wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

SC-300: Identity and Access Administrator - TCS

Total questions: 24

Worksheet time: 16mins

Name
Class
Date
1.

Which of the following directories is maintained by Microsoft and used to publish applications?

a)

SaaS directory

b)

App gallery directory

c)

Single-sign-on app connected directory

2.

Which one of the following is a best practice for building multi-tenant apps?

a)

Follow the principle of least user access to ensure that your app only requests permissions it actually needs.

b)

Test your app in each tenant to ensure functionality.

c)

Use names and descriptions that are only meaningful to your team.

3.

What service and connector work together to securely pass a user sign-on token from Azure AD to a web application running in an organization's on-premises datacenter?

a)

The Azure AD Application Proxy service and Application Proxy connector

b)

An Application Proxy connector and the Azure Firewall service

c)

The Azure AD Application Proxy service and Application Gateway

4.

Which user provision mode(s) are supported for applications in the Azure AD gallery?

a)

Administrator approved and automatic.

b)

You should only use Manual Provisioning to ensure security.

c)

Manual and automatic

5.

What is Microsoft's Cloud Access Security Broker solution?

a)

Microsoft Defender for Cloud Apps

b)

Microsoft Cloud Computing Services

c)

Microsoft Security Center

6.

What is the purpose of the audit logs?

a)

Azure AD audit logs allow customer to monitor activity when provisioning new services within Azure.

b)

Azure AD audit logs provide records of system activities for compliance reporting.

c)

Azure AD audit logs provide a comparison of budgeted Azure usage compared to actual.

7.

Typically, Azure AD defines users in three ways. Cloud identities and guest users are two of the ways. What is the third way Azure AD defines users?

a)

As non-connected users.

b)

As directory-synchronized identities.

c)

As transitional users.

8.

Which roles can only be assigned using Privileged Identity Management?

a)

Permanent roles.

b)

Eligible roles.

c)

Transient roles.

9.

What is an access package?

a)

An access package is a group of users with the access they need to work on a project or perform a task.

b)

An access package is a bundle of all the resources with the access a user needs to work on a project or perform their task.

c)

An access package is a used to create a transitive trust between B2B organizations.

10.

What do catalogs contain?

a)

Device registrations

b)

Resources and access packages

c)

User lists

11.

How long are deleted users retained by Azure AD by default?

a)

14 days

b)

30 days

c)

60 days

d)

90

12.

You have an Azure Active Directory (Azure AD) tenant named contoso.com. You plan to bulk invite Azure AD business-to-business (B2B) collaboration users. Which two parameters must you include when you create the bulk invite? Each correct answer presents part of the solution.

a)

email address

b)

redirection URL

c)

username

d)

password

13.

You configure a new Microsoft 365 tenant to use a default domain name of contoso.com. You need to ensure that you can control access to Microsoft 365 resources by using conditional access policies.What should you do first?

a)

Disable the User consent settings.

b)

Disable Security defaults.

c)

Configure a multi-factor authentication (MFA) registration policy.

d)

Configure password protection for Windows Server Active Directory.

14.

Which of these authentication methods offers the highest level of security?

a)

SMS verification

b)

Microsoft Authenticator App

c)

Voice call verification

15.

What is user sign-in frequency?

a)

User sign-in frequency defines the time period before a user is asked to sign in again when attempting to access a resource.

b)

User sign-in frequency defines the number of times a user signs in from a single device in a 24-hour period

c)

User sign-in frequency defines the number of devices a single user is signed in to.

16.

Which authentication method requires the least effort regarding deployment, maintenance, and infrastructure?

a)

Password hash synchronization (PHS)

b)

Pass-through authentication (PTA)

c)

Federated authentication

17.

Who should be engaged when planning a technology project?

a)

Engage the right stakeholders.

b)

Start planning with a small team to avoid extra work for others.

c)

Keep your team small to avoid project creep.

18.

Can Azure export logging data to third-party SIEM (security information and event management) tools?

a)

Yes, Azure supports exporting log data to several common third-party SIEM tools.

b)

No, Azure only supports the export to Azure Sentinel.

c)

Yes, Splunk is the third party SIEM Azure can export to.

19.

Azure AD allows for the definition of two different types of groups; one type is Security groups, which are used to manage member and computer access to shared resources. What is the other type of group?

a)

Distribution groups, which are used for communications purposes via applications such as Teams and Exchange.

b)

Licensing groups, which are used to make it easier to administer software licenses.

c)

Microsoft 365 groups, which provide access to shared mailboxes, calendars, SharePoint sites, and so on.

20.

What are dynamic groups?

a)

Dynamic groups are Microsoft 365 groups whose membership are based on rules containing attributes.

b)

They are special groups where we assign the members manually

21.

You have a Microsoft Entra tenant with Microsoft Entra ID P2 licenses.

Your company’s security department is requesting a solution to evaluate risky sign-ins.

You plan to implement Microsoft Entra ID Protection.

You need to create a Microsoft Entra ID Protection policy that requires risky users to change their passwords.

Which Identity Protection policy should you create?

a)

Multifactor authentication registration policy

b)


Sign-in risk policy

c)


User risk policy

22.

Your company has a Microsoft Entra tenant with Microsoft Entra ID P2 licenses.

You enforce MFA by using Microsoft Entra ID Protection for all users.

What is the maximum number of days, after a user sign-in, when users are required to use MFA?

a)

2

b)

7

c)

14

d)

30

23.

Your company uses the following cloud environments:

  • Microsoft Azure

  • Google Cloud Platform (GCP)

  • Amazon Web Services (AWS)

Which cloud environment or cloud environments can be onboarded to Microsoft Entra Permissions Manager?

a)

Microsoft Azure and AWS only

b)

Microsoft Azure and GCP only

c)

Microsoft Azure only

d)

Microsoft Azure, GCP and AWS

24.

You have a Microsoft Entra tenant.

You need to register an app named App1 in the tenant.

What information is required to register App1?

a)

permissions

b)

Application ID

c)

Redirect URI

d)

Supported account types