Download Microsoft Identity and Access Administrator.SC-300.VCEplus.2021-04-13.37q.vcex

Vendor: Microsoft
Exam Code: SC-300
Exam Name: Microsoft Identity and Access Administrator
Date: Apr 13, 2021
File Size: 1 MB
Downloads: 18

How to open VCEX files?

Files with VCEX extension can be opened by ProfExam Simulator.

Demo Questions

Question 1
You need to sync the ADatum users. The solution must meet the technical requirements.  
What should you do?  
 
  1. From the Microsoft Azure Active Directory Connect wizard, select Customize synchronization options.
  2. From PowerShell, run Set-ADSyncScheduler.
  3. From PowerShell, run Start-ADSyncSyncCycle.
  4. From the Microsoft Azure Active Directory Connect wizard, select Change user sign-in.
Correct answer: A
Explanation:
You need to select Customize synchronization options to configure Azure AD Connect to sync the Adatum organizational unit (OU).
You need to select Customize synchronization options to configure Azure AD Connect to sync the Adatum organizational unit (OU).
Question 2
You need to meet the authentication requirements for leaked credentials. What should you do?
  1. Enable password hash synchronization in Azure AD Connect.
  2. Configure Azure AD Password Protection.
  3. Configure an authentication method policy in Azure AD.
  4. Enable federation with PingFederate in Azure AD Connect.
Correct answer: A
Explanation:
Reference: https://docs.microsoft.com/en-us/azure/security/fundamentals/steps-secure-identity
Reference: https:
//docs.microsoft.com/en-us/azure/security/fundamentals/steps-secure-identity
Question 3
Your network contains an on-premises Active Directory domain that syncs to an Azure Active Directory (Azure AD) tenant. Users sign in to computers that run Windows 10 and are joined to the domain. You plan to implement Azure AD Seamless Single Sign-On (Azure AD Seamless SSO). You need to configure the computers for Azure AD Seamless SSO.  
What should you do?
  1. Configure Sign-in options.
  2. Enable Enterprise State Roaming.
  3. Modify the Intranet Zone settings.
  4. Install the Azure AD Connect Authentication Agent.
Correct answer: C
Explanation:
Reference: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sso-quick-start
Reference: 
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sso-quick-start
Question 4
You have an Azure Active Directory (Azure AD) tenant that contains the following objects: 
  • A device named Device1  
  • Users named User1, User2, User3, User4, and User5  
  • Groups named Group1, Group2, Group3, Group4, and Group5 The groups are configured as shown in the following table.  
      
  
To which groups can you assign a Microsoft Office 365 Enterprise E5 license directly?
  1. Group1 and Group4 only
  2. Group1, Group2, Group3, Group4, and Group5
  3. Group1 and Group2 only
  4. Group1 only
  5. Group1, Group2, Group4, and Group5 only
Correct answer: C
Explanation:
Reference: https://docs.microsoft.com/en-us/azure/active-directory/enterprise-users/licensing-group-advanced
Reference: 
https://docs.microsoft.com/en-us/azure/active-directory/enterprise-users/licensing-group-advanced
Question 5
You have a Microsoft Exchange organization that uses an SMTP address space of contoso.com.  
Several users use their contoso.com email address for self-service sign-up to Azure Active Directory (Azure AD).  
You gain global administrator privileges to the Azure AD tenant that contains the self-signed users.  
You need to prevent the users from creating user accounts in the contoso.com Azure AD tenant for self-service sign-up to Microsoft 365 services.  
Which PowerShell cmdlet should you run?
  1. Set-MsolCompanySettings
  2. Set-MsolDomainFederationSettings
  3. Update-MsolfederatedDomain
  4. Set-MsolDomain
Correct answer: A
Explanation:
Reference: https://docs.microsoft.com/en-us/azure/active-directory/enterprise-users/directory-self-service-signup
Reference: 
https://docs.microsoft.com/en-us/azure/active-directory/enterprise-users/directory-self-service-signup
Question 6
You have a Microsoft 365 tenant that uses the domain named fabrikam.com. 
The Guest invite settings for Azure Active Directory (Azure AD) are configured as shown in the exhibit. (Click the Exhibit tab.)  
      
A user named [email protected] shares a Microsoft SharePoint Online document library to the users shown in the following table.  
      
  
Which users will be emailed a passcode?
  1. User2 only
  2. User1 only
  3. User1 and User2 only
  4. User1, User2, and User3
Correct answer: A
Explanation:
Reference: https://docs.microsoft.com/en-us/azure/active-directory/external-identities/one-time-passcode
Reference: 
https://docs.microsoft.com/en-us/azure/active-directory/external-identities/one-time-passcode
Question 7
You have 2,500 users who are assigned Microsoft Office 365 Enterprise E3 licenses. The licenses are assigned to individual users.  
From the Groups blade in the Azure Active Directory admin center, you assign Microsoft 365 Enterprise E5 licenses to the users.  
You need to remove the Office 365 Enterprise E3 licenses from the users by using the least amount of administrative effort.  
What should you use?  
 
  1. the Identity Governance blade in the Azure Active Directory admin center
  2. the Set-AzureAdUser cmdlet
  3. the Licenses blade in the Azure Active Directory admin center
  4. the Set-WindowsProductKey cmdlet
Correct answer: C
Question 8
You have an Azure Active Directory (Azure AD) tenant named contoso.com. You plan to bulk invite Azure AD business-to-business (B2B) collaboration users.  
Which two parameters must you include when you create the bulk invite? Each correct answer presents part of the solution  
NOTE: Each correct selection is worth one point.
  1. email address
  2. redirection URL
  3. username
  4. shared key
  5. password
Correct answer: AB
Explanation:
Reference: https://docs.microsoft.com/en-us/azure/active-directory/external-identities/tutorial-bulk-invite
Reference: 
https://docs.microsoft.com/en-us/azure/active-directory/external-identities/tutorial-bulk-invite
Question 9
You have an Azure Active Directory (Azure AD) tenant that contains the objects shown in the following table.  
      
  
Which objects can you add as members to Group3?
  1. User2 and Group2 only
  2. User2, Group1, and Group2 only
  3. User1, User2, Group1 and Group2
  4. User1 and User2 only
  5. User2 only
Correct answer: E
Explanation:
Reference:https://bitsizedbytes.wordpress.com/2018/12/10/distribution-security-and-office-365-groups-nesting/   
Reference:
https://bitsizedbytes.wordpress.com/2018/12/10/distribution-security-and-office-365-groups-nesting/  
 
Question 10
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. 
Some question sets might have more than one correct solution, while others might not have a correct solution. 
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have an Azure Active Directory (Azure AD) tenant that syncs to an Active Directory forest. You discover that when a user account is disabled in Active Directory, the disabled user can still authenticate to Azure AD for up to 30 minutes.You need to ensure that when a user account is disabled in Active Directory, the user account is immediately prevented from authenticating to Azure AD.  
Solution: You configure password writeback. 
Does this meet the goal?
  1. Yes
  2. No
Correct answer: B
Explanation:
Reference: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/choose-ad-authn
Reference: 
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/choose-ad-authn
HOW TO OPEN VCE FILES

Use VCE Exam Simulator to open VCE files
Avanaset

HOW TO OPEN VCEX AND EXAM FILES

Use ProfExam Simulator to open VCEX and EXAM files
ProfExam Screen

ProfExam
ProfExam at a 20% markdown

You have the opportunity to purchase ProfExam at a 20% reduced price

Get Now!