SC-300 Exam Question 51

You have an Azure Active Directory (Azure AD) tenant that contains three users named User1, User1, and User3, You create a group named Group1. You add User2 and User3 to Group1.
You configure a role in Azure AD Privileged identity Management (PIM) as shown in the application administrator exhibit. (Click the application Administrator tab.)

Group1 is configured as the approver for the application administrator role.
You configure User2to be eligible for the application administrator role.
For User1, you add an assignment to the Application administrator role as shown in the Assignment exhibit. (Click Assignment tab)

For each of the following statement, select Yes if the statement is true, Otherwise, select No.
NOTE: Each correct selection is worth one point.

SC-300 Exam Question 52

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You use Azure Monitor to analyze Azure Active Directory (Azure AD) activity logs.
You receive more than 100 email alerts each day for failed Azure AD user sign-in attempts.
You need to ensure that a new security administrator receives the alerts instead of you.
Solution: From Azure AD, you modify the Diagnostics settings.
Does this meet the goal?
  • SC-300 Exam Question 53

    You have a Microsoft 365 tenant.
    The Azure Active Directory (Azure AD) tenant syncs to an on-premises Active Directory domain. The domain contains the servers shown in the following table.

    The domain controllers are prevented from communicating to the internet.
    You implement Azure AD Password Protection on Server1 and Server2.
    You deploy a new server named Server4 that runs Windows Server 2019.
    You need to ensure that Azure AD Password Protection will continue to work if a single server fails.
    What should you implement on Server4?
  • SC-300 Exam Question 54

    You have a Microsoft 365 E5 subscription that contains a web app named App1.
    Guest users are regularly granted access to App1.
    You need to ensure that the guest users that have NOT accessed App1 during the past 30 days have their access removed the solution must minimize administrative effort.
    What should you configure?
  • SC-300 Exam Question 55

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
    After you answer a question in this section, you will NOT be able to return to it as a result these questions will not appear in the review screen.
    You have a Microsoft 365 E5 subscription.
    You create a user named User1.
    You need to ensure that User1 can update the status of identity Secure Score improvement actions.
    Solution: You assign the SharePoint Administrator role to User1
    Does this meet the goal?