Microsoft SC-300 Practice Test Questions and Exam Dumps Part10 Q181-200

View Full Microsoft SC-300 Exam Dumps and Practice Test Dumps.

 

Question 181

Which Microsoft Entra feature allows an organization to restrict access to applications based on the user’s device platform, such as Windows or Android?

  1. Access Reviews
  2. Conditional Access
  3. Lifecycle Workflows
  4. Entitlement Management

Correct Answer: 2

Explanation

Conditional Access can use device platform as a condition when evaluating a user’s access request. Administrators can create policies that target specific platforms, such as Windows, macOS, iOS, or Android, depending on the supported scenario. The policy can then apply controls such as requiring MFA, requiring a compliant device, or blocking access. Access Reviews evaluate existing permissions, Lifecycle Workflows automate identity lifecycle tasks, and Entitlement Management governs access packages. Conditional Access is therefore the appropriate Microsoft Entra feature for applying access requirements according to device platform.

Question 182

Which Microsoft Entra authentication method uses number matching to help protect users from accidental approval of fraudulent sign-in requests?

  1. FIDO2 security keys
  2. Temporary Access Pass
  3. Microsoft Authenticator
  4. Password Hash Synchronization

Correct Answer: 3

Explanation

Microsoft Authenticator can use number matching to provide an additional verification step during push authentication. Instead of simply approving a notification, the user is asked to enter the number displayed during the sign-in attempt into the Authenticator application. This helps reduce accidental approvals and certain social-engineering attacks in which an attacker repeatedly sends authentication requests. FIDO2 security keys use a different phishing-resistant mechanism, Temporary Access Pass is a temporary credential, and Password Hash Synchronization supports hybrid authentication. Microsoft Authenticator is therefore the correct answer.

Question 183

A company wants to automatically assign an application to all users in the Sales department based on their department attribute. Which combination is most appropriate?

  1. Dynamic group and group-based application assignment
  2. Access Review and PIM
  3. Smart Lockout and SSPR
  4. Named location and Terms of Use

Correct Answer: 1

Explanation

A dynamic group can automatically include users whose department attribute matches a defined rule, such as Sales. The organization can then assign the required enterprise application to that group. When a user’s department changes, dynamic membership can update automatically, which can also affect application access. This approach reduces manual administration and helps align access with organizational attributes. Access Reviews and PIM serve governance and privileged access purposes, while Smart Lockout and SSPR address authentication. Named locations and Terms of Use serve Conditional Access scenarios rather than automated department-based application assignment.

Question 184

Which Microsoft Entra capability can require administrator approval before a user receives an eligible privileged role?

  1. Security Defaults
  2. Privileged Identity Management
  3. My Apps
  4. Application Proxy

Correct Answer: 2

Explanation

Privileged Identity Management supports approval workflows for eligible privileged role activation. An organization can configure a role so that a user must request activation and wait for an authorized approver before the role becomes active. PIM can also require MFA, justification, and a limited activation duration. These controls reduce the risks associated with standing administrative privileges. Security Defaults provide baseline security settings, My Apps provides application access, and Application Proxy enables access to on-premises web applications. PIM is therefore the correct feature for approval-based privileged role activation.

Question 185

Which Microsoft Entra feature can be used to configure a policy requiring users to register for MFA before they can access protected resources?

  1. Authentication registration campaign
  2. Access Reviews
  3. Application provisioning
  4. Administrative units

Correct Answer: 1

Explanation

An authentication registration campaign can encourage or require users to register supported authentication methods, such as Microsoft Authenticator, according to organizational policy. This helps organizations prepare users for stronger authentication requirements and reduce situations where a user is expected to use MFA but has not completed registration. Access Reviews evaluate existing permissions, application provisioning manages application accounts, and administrative units provide administrative scope. The authentication registration campaign is therefore the appropriate feature for guiding users through required authentication method registration before stronger authentication policies are enforced.

Question 186

An administrator wants to configure a Conditional Access policy that applies only when users access resources from a specific country. Which feature should be configured first?

  1. Access package catalog
  2. Named location
  3. Administrative unit
  4. Dynamic group

Correct Answer: 2

Explanation

Named locations allow administrators to define geographic or network-based locations that can be referenced by Conditional Access policies. Depending on the supported configuration, locations can represent countries or regions or be based on known IP ranges. Once the relevant location is defined, a Conditional Access policy can use it as a condition and apply controls such as requiring MFA or blocking access. Access package catalogs organize resources, administrative units provide administrative boundaries, and dynamic groups manage membership. Named locations are therefore the appropriate starting point for location-based Conditional Access policies.

Question 187

Which Microsoft Entra feature can be used to assign a user an eligible role rather than keeping the role permanently active?

  1. Privileged Identity Management
  2. Access Reviews
  3. Group-based licensing
  4. Password Protection

Correct Answer: 1

Explanation

Privileged Identity Management allows organizations to make users eligible for privileged roles instead of keeping those roles permanently active. An eligible user activates the role when administrative work is required and can be subject to controls such as MFA, approval, justification, and time limits. This supports least privilege and reduces the attack surface associated with permanent administrative access. Access Reviews periodically evaluate permissions, group-based licensing manages licenses, and Password Protection helps prevent weak passwords. PIM is therefore the appropriate Microsoft Entra feature for eligible privileged role assignments.

Question 188

Which Microsoft Entra capability is designed to synchronize password hashes from on-premises Active Directory to Microsoft Entra ID?

  1. Federation
  2. Pass-through Authentication
  3. Password Hash Synchronization
  4. Application Proxy

Correct Answer: 3

Explanation

Password Hash Synchronization synchronizes a representation of users’ on-premises password hashes with Microsoft Entra ID. This enables cloud authentication without requiring the cloud service to contact the on-premises domain controller for every authentication attempt. It is commonly used as a straightforward hybrid identity authentication method and can also support Microsoft Entra ID Protection capabilities. Federation uses an external identity provider, Pass-through Authentication validates passwords against on-premises Active Directory during sign-in, and Application Proxy provides access to applications. Password Hash Synchronization is therefore the correct answer.

Question 189

A company wants to authenticate users against on-premises Active Directory passwords without synchronizing password hashes to Microsoft Entra ID. Which authentication method should be considered?

  1. Pass-through Authentication
  2. Password Hash Synchronization
  3. FIDO2 authentication
  4. Temporary Access Pass

Correct Answer: 1

Explanation

Microsoft Entra Pass-through Authentication allows users to authenticate with their on-premises Active Directory passwords without synchronizing password hashes to Microsoft Entra ID. Authentication requests are validated through agents connected to the on-premises environment. This can be useful for organizations that want cloud-based authentication while keeping password validation within the on-premises Active Directory environment. Password Hash Synchronization uses synchronized password hash information, while FIDO2 and Temporary Access Pass are authentication methods rather than hybrid password validation architectures. Pass-through Authentication is therefore the appropriate choice.

Question 190

Which Microsoft Entra feature allows an organization to provide browser-based access to an on-premises web application without requiring inbound firewall connections?

  1. Access Reviews
  2. Application Proxy
  3. Group-based licensing
  4. Authentication Methods

Correct Answer: 2

Explanation

Microsoft Entra Application Proxy provides remote access to supported on-premises web applications through Microsoft Entra ID. It uses an Application Proxy connector installed within the organization’s network, allowing users to access published applications without exposing the application directly through inbound firewall connections. Administrators can also integrate the application with authentication and access policies. Access Reviews evaluate permissions, group-based licensing manages licenses, and Authentication Methods controls authentication options. Application Proxy is therefore the appropriate Microsoft Entra service for publishing supported on-premises web applications securely.

Question 191

Which Microsoft Entra feature can automatically remove a user from an access package when the user’s assignment expires?

  1. Entitlement Management
  2. Conditional Access
  3. Audit logs
  4. Authentication Methods

Correct Answer: 1

Explanation

Microsoft Entra Entitlement Management allows administrators to define expiration settings for access package assignments. When an assignment reaches its configured expiration, the user’s access to the resources provided through that package can be removed. This is particularly useful for temporary employees, contractors, and project-based access because it reduces the chance that users retain permissions after their business need ends. Conditional Access controls sign-in conditions, audit logs record directory activity, and Authentication Methods manages authentication options. Entitlement Management is therefore the appropriate feature for automatically expiring governed access.

Question 192

Which Microsoft Entra feature can help an organization identify accounts that require risk remediation because Microsoft has detected elevated user risk?

  1. My Apps
  2. Microsoft Entra ID Protection
  3. Application Proxy
  4. Group-based licensing

Correct Answer: 2

Explanation

Microsoft Entra ID Protection identifies potentially risky users and sign-ins by analyzing security signals associated with authentication activity and identity compromise. When elevated user risk is detected, administrators can investigate the account and use supported remediation methods, such as requiring a secure password reset or applying Conditional Access controls. My Apps provides users with application access, Application Proxy publishes on-premises applications, and group-based licensing manages license assignments. Microsoft Entra ID Protection is therefore the appropriate capability for detecting elevated user risk and supporting remediation.

Question 193

An organization wants to make an application available only to members of a specific security group. Which setting should be configured for the enterprise application?

  1. Assignment required
  2. Smart Lockout
  3. Authentication strength
  4. Terms of Use

Correct Answer: 1

Explanation

The enterprise application’s assignment configuration can require users to be assigned before they can access the application. Administrators can assign the application to a specific security group, allowing members of that group to receive access while unassigned users are denied access when assignment is required. This provides a simple way to control application availability according to group membership. Smart Lockout protects accounts from repeated failed authentication attempts, authentication strength controls authentication requirements, and Terms of Use manages acceptance conditions. Assignment required is therefore the appropriate setting.

Question 194

Which Microsoft Entra capability can be used to require a user to provide justification when activating a privileged role?

  1. Privileged Identity Management
  2. Access Reviews
  3. Lifecycle Workflows
  4. Application provisioning

Correct Answer: 1

Explanation

Privileged Identity Management can require users to provide a justification when activating eligible privileged roles. This creates an additional governance record explaining why elevated permissions are needed at a particular time. PIM can combine justification with controls such as MFA, approval, and limited activation duration. Access Reviews evaluate whether access should continue, Lifecycle Workflows automate identity lifecycle processes, and application provisioning manages application accounts. PIM is therefore the appropriate feature for requiring justification when users activate privileged administrative roles.

Question 195

Which Microsoft Entra capability is primarily used to automate user and group provisioning to supported SaaS applications?

  1. Application provisioning
  2. Access Reviews
  3. Conditional Access
  4. Smart Lockout

Correct Answer: 1

Explanation

Microsoft Entra application provisioning automates the creation, updating, and removal of user accounts in supported applications. It can use standards such as SCIM to exchange identity information with compatible SaaS applications. This reduces manual account administration and helps keep application identities synchronized with organizational changes. For example, a user’s application account can be created when access is assigned and removed when access is revoked. Access Reviews govern existing permissions, Conditional Access controls access conditions, and Smart Lockout protects authentication. Application provisioning is therefore the correct solution.

Question 196

Which Microsoft Entra capability can allow an application to authenticate using an identity that is managed by Azure rather than storing a client secret in application code?

  1. Managed identity
  2. Access package
  3. Dynamic group
  4. Administrative unit

Correct Answer: 1

Explanation

Managed identities provide Azure resources with identities that Microsoft Entra ID manages. Applications can use these identities to authenticate to supported Azure services without storing passwords, certificates, or client secrets directly in application code. This reduces secret-management overhead and can improve security because credentials do not need to be embedded or manually rotated. Access packages govern user access, dynamic groups automatically manage membership, and administrative units provide administrative scope. Managed identities are therefore the appropriate capability for credential-free authentication by supported Azure workloads.

Question 197

Which Conditional Access feature can help prevent access from devices that use an operating system the organization does not support?

  1. Device platforms condition
  2. Access package policy
  3. User risk remediation
  4. Group-based licensing

Correct Answer: 1

Explanation

The device platforms condition in Conditional Access allows administrators to target policies based on the operating system or device platform used during sign-in. An organization can create a policy that blocks unsupported platforms or requires additional controls when users sign in from them. This helps standardize access according to organizational security requirements. Access package policies govern entitlement requests, user risk remediation addresses identity risks, and group-based licensing manages licenses. The device platforms condition is therefore the appropriate Conditional Access feature for controlling access based on operating system.

Question 198

A security administrator wants to review which changes were made to Conditional Access policies and when those changes occurred. Which resource should be examined?

  1. Microsoft Entra audit logs
  2. My Apps
  3. Access package catalog
  4. Authentication Methods policy

Correct Answer: 1

Explanation

Microsoft Entra audit logs record many administrative changes made within the directory, including changes to supported security and identity configurations. Reviewing audit logs can help administrators determine who changed a Conditional Access policy, what type of operation occurred, and when the activity took place. This information is valuable for troubleshooting, investigations, compliance, and change tracking. My Apps is an application launcher, access package catalogs organize entitlement resources, and Authentication Methods policies control authentication options. Audit logs are therefore the appropriate resource for investigating historical configuration changes.

Question 199

Which Microsoft Entra feature can provide a user with access to multiple applications, groups, and SharePoint resources through a single governed request?

  1. Access package
  2. Named location
  3. Authentication strength
  4. Smart Lockout

Correct Answer: 1

Explanation

An access package in Microsoft Entra Entitlement Management can bundle multiple resources into a single governed access request. Depending on the organization’s configuration, an access package can include applications, groups, SharePoint sites, and other supported resources. Policies can control who can request access, whether approval is required, how long access remains active, and when it should expire. Named locations support location-based Conditional Access, authentication strength controls authentication requirements, and Smart Lockout protects accounts from repeated failed passwords. An access package is therefore the correct solution.

Question 200

Which Microsoft Entra capability allows administrators to define a policy that requires users to satisfy multiple access conditions before gaining access to a resource?

  1. Conditional Access
  2. Access Reviews
  3. Lifecycle Workflows
  4. Group-based licensing

Correct Answer: 1

Explanation

Conditional Access allows administrators to combine multiple signals and controls when making access decisions. A policy can consider factors such as user or group membership, application, device platform, location, sign-in risk, and authentication strength before applying controls such as MFA, device compliance, or blocking access. This enables organizations to create detailed, risk-based access policies rather than relying on a single security requirement. Access Reviews evaluate existing permissions, Lifecycle Workflows automate identity processes, and group-based licensing manages licenses. Conditional Access is therefore the correct capability for combining multiple access conditions.