exam questions

Exam SC-300 All Questions

View all questions & answers for the SC-300 exam

Exam SC-300 topic 4 question 66 discussion

Actual exam question from Microsoft's SC-300
Question #: 66
Topic #: 4
[All SC-300 Questions]

You have three Azure subscriptions that are linked to a single Microsoft Entra tenant.

You need to evaluate and remediate the risks associated with highly privileged accounts. The solution must minimize administrative effort.

What should you use?

  • A. Global Secure Access
  • B. Privileged Identity Management (PIM)
  • C. Microsoft Entra Permissions Management
  • D. Microsoft Entra Verified ID
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Steingalen
Highly Voted 1 year, 5 months ago
Selected Answer: B
To evaluate and remediate the risks associated with highly privileged accounts across multiple Azure subscriptions linked to a single Microsoft Entra tenant, you should use Privileged Identity Management (PIM) (Option B). Microsoft Entra PIM provides time-based and approval-based role activation to mitigate the risks of excessive, unnecessary, or misused access permissions on resources that you care about. It helps you manage, control, and monitor access within your organization, which includes access to Azure resources and other Microsoft services. Please note that while Microsoft Entra Permissions Management can provide visibility into permissions across multicloud infrastructures, it doesn’t specifically target the management of highly privileged accounts. Global Secure Access and Microsoft Entra Verified ID do not provide the specific capabilities required for this scenario.
upvoted 10 times
...
Sneekygeek
Highly Voted 1 year, 6 months ago
Selected Answer: C
Answer is C
upvoted 5 times
...
Obi_Wan_Jacoby
Most Recent 3 months ago
Selected Answer: B
Answer: B. I was torn between B and C. Lots of back and forth between a couple diff AI's turned up the below. PIM's direct focus on the lifecycle management of privileged roles within the Microsoft Entra tenant and its linked subscriptions, along with its built-in workflows and centralized control, likely leads to a solution that minimizes administrative effort more effectively for this specific requirement. Therefore, while Permissions Management excels at evaluating risk, Privileged Identity Management (PIM) (Option B) likely better addresses the requirement to minimize administrative effort while still providing significant capabilities for evaluating (through visibility of assignments) and remediating (through control) risks associated with highly privileged accounts within the specified Microsoft Entra tenant and its linked Azure subscriptions.
upvoted 1 times
...
YesPlease
5 months ago
Selected Answer: C
Answer C) Microsoft Entra Permissions Management https://learn.microsoft.com/en-us/entra/permissions-management/
upvoted 1 times
...
Frank9020
6 months, 3 weeks ago
Selected Answer: C
To evaluate and remediate the risks associated with highly privileged accounts while minimizing administrative effort, you should use Microsoft Entra Permissions Management. This tool provides a comprehensive solution for managing permissions and roles across multiple cloud environments, including Azure
upvoted 2 times
rvln7
5 months, 2 weeks ago
You can basically evaluate and remediate the risk by using both PIM and Permission Management, but I think they were aiming to Permission Management "minimizing administrative effort" was mentioned
upvoted 1 times
...
...
Nail
9 months, 2 weeks ago
Selected Answer: C
I think it's got to be C. in the description: "Discover Customers can assess permission risks by evaluating the gap between permissions granted and permissions used." " Remediate Customers can right-size permissions based on usage, grant new permissions on-demand, and automate just-in-time access for cloud resources." https://learn.microsoft.com/en-us/entra/permissions-management/overview. I don't see how PIM does anything to "evaluate" risk.
upvoted 1 times
...
aocferreira
9 months, 3 weeks ago
Selected Answer: C
it doesn't matter if its multi-cloud or not, Entra Permissions Management can be used for Azure only without onboarding AWS or GCP. The answer is C as it provides this centralized location where we can easily check and fix the issues with permissions that have higher privileges..
upvoted 1 times
...
Sc300ExamDemo
1 year, 2 months ago
Selected Answer: B
Only if the question asks about multi cloud, then I would go for C "Entra Permission Management". Else just within Azure, PIM would suffice.
upvoted 2 times
...
medi1520
1 year, 4 months ago
Selected Answer: B
La respuesta es la B
upvoted 4 times
...
Ody
1 year, 5 months ago
Could make a case for PIM, but I think Microsoft wants to hear Permission Management. The only thing that may not make it Permission Management is that it doesn't say multi-cloud.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...