SC-300 Exam Question 51
You have an Azure subscription that contains a virtual machine named VM1 and an Azure key vault named Vault1. VM1 has a system-assigned managed identity. You need to ensure that VM1 can retrieve the values of secrets stored in Vault 1. The solution must minimize administrative effort. What should you do first?
SC-300 Exam Question 52
You have a Microsoft 365 E5 subscription that contains three gr oups named Groups1, Group2, and Group3, and the users shown in the following table.

You create a Conditional Access policy named CAT that has the following settings:
* Users
* Include
#Users and groups: Group1
o Exclude
#Users and groups: Group2
#Directory roles: Global Administrator
o Target resources
#Include: All cloud apps
o Access controls
#Grant: Require multifactor authentication
You create a Conditional Access policy named CA2 that has the following settings:
* Users
* Include
#Users and g roups: Group2
o Exclude
#Users and groups: Group3
o Target resources
#Include: All cloud apps
o Access controls
#Grant: Block access
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selecti on is worth one point.


You create a Conditional Access policy named CAT that has the following settings:
* Users
* Include
#Users and groups: Group1
o Exclude
#Users and groups: Group2
#Directory roles: Global Administrator
o Target resources
#Include: All cloud apps
o Access controls
#Grant: Require multifactor authentication
You create a Conditional Access policy named CA2 that has the following settings:
* Users
* Include
#Users and g roups: Group2
o Exclude
#Users and groups: Group3
o Target resources
#Include: All cloud apps
o Access controls
#Grant: Block access
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selecti on is worth one point.

SC-300 Exam Question 53
You have a Microsoft 365 E5 subscription that has a Conditional Access policy named Policy1. You need to perform the following actions:
* Create a Conditional Access App Control custom policy named Custom1.
* Configure Policy! to use Custom1
What should you use to create Custom1, and in which settings of Policy! should you enable Conditional Access App Control? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

* Create a Conditional Access App Control custom policy named Custom1.
* Configure Policy! to use Custom1
What should you use to create Custom1, and in which settings of Policy! should you enable Conditional Access App Control? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

SC-300 Exam Question 54
You have a Microsoft 365 tenant.
You have an Active Dire ctory domain that syncs to the Azure Active Directory {Azure AD) tenant.
Users connect to the internet by using a hardware firewall at your company. The users authenticate to the firewall by using their Active Directory credentials.
You plan to manage acce ss to external applications by using Azure AD.
You need to use the firewall logs to create a list of unmanaged external applications and the users who access them.
What should you use to gather the information?
You have an Active Dire ctory domain that syncs to the Azure Active Directory {Azure AD) tenant.
Users connect to the internet by using a hardware firewall at your company. The users authenticate to the firewall by using their Active Directory credentials.
You plan to manage acce ss to external applications by using Azure AD.
You need to use the firewall logs to create a list of unmanaged external applications and the users who access them.
What should you use to gather the information?
SC-300 Exam Question 55
You have a Microsoft Entra tenant.
You configure self-service password reset (SSPR) with the following settings:
Require users to register when signing in: Yes
Number of methods required to reset: 1
What is a valid authentication method available to users?
You configure self-service password reset (SSPR) with the following settings:
Require users to register when signing in: Yes
Number of methods required to reset: 1
What is a valid authentication method available to users?




