Font size
WorksheetsSC-300: Identity and Access Administrator - TCS
Total questions: 24
Worksheet time: 16mins
Which of the following directories is maintained by Microsoft and used to publish applications?
SaaS directory
App gallery directory
Single-sign-on app connected directory
Which one of the following is a best practice for building multi-tenant apps?
Follow the principle of least user access to ensure that your app only requests permissions it actually needs.
Test your app in each tenant to ensure functionality.
Use names and descriptions that are only meaningful to your team.
What service and connector work together to securely pass a user sign-on token from Azure AD to a web application running in an organization's on-premises datacenter?
The Azure AD Application Proxy service and Application Proxy connector
An Application Proxy connector and the Azure Firewall service
The Azure AD Application Proxy service and Application Gateway
Which user provision mode(s) are supported for applications in the Azure AD gallery?
Administrator approved and automatic.
You should only use Manual Provisioning to ensure security.
Manual and automatic
What is Microsoft's Cloud Access Security Broker solution?
Microsoft Defender for Cloud Apps
Microsoft Cloud Computing Services
Microsoft Security Center
What is the purpose of the audit logs?
Azure AD audit logs allow customer to monitor activity when provisioning new services within Azure.
Azure AD audit logs provide records of system activities for compliance reporting.
Azure AD audit logs provide a comparison of budgeted Azure usage compared to actual.
Typically, Azure AD defines users in three ways. Cloud identities and guest users are two of the ways. What is the third way Azure AD defines users?
As non-connected users.
As directory-synchronized identities.
As transitional users.
Which roles can only be assigned using Privileged Identity Management?
Permanent roles.
Eligible roles.
Transient roles.
What is an access package?
An access package is a group of users with the access they need to work on a project or perform a task.
An access package is a bundle of all the resources with the access a user needs to work on a project or perform their task.
An access package is a used to create a transitive trust between B2B organizations.
What do catalogs contain?
Device registrations
Resources and access packages
User lists
How long are deleted users retained by Azure AD by default?
14 days
30 days
60 days
90
You have an Azure Active Directory (Azure AD) tenant named contoso.com. You plan to bulk invite Azure AD business-to-business (B2B) collaboration users. Which two parameters must you include when you create the bulk invite? Each correct answer presents part of the solution.
email address
redirection URL
username
password
You configure a new Microsoft 365 tenant to use a default domain name of contoso.com. You need to ensure that you can control access to Microsoft 365 resources by using conditional access policies.What should you do first?
Disable the User consent settings.
Disable Security defaults.
Configure a multi-factor authentication (MFA) registration policy.
Configure password protection for Windows Server Active Directory.
Which of these authentication methods offers the highest level of security?
SMS verification
Microsoft Authenticator App
Voice call verification
What is user sign-in frequency?
User sign-in frequency defines the time period before a user is asked to sign in again when attempting to access a resource.
User sign-in frequency defines the number of times a user signs in from a single device in a 24-hour period
User sign-in frequency defines the number of devices a single user is signed in to.
Which authentication method requires the least effort regarding deployment, maintenance, and infrastructure?
Password hash synchronization (PHS)
Pass-through authentication (PTA)
Federated authentication
Who should be engaged when planning a technology project?
Engage the right stakeholders.
Start planning with a small team to avoid extra work for others.
Keep your team small to avoid project creep.
Can Azure export logging data to third-party SIEM (security information and event management) tools?
Yes, Azure supports exporting log data to several common third-party SIEM tools.
No, Azure only supports the export to Azure Sentinel.
Yes, Splunk is the third party SIEM Azure can export to.
Azure AD allows for the definition of two different types of groups; one type is Security groups, which are used to manage member and computer access to shared resources. What is the other type of group?
Distribution groups, which are used for communications purposes via applications such as Teams and Exchange.
Licensing groups, which are used to make it easier to administer software licenses.
Microsoft 365 groups, which provide access to shared mailboxes, calendars, SharePoint sites, and so on.
What are dynamic groups?
Dynamic groups are Microsoft 365 groups whose membership are based on rules containing attributes.
They are special groups where we assign the members manually
You have a Microsoft Entra tenant with Microsoft Entra ID P2 licenses.
Your company’s security department is requesting a solution to evaluate risky sign-ins.
You plan to implement Microsoft Entra ID Protection.
You need to create a Microsoft Entra ID Protection policy that requires risky users to change their passwords.
Which Identity Protection policy should you create?
Multifactor authentication registration policy
Sign-in risk policy
User risk policy
Your company has a Microsoft Entra tenant with Microsoft Entra ID P2 licenses.
You enforce MFA by using Microsoft Entra ID Protection for all users.
What is the maximum number of days, after a user sign-in, when users are required to use MFA?
2
7
14
30
Your company uses the following cloud environments:
Microsoft Azure
Google Cloud Platform (GCP)
Amazon Web Services (AWS)
Which cloud environment or cloud environments can be onboarded to Microsoft Entra Permissions Manager?
Microsoft Azure and AWS only
Microsoft Azure and GCP only
Microsoft Azure only
Microsoft Azure, GCP and AWS
You have a Microsoft Entra tenant.
You need to register an app named App1 in the tenant.
What information is required to register App1?
permissions
Application ID
Redirect URI
Supported account types
