exam questions

Exam SC-300 All Questions

View all questions & answers for the SC-300 exam

Exam SC-300 topic 4 question 40 discussion

Actual exam question from Microsoft's SC-300
Question #: 40
Topic #: 4
[All SC-300 Questions]

Case Study -


Overview -

ADatum Corporation is a consulting company in Montreal.

ADatum recently acquired a Vancouver-based company named Litware, Inc.

Existing Environment. ADatum Environment

The on-premises network of ADatum contains an Active Directory Domain Services (AD DS) forest named adatum.com.

ADatum has a Microsoft 365 E5 subscription. The subscription contains a verified domain that syncs with the adatum.com AD DS domain by using Azure AD Connect.

ADatum has an Azure Active Directory (Azure AD) tenant named adatum.com. The tenant has Security defaults disabled.

The tenant contains the users shown in the following table.



The tenant contains the groups shown in the following table.



Existing Environment. Litware Environment

Litware has an AD DS forest named litware.com

Existing Environment. Problem Statements

ADatum identifies the following issues:

• Multiple users in the sales department have up to five devices. The sales department users report that sometimes they must contact the support department to join their devices to the Azure AD tenant because they have reached their device limit.
• A recent security incident reveals that several users leaked their credentials, a suspicious browser was used for a sign-in, and resources were accessed from an anonymous IP address.
• When you attempt to assign the Device Administrators role to IT_Group1, the group does NOT appear in the selection list.
• Anyone in the organization can invite guest users, including other guests and non-administrators.
• The helpdesk spends too much time resetting user passwords.
• Users currently use only passwords for authentication.


Requirements. Planned Changes -

ADatum plans to implement the following changes:

• Configure self-service password reset (SSPR).
• Configure multi-factor authentication (MFA) for all users.
• Configure an access review for an access package named Package1.
• Require admin approval for application access to organizational data.
• Sync the AD DS users and groups of litware.com with the Azure AD tenant.
• Ensure that only users that are assigned specific admin roles can invite guest users.
• Increase the maximum number of devices that can be joined or registered to Azure AD to 10.

Requirements. Technical Requirements

ADatum identifies the following technical requirements:

• Users assigned the User administrator role must be able to request permission to use the role when needed for up to one year.
• Users must be prompted to register for MFA and provided with an option to bypass the registration for a grace period.
• Users must provide one authentication method to reset their password by using SSPR. Available methods must include:
- Email
- Phone
- Security questions
- The Microsoft Authenticator app
• Trust relationships must NOT be established between the adatum.com and litware.com AD DS domains.
• The principle of least privilege must be used.


You need to implement the planned changes for Package1.

Which users can create and manage the access review?

  • A. User3 only
  • B. User4 only
  • C. User5 only
  • D. User3 and User4
  • E. User3 and User5
  • F. User4 and User5
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Siraf
Highly Voted 1 year, 4 months ago
Answer is C To enable reviews of access packages, you must meet the prerequisites for creating an access package: - Microsoft Entra ID P2 or Microsoft Entra ID Governance - Global administrator, Identity Governance administrator, Catalog owner, or Access package manager https://learn.microsoft.com/en-us/entra/id-governance/entitlement-management-access-reviews-create
upvoted 12 times
...
Ikazimirs
Highly Voted 1 year, 9 months ago
but user 4 is the user with Priviledged Role Administrator role....
upvoted 8 times
Alcpt
11 months, 3 weeks ago
Answer is C. You are confusing access reviews for Azure resources vs access reviews for Microsoft Entra roles. For creating access reviews for Azure RESOURCES, you need Owner or the User Access Administrator role for the Azure resources. For creating access reviews for Microsoft Entra ROLES, you need Global Administrator or the Privileged Role Administrator role. You are review access packages here, which are Azure RESOURCES. Evidence: https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-create-roles-and-resource-roles-review
upvoted 3 times
Alcpt
11 months, 3 weeks ago
sorry above answer is for a different question. Answer is C. You are reviewing an application, not a role-assignable group = #1 #1 Global Administrator or Identity Governance Administrator to create reviews on groups or applications. #2 Users must be in the Global administrator role or the Privileged Role administrator role to create reviews on role-assignable groups
upvoted 2 times
...
...
...
Obi_Wan_Jacoby
Most Recent 2 days, 2 hours ago
Selected Answer: C
Answer: C (user 5) Identity Governance Administrator
upvoted 1 times
...
watanabetatarou
7 months, 1 week ago
Selected Answer: E
E
upvoted 1 times
...
GummyBear95
7 months, 2 weeks ago
Selected Answer: C
Those who can create and manage access reviews are: Global Administrator Identity Governance Administrator Catalog owner (for the access package) Access package manager (for the access package) User Administrator can only read not create and manage https://learn.microsoft.com/en-us/entra/id-governance/deploy-access-reviews#who-will-create-and-manage-access-reviews
upvoted 2 times
...
hml_2024
7 months, 3 weeks ago
Privileged Role Administrator does not have access to create access review.
upvoted 1 times
...
hml_2024
7 months, 3 weeks ago
Selected Answer: C
To create and manage Access Reviews, a user needs to have one of the following roles in Azure AD: • Global Administrator • Privileged Role Administrator • Identity Governance Administrator
upvoted 3 times
...
Tony416
7 months, 4 weeks ago
Selected Answer: C
https://learn.microsoft.com/en-us/entra/id-governance/deploy-access-reviews#who-will-create-and-manage-access-reviews
upvoted 3 times
...
Sc300ExamDemo
11 months, 1 week ago
For review access package, only these roles are required Global administrator Identity Governance administrator Catalog owner (for the access package) Access package manager (for the access package) https://learn.microsoft.com/en-us/entra/id-governance/deploy-access-reviews#who-will-create-and-manage-access-reviews Answer: C
upvoted 1 times
...
criminal1979
1 year ago
Selected Answer: C
https://learn.microsoft.com/en-us/entra/id-governance/deploy-access-reviews#who-will-create-and-manage-access-reviews
upvoted 3 times
...
JuanZ
1 year ago
Selected Answer: E
Create and manage access reviews (creators): -Global administrator -User administrator -Identity Governance administrator -Privileged Role administrator (only does reviews for Microsoft Entra role-assignable groups) -Group owner (if enabled by an admin) https://learn.microsoft.com/en-us/entra/id-governance/deploy-access-reviews#who-will-create-and-manage-access-reviews
upvoted 3 times
...
HartMS
1 year ago
Selected Answer: C
Only following roles can create and manage access reviewes for packages: Global administrator Identity Governance administrator
upvoted 4 times
...
KRISTINMERIEANN
1 year ago
Selected Answer: C
https://learn.microsoft.com/en-us/entra/id-governance/deploy-access-reviews#who-will-create-and-manage-access-reviews
upvoted 4 times
...
blanco00555
1 year, 1 month ago
Selected Answer: C
https://learn.microsoft.com/en-us/entra/id-governance/deploy-access-reviews#who-will-create-and-manage-access-reviews see table: Access package: Global administrator Identity Governance administrator
upvoted 3 times
...
belyo
1 year, 1 month ago
Selected Answer: C
it is not clear what access package covers.. so following this: https://learn.microsoft.com/en-us/entra/id-governance/deploy-access-reviews#who-will-create-and-manage-access-reviews:~:text=Authorization/*/read%20permissions.-,Access%20package,-Global%20administrator i vote for ID Governance admin
upvoted 3 times
...
Sneekygeek
1 year, 3 months ago
Selected Answer: C
Answer is C https://learn.microsoft.com/en-us/entra/id-governance/deploy-access-reviews#who-will-create-and-manage-access-reviews The role required to create an access review will depend on the type of resource the access review is for.
upvoted 4 times
...
Another_one
1 year, 4 months ago
Selected Answer: C
https://learn.microsoft.com/en-us/entra/id-governance/deploy-access-reviews#who-will-create-and-manage-access-reviews Definitely C is the answer.
upvoted 4 times
siffy
1 year, 3 months ago
how is it c when it says Global administrator User administrator
upvoted 1 times
Ody
1 year, 2 months ago
Look in the table where it says "Access Packages"
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago