Microsoft SC-300 Practice Test Questions and Exam Dumps Part17 Q321-340

View Full Microsoft SC-300 Exam Dumps and Practice Test Dumps.

 

Question 321

Which Microsoft Entra feature can be used to restrict access to an application based on whether the sign-in originates from a trusted network range?

  1. Access Reviews
  2. Application provisioning
  3. Named locations
  4. Lifecycle Workflows

Correct Answer: 3

Explanation

Named locations allow administrators to define network locations using IP address ranges or other supported location information. Conditional Access policies can then use these locations as conditions when determining whether access should be allowed, blocked, or require additional authentication. This is useful when organizations want to treat corporate network traffic differently from traffic originating from untrusted locations. Access Reviews evaluate existing permissions, application provisioning manages application accounts, and Lifecycle Workflows automate identity lifecycle tasks. Named locations are therefore the appropriate capability for defining trusted network locations.

Question 322

Which Microsoft Entra feature allows an administrator to temporarily elevate a user into a privileged role after the user provides a business justification?

  1. Privileged Identity Management
  2. Dynamic groups
  3. Access package
  4. Application Proxy

Correct Answer: 1

Explanation

Privileged Identity Management provides just-in-time access to privileged Microsoft Entra roles. A user can be made eligible for a role and activate it only when elevated permissions are required. Administrators can configure activation requirements such as business justification, MFA, approval, and a maximum activation duration. This approach reduces permanent administrative access and supports least privilege. Dynamic groups manage membership, access packages govern resource access, and Application Proxy publishes supported on-premises applications. Privileged Identity Management is therefore the appropriate solution for temporary role elevation with justification.

Question 323

Which Microsoft Entra capability can require a user to complete additional authentication when accessing a sensitive operation within an application?

  1. Group-based licensing
  2. Authentication context
  3. Access Reviews
  4. Password Protection

Correct Answer: 2

Explanation

Authentication context allows applications and Conditional Access policies to apply additional access requirements to specific scenarios. An application can request an authentication context when a sensitive operation requires stronger controls than the application’s normal sign-in. A Conditional Access policy can then require additional authentication or other conditions associated with that context. Group-based licensing manages licenses, Access Reviews evaluate existing permissions, and Password Protection prevents weak password choices. Authentication context is therefore the appropriate capability for applying additional Conditional Access requirements to sensitive application operations.

Question 324

An organization wants to automatically add newly hired employees to a department-specific group based on their department attribute. Which feature should be used?

  1. Access package
  2. Dynamic group
  3. PIM
  4. Terms of Use

Correct Answer: 2

Explanation

Dynamic groups use membership rules that evaluate directory attributes. An administrator can create a rule based on the department attribute so that users assigned to that department are automatically added to the appropriate group. When a user’s department changes, Microsoft Entra can reevaluate the rule and update membership accordingly. This can simplify application assignment, licensing, and access management. Access packages govern resource access, PIM manages privileged permissions, and Terms of Use require acceptance of organizational agreements. A dynamic group is therefore the correct solution for automatic department-based membership.

Question 325

Which Microsoft Entra capability can help prevent an administrator from accidentally granting broad permissions when a narrower built-in role is available?

  1. Least-privilege role assignment
  2. Application Proxy
  3. Access package expiration
  4. Sign-in frequency

Correct Answer: 1

Explanation

Least-privilege role assignment means administrators receive only the permissions necessary to perform their responsibilities. Microsoft Entra provides many directory roles with different permission scopes, allowing organizations to select a role that closely matches the administrator’s job requirements. Using the narrowest suitable role reduces the potential impact of compromised or misused administrative accounts. Application Proxy manages access to on-premises applications, access package expiration controls temporary resource access, and sign-in frequency controls authentication intervals. Least-privilege role assignment is therefore the appropriate security principle and configuration approach.

Question 326

Which Microsoft Entra feature can automatically synchronize user accounts between Microsoft Entra ID and a supported application when users are assigned to that application?

  1. Authentication strength
  2. Application provisioning
  3. Named locations
  4. Access Reviews

Correct Answer: 2

Explanation

Application provisioning can automatically create and manage user accounts in supported applications based on assignments in Microsoft Entra ID. When a user is assigned to an application, provisioning can create the corresponding account and populate configured attributes. Changes to the user’s assignment or directory information can also be synchronized according to the provisioning configuration. Authentication strength controls authentication requirements, named locations define network locations, and Access Reviews evaluate continued access. Application provisioning is therefore the correct feature for synchronizing application accounts based on Microsoft Entra assignments.

Question 327

Which Microsoft Entra capability can be used to require MFA only when users access a particular enterprise application?

  1. Application-targeted Conditional Access policy
  2. Group-based licensing
  3. Lifecycle Workflows
  4. Dynamic group

Correct Answer: 1

Explanation

Conditional Access policies can target specific cloud applications, allowing administrators to apply MFA requirements only when users access selected applications. For example, an organization can require MFA for a sensitive financial application while allowing lower-risk applications to follow different authentication requirements. The policy can also include user, group, device, location, or risk conditions. Group-based licensing manages licenses, Lifecycle Workflows automate identity lifecycle tasks, and dynamic groups manage membership. An application-targeted Conditional Access policy is therefore the appropriate solution for application-specific MFA.

Question 328

Which Microsoft Entra feature can help an organization provide external users with controlled access that automatically expires after a defined period?

  1. Access package with expiration
  2. Smart Lockout
  3. Password Protection
  4. Audit logs

Correct Answer: 1

Explanation

Microsoft Entra Entitlement Management access packages can provide external users with governed access that expires automatically. Administrators can configure an access package policy with an expiration period so that temporary access does not remain indefinitely. This is particularly useful for contractors, vendors, partners, and temporary project members. Smart Lockout protects against repeated failed authentication attempts, Password Protection controls password selection, and audit logs record directory activity. An access package with an expiration policy is therefore the appropriate solution for providing time-limited external access.

Question 329

Which Microsoft Entra capability can help users recover access to their account without contacting the help desk when they forget their password?

  1. Self-service password reset
  2. Access Reviews
  3. Application Proxy
  4. Administrative units

Correct Answer: 1

Explanation

Self-service password reset, or SSPR, allows users to reset or change their passwords without requiring assistance from the help desk, provided they meet the configured authentication requirements. Organizations can configure authentication methods and registration requirements to verify the user’s identity before allowing the password reset. SSPR can reduce help-desk workload and improve user productivity. Access Reviews evaluate existing permissions, Application Proxy provides access to supported on-premises applications, and administrative units provide administrative scope. Self-service password reset is therefore the appropriate feature for user-driven password recovery.

Question 330

Which Microsoft Entra feature allows an organization to review whether members of a privileged group still require their membership?

  1. Authentication Methods
  2. Access Reviews
  3. Application provisioning
  4. Named locations

Correct Answer: 2

Explanation

Access Reviews can be used to periodically evaluate membership in groups, including groups that provide privileged access. Reviewers can examine the members and determine whether each person still requires the assigned access. This helps organizations identify unnecessary or outdated privileged memberships and supports least-privilege governance. Authentication Methods manages sign-in methods, application provisioning manages application accounts, and named locations provide location-based conditions. Access Reviews are therefore the appropriate capability for periodically validating membership in privileged groups.

Question 331

Which Microsoft Entra feature can be used to configure a user risk policy that requires remediation when an account is considered compromised?

  1. Microsoft Entra ID Protection
  2. Group-based licensing
  3. My Apps
  4. Application Proxy

Correct Answer: 1

Explanation

Microsoft Entra ID Protection can identify potentially compromised users and assign a user risk level. Organizations can use Conditional Access policies with user risk conditions to require remediation when a user’s risk reaches a configured level. Depending on the configuration, remediation can involve actions such as MFA or a secure password reset. Group-based licensing manages licenses, My Apps provides access to assigned applications, and Application Proxy publishes supported on-premises applications. Microsoft Entra ID Protection is therefore the appropriate capability for managing account compromise risk and remediation.

Question 332

Which authentication protocol is primarily designed to allow an application to obtain an access token for calling a protected API?

  1. SAML
  2. OAuth 2.0
  3. SCIM
  4. LDAP

Correct Answer: 2

Explanation

OAuth 2.0 is an authorization framework that allows applications to obtain access tokens for accessing protected resources and APIs. The token represents the authorization granted to the application under the configured flow and permissions. OAuth 2.0 can support delegated scenarios where an application acts on behalf of a user and application-only scenarios where the workload operates without a user. SAML is commonly used for federated authentication, SCIM is used for provisioning, and LDAP is a directory access protocol. OAuth 2.0 is therefore the correct protocol for API authorization.

Question 333

Which Microsoft Entra capability can allow an application to use Microsoft Entra ID as its identity provider while supporting SAML-based single sign-on?

  1. Enterprise application SAML configuration
  2. Dynamic group
  3. Access Review
  4. Security Defaults

Correct Answer: 1

Explanation

Enterprise applications in Microsoft Entra ID can be configured for SAML-based single sign-on. In this arrangement, Microsoft Entra ID acts as the identity provider and sends a SAML assertion to the service provider application after successful authentication. Administrators can configure settings such as identifiers, reply URLs, claims, and certificates according to the application’s requirements. Dynamic groups manage membership, Access Reviews evaluate existing access, and Security Defaults provide baseline identity protections. Enterprise application SAML configuration is therefore the correct capability for implementing SAML-based SSO.

Question 334

An administrator wants to see whether a Conditional Access policy would block a sign-in before enabling the policy. Which option should be used?

  1. What If tool
  2. Access package catalog
  3. PIM
  4. Authentication Methods

Correct Answer: 1

Explanation

The Conditional Access What If tool allows administrators to simulate sign-in conditions and determine which policies would apply. It can help identify whether a policy would allow, require additional controls, or block a particular access attempt. This is useful when testing policies before enforcement and when troubleshooting unexpected Conditional Access behavior. Access package catalogs organize resources for Entitlement Management, PIM manages privileged access, and Authentication Methods manages available authentication options. The What If tool is therefore the appropriate option for evaluating Conditional Access behavior before applying a policy.

Question 335

Which Microsoft Entra feature can help an organization manage external users through an access package catalog containing resources approved for external collaboration?

  1. Access package catalog
  2. Smart Lockout
  3. Password Protection
  4. Authentication strength

Correct Answer: 1

Explanation

An access package catalog in Microsoft Entra Entitlement Management is a container for related resources and access packages. Organizations can use catalogs to organize resources that are intended for specific teams, departments, or external collaboration scenarios. Access packages within the catalog can then define how users request and receive access, including approval and expiration requirements. Smart Lockout protects authentication, Password Protection manages password restrictions, and authentication strength controls authentication requirements. An access package catalog is therefore the appropriate feature for organizing approved resources for governed external access.

Question 336

Which Microsoft Entra capability can allow a user to register an authentication method using a temporary credential that automatically becomes invalid after its configured lifetime?

  1. Temporary Access Pass
  2. Dynamic group
  3. Access Review
  4. Application Proxy

Correct Answer: 1

Explanation

Temporary Access Pass is a time-limited authentication credential designed to help users establish or register stronger authentication methods. Administrators can configure its lifetime and usage restrictions, after which the temporary credential becomes invalid. TAP can be particularly useful during onboarding or when a user does not yet have another usable authentication method. Dynamic groups manage membership, Access Reviews evaluate permissions, and Application Proxy provides access to supported on-premises applications. Temporary Access Pass is therefore the correct capability for providing a temporary credential during authentication-method registration.

Question 337

Which Microsoft Entra capability can be used to assign administrative permissions only to users located within a defined organizational scope?

  1. Administrative unit-scoped role assignment
  2. Application provisioning
  3. Access package expiration
  4. Sign-in frequency

Correct Answer: 1

Explanation

Administrative units can provide a defined scope for supported Microsoft Entra administrative roles. By assigning an administrative role with an administrative-unit scope, an administrator can manage objects within that unit without automatically receiving the same management permissions across the entire tenant. This supports delegated administration and least privilege. Application provisioning manages application accounts, access package expiration controls resource access duration, and sign-in frequency controls how often users must authenticate. Administrative unit-scoped role assignment is therefore the correct capability for limiting administrative permissions to an organizational scope.

Question 338

Which Microsoft Entra capability can help prevent a compromised password from being the only requirement for accessing a sensitive application?

  1. Conditional Access requiring MFA
  2. Group-based licensing
  3. Application provisioning
  4. Dynamic group

Correct Answer: 1

Explanation

Conditional Access can require multifactor authentication before users access sensitive applications. This adds an additional verification factor, reducing the likelihood that a stolen password alone will provide access to protected resources. Organizations can further strengthen protection by using authentication strength to require phishing-resistant methods for particularly sensitive scenarios. Group-based licensing manages licenses, application provisioning manages application accounts, and dynamic groups automate membership. Conditional Access requiring MFA is therefore the appropriate control when an organization wants to ensure that a compromised password alone is insufficient for application access.

Question 339

Which Microsoft Entra capability can automatically remove a user’s access to resources when the associated access package assignment expires?

  1. Entitlement Management
  2. Smart Lockout
  3. Authentication Methods
  4. Named locations

Correct Answer: 1

Explanation

Microsoft Entra Entitlement Management provides governance for access packages and their assignments. An access package policy can define an expiration period, after which the assignment ends and the user’s governed access to the associated resources can be removed according to the configuration. This is useful for temporary employees, contractors, partners, and project-based access. Smart Lockout protects accounts from repeated failed sign-ins, Authentication Methods manages authentication options, and named locations provide location signals. Entitlement Management is therefore the appropriate capability for controlling resource access through assignment expiration.

Question 340

Which Microsoft Entra feature can be used to configure a service principal so that an application can operate as an identity within a tenant?

  1. Enterprise application
  2. Access Review
  3. Dynamic group
  4. Administrative unit

Correct Answer: 1

Explanation

A service principal represents an application identity within a Microsoft Entra tenant and is commonly surfaced through the Enterprise applications area. It allows the application to receive permissions and participate in authentication and authorization within that tenant. Administrators can manage assignments, permissions, and other application-specific settings through the service principal. Access Reviews evaluate user access, dynamic groups manage automatic membership, and administrative units provide administrative scope. An enterprise application represents the service principal in the tenant and is therefore the appropriate choice for managing an application’s identity.