SC-300 Microsoft Identity and Access Administrator Dumps 5 — Questions and Answers
Question 1: Which Azure AD Connect sync rule precedence value takes priority when two rules conflict — a lower number or a higher number?
- Higher number (e.g., 200) takes priority over lower numbers
- Lower number (e.g., 50) takes priority over higher numbers (Correct answer)
- Both rules merge and the most restrictive value wins
- The most recently modified rule always takes priority
Correct answer: Lower number (e.g., 50) takes priority over higher numbers
In Azure AD Connect, sync rules with a lower precedence number have higher priority and win conflicts over rules with higher numbers.
Question 2: An administrator needs to audit all changes made to Conditional Access policies in the last 30 days. Where should they look?
- Azure AD Sign-in logs filtered by Conditional Access
- Microsoft Entra audit logs filtered by category 'Policy' (Correct answer)
- Azure Monitor Activity Log for the subscription
- Microsoft Defender XDR advanced hunting
Correct answer: Microsoft Entra audit logs filtered by category 'Policy'
Microsoft Entra audit logs capture all configuration changes, including Conditional Access policy modifications, filterable by the 'Policy' category.
Question 3: A company acquires another organization and wants to allow the acquired company's Azure AD users to access resources in the parent company's tenant without converting them to guest accounts. Which feature enables this?
- Azure AD B2B direct connect with shared channels
- Azure AD B2B collaboration guest invitations
- Azure AD cross-tenant synchronization (Correct answer)
- Azure AD External Identities B2C
Correct answer: Azure AD cross-tenant synchronization
Cross-tenant synchronization automatically creates and maintains member (non-guest) user objects in the resource tenant synced from the source tenant.
Question 4: Which Microsoft Entra workload identity feature detects when a service principal or managed identity exhibits anomalous behavior, such as signing in from an unusual location?
- Workload Identity Federation
- Managed Identity credential rotation
- Identity Protection for workload identities (Correct answer)
- Microsoft Defender for Cloud Apps CASB
Correct answer: Identity Protection for workload identities
Identity Protection for workload identities extends risk detection to service principals and managed identities, flagging anomalous sign-ins.
Question 5: An administrator registers an application and needs to ensure it can only be used by users within the organization's tenant. What setting controls this?
- Set 'Supported account types' to 'Accounts in this organizational directory only (Single tenant)' (Correct answer)
- Add the application to an Conditional Access policy scoped to internal users only
- Configure API permissions as Application type only
- Disable the 'Allow public client flows' toggle
Correct answer: Set 'Supported account types' to 'Accounts in this organizational directory only (Single tenant)'
Setting 'Supported account types' to single-tenant restricts the application so that only accounts in the home tenant can authenticate.
Question 6: Which SSPR authentication method is considered the most secure because it requires physical possession of a registered device?
- Security questions
- Email OTP sent to an alternate email address
- Microsoft Authenticator app notification (Correct answer)
- Mobile phone SMS code
Correct answer: Microsoft Authenticator app notification
The Microsoft Authenticator app push notification requires approval on a registered physical device, providing possession-based verification stronger than SMS or email.
Question 7: A Conditional Access policy is in 'Report-only' mode. What is the effect on end users signing in?
- Users are blocked but can self-remediate by completing MFA
- Users are not affected; the policy only logs what would have happened (Correct answer)
- Users see a warning message but can proceed without MFA
- Administrators are prompted to approve each sign-in in real time
Correct answer: Users are not affected; the policy only logs what would have happened
Report-only mode evaluates the policy and logs the result to sign-in logs without enforcing any grant or session controls on the user.
Which Azure AD Connect sync rule precedence value takes priority when two rules conflict — a lower number or a higher number?