Go Back on SC-300 Exam
Available in 1, 3, 6 and 12 Months Free Updates Plans
PDF: $15 $60

Test Engine: $20 $80

PDF + Engine: $25 $99

SC-300 Practice Test


Page 2 out of 61 Pages

Topic 4: Misc. Questions

You create the Azure Active Directory (Azure AD) users shown in the following table.


A. Option A


B. Option B


C. Option C


D. Option D





B.
  Option B

You have an Azure subscription that contains an Azure Automation account named Automation1 and an Azure key vault named Vault1. Vault1 contains a secret named Secret 1.
You enable a system-assigned managed identity for Automation1.
You need to ensure that Automation! can read the contents of Secret1. The solution must meet the following requirements:

  • Prevent Automation1 from accessing other secrets stored in Vault1.
  • Follow the principle of least privilege.
What should you do?


A. From Vault1, configure the Access control (1AM) settings.


B. From Automation1, configure the Identity settings.


C. From Secret1, configure the Access control (1AM) settings


D. From Automation1, configure the Run as accounts settings.





A.
  From Vault1, configure the Access control (1AM) settings.

You have an Azure AD tenant that contains a user named User1 User1 needs to manage license assignments and reset user passwords. Which role should you assign to User1?


A. License administrator


B. Helpdesk administrator


C. Billing administrator


D. User administrator





D.
  User administrator

You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1. You need to be notified if a user downloads more than 50 files in one minute from Site1. Which type of policy should you create in the Microsoft Defender for Cloud Apps portal?


A. session policy


B. anomaly detection policy


C. activity policy


D. file policy





C.
  activity policy

Your network contains an Active Directory forest named contoso.com that is linked to an Azure Active Directory
(Azure AD) tenant named contoso.com by using Azure AD Connect.
You need to prevent the synchronization of users who have the extensionAttribute15 attribute set to NoSync.
What should you do in Azure AD Connect?


A. Create an inbound synchronization rule for the Windows Azure Active Directory connector.


B. Configure a Full Import run profile.


C. Create an inbound synchronization rule for the Active Directory Domain Services connector.


D. Configure an Export run profile.





C.
  Create an inbound synchronization rule for the Active Directory Domain Services connector.


Page 2 out of 61 Pages
Previous