exam questions

Exam SC-300 All Questions

View all questions & answers for the SC-300 exam

Exam SC-300 topic 1 question 50 discussion

Actual exam question from Microsoft's SC-300
Question #: 50
Topic #: 1
[All SC-300 Questions]

Case Study -


Overview -

ADatum Corporation is a consulting company in Montreal.

ADatum recently acquired a Vancouver-based company named Litware, Inc.

Existing Environment. ADatum Environment

The on-premises network of ADatum contains an Active Directory Domain Services (AD DS) forest named adatum.com.

ADatum has a Microsoft 365 E5 subscription. The subscription contains a verified domain that syncs with the adatum.com AD DS domain by using Azure AD Connect.

ADatum has an Azure Active Directory (Azure AD) tenant named adatum.com. The tenant has Security defaults disabled.

The tenant contains the users shown in the following table.



The tenant contains the groups shown in the following table.



Existing Environment. Litware Environment

Litware has an AD DS forest named litware.com

Existing Environment. Problem Statements

ADatum identifies the following issues:

• Multiple users in the sales department have up to five devices. The sales department users report that sometimes they must contact the support department to join their devices to the Azure AD tenant because they have reached their device limit.
• A recent security incident reveals that several users leaked their credentials, a suspicious browser was used for a sign-in, and resources were accessed from an anonymous IP address.
• When you attempt to assign the Device Administrators role to IT_Group1, the group does NOT appear in the selection list.
• Anyone in the organization can invite guest users, including other guests and non-administrators.
• The helpdesk spends too much time resetting user passwords.
• Users currently use only passwords for authentication.


Requirements. Planned Changes -

ADatum plans to implement the following changes:

• Configure self-service password reset (SSPR).
• Configure multi-factor authentication (MFA) for all users.
• Configure an access review for an access package named Package1.
• Require admin approval for application access to organizational data.
• Sync the AD DS users and groups of litware.com with the Azure AD tenant.
• Ensure that only users that are assigned specific admin roles can invite guest users.
• Increase the maximum number of devices that can be joined or registered to Azure AD to 10.

Requirements. Technical Requirements

ADatum identifies the following technical requirements:

• Users assigned the User administrator role must be able to request permission to use the role when needed for up to one year.
• Users must be prompted to register for MFA and provided with an option to bypass the registration for a grace period.
• Users must provide one authentication method to reset their password by using SSPR. Available methods must include:
- Email
- Phone
- Security questions
- The Microsoft Authenticator app
• Trust relationships must NOT be established between the adatum.com and litware.com AD DS domains.
• The principle of least privilege must be used.


You need to implement the planned changes for litware.com.

What should you configure?

  • A. Azure AD Connect cloud sync between the Azure AD tenant and litware.com
  • B. Azure AD Connect to include the litware.com domain
  • C. staging mode in Azure AD Connect for the litware.com domain
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
penatuna
Highly Voted 1 year, 8 months ago
Selected Answer: A
Existing Environment. Litware Environment: "Litware has an AD DS forest named litware.com." Planned Changes: “Sync the AD DS users and groups of litware.com with the Azure AD tenant.” Technical Requirements: “Trust relationships must NOT be established between the adatum.com and litware.com AD DS domains.” You need a Azure AD Connect Cloud Sync to connect to multiple disconnected on-premises AD forests. See the video from 7:42 https://learn.microsoft.com/en-us/azure/active-directory/hybrid/cloud-sync/what-is-cloud-sync You can also use evaluate your options using the Wizard to evaluate sync options: https://setup.microsoft.com/azure/add-or-sync-users-to-azure-ad
upvoted 16 times
Alcpt
11 months, 3 weeks ago
i had to do some research but its definitely A as per MS video at 1:45. https://youtu.be/9T6lKEloq0Q
upvoted 2 times
...
...
0byte
Highly Voted 1 year, 7 months ago
Selected Answer: A
Even though Azure Connect Sync (Azure AD Connect) supports syncing objects from multiple AD forests, it does not support syncing from more than one on-prem server (https://learn.microsoft.com/en-us/azure/active-directory/hybrid/connect/plan-connect-topologies#multiple-forests-multiple-sync-servers-to-one-microsoft-entra-tenant). For this to work, AD trust would be required and we cannot do it. Cloud Sync does support multi-forest natively: https://learn.microsoft.com/en-us/azure/active-directory/hybrid/cloud-sync/plan-cloud-sync-topologies#multi-forest-single-microsoft-entra-tenant
upvoted 10 times
...
AlexBrazil
Most Recent 6 months, 1 week ago
Selected Answer: A
"Support for synchronizing to an Azure AD tenant from a multi-forest disconnected Active Directory forest environment: The common scenarios include merger & acquisition (where the acquired company's AD forests are isolated from the parent company's AD forests), and companies that have historically had multiple AD forests." https://learn.microsoft.com/en-us/entra/identity/hybrid/cloud-sync/what-is-cloud-sync
upvoted 1 times
...
baz
1 year, 3 months ago
Answer = B. Some of the excluded options in cloud sync prevent the solution – pass thru auth required for SSPR https://practical365.com/how-to-decide-between-azure-ad-connect-and-azure-ad-connect-cloud-sync/
upvoted 5 times
...
Waiuku2123
1 year, 4 months ago
Both AADC and Cloud Sync would work, however there is no detail that there is comms links between the two AD forests therefore Cloud Connect is the better option. AADC does not require an AD Trust unless Pass-thru-auth is to be deployed. PTA is not a requirement
upvoted 4 times
...
Kipper_2022
1 year, 8 months ago
Selected Answer: A
No trust = Cloud sync
upvoted 6 times
...
ServerBrain
1 year, 8 months ago
Selected Answer: A
"Trust relationships must NOT be established between the adatum.com and litware.com AD DS domains."
upvoted 3 times
...
KrissB
1 year, 9 months ago
There is a requirement to not create a trust between the two merging companies ADDS. Wouldn't cloud sync be the right selection?
upvoted 2 times
...
AZ_Master
1 year, 9 months ago
Why not A for cloud sync? "Support for synchronizing to an Azure AD tenant from a multi-forest disconnected Active Directory forest environment: The common scenarios include merger & acquisition (where the acquired company's AD forests are isolated from the parent company's AD forests), and companies that have historically had multiple AD forests." Ref: https://learn.microsoft.com/en-us/azure/active-directory/hybrid/cloud-sync/what-is-cloud-sync
upvoted 5 times
...
katvik001
1 year, 9 months ago
B is correct, litware.com should be included in AADC.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago