are passed as a hashtable to the-BodyParameter. - 6
A financial services company, Woodgrove Bank, is implementing Microsoft Entra Privileged Identity Management (PIM) to manage access to sensitive Azure resources. They have a requirement that any activation of the 'Subscription Owner' role must be approved by at least two members of the 'IT Security Leads' group. Additionally, the activation request must include a mandatory ticket number from their ServiceNow instance. How should you configure the PIM role settings to meet these requirements?
Show answer details
Correct answer: B
This is the correct solution because it meets both requirements precisely. PIM role settings allow for multi-member approval by selecting a group and specifying the number of required approvers. The 'Require ticket information on activation' setting is specifically designed to integrate with ticketing systems like ServiceNow, making the ticket number a mandatory field during activation. Simply requiring justification is not sufficient as it doesn't enforce the format or presence of a ticket number.
- 7
A manufacturing company uses Microsoft Entra Connect cloud sync to provision users from a disconnected on-premises Active Directory forest. After a successful initial deployment, a new organizational unit (OU) named 'Robotics Division' was created in the on-premises AD, and new user accounts were added to it. However, these new users are not appearing in Microsoft Entra ID. Existing users are syncing correctly. What is the most likely cause of this issue?
Show answer details
Correct answer: C
Microsoft Entra Connect cloud sync uses scoping filters to determine which objects to synchronize. When a new OU is created, it is not automatically included in the sync scope. An administrator must explicitly edit the cloud sync agent configuration, navigate to the OU scoping filters, and select the new 'Robotics Division' OU to include its objects in the synchronization process. Service account permissions are usually set at the domain level, and password hash sync failure would not prevent object creation, only password synchronization.
- 8
A global logistics company has registered a custom line-of-business application in their Microsoft Entra tenant. The application requires access to read user profiles and send emails on behalf of the signed-in user. To adhere to the principle of least privilege, which TWO API permissions should be granted to this application? (Select TWO)
Show answer details
Correct answer: B, C
This delegated permission allows the application to send mail as the signed-in user, which directly meets one of the stated requirements.
This delegated permission allows the application to read the basic profile of all users in the organization, which is a least-privilege way to fulfill the requirement of reading user profiles. 'User.Read' would only allow reading the signed-in user's profile, and 'User.Read.All' is more permissive than necessary if only basic profile information is needed.
- 9
True or False: When configuring a Microsoft Entra access review for a dynamic group, if a user's attributes change during the review period causing them to be removed from the group by the dynamic membership rule, their access is immediately revoked regardless of the reviewer's decision.
Show answer details
Correct answer: A
This statement is true. Dynamic group membership is evaluated continuously. If a user no longer meets the criteria of the dynamic membership rule, they are automatically removed from the group. The access review process audits existing membership but does not override the fundamental logic of the dynamic group itself. The removal by the rule takes precedence.
- 10
To deploy Microsoft Entra pass-through authentication (PTA), you must install an Authentication Agent on a domain-joined server. To ensure high availability, you plan to install agents on three different servers. The PowerShell command to register the first agent is
Register-AzureADConnectAuthenticationAgent. What is the value for the____parameter when registering the second and third agents to ensure they are part of the same agent group for load balancing and failover?Show answer details
Correct answer: A
When installing additional Pass-through Authentication agents for high availability, you run the same registration command (
Register-AzureADConnectAuthenticationAgent) on each new server. The service automatically detects that it's being registered for an existing tenant and adds the new agent to the default agent group, enabling load balancing and failover. No special parameters are needed to join an existing group.
