exam questions

Exam SC-300 All Questions

View all questions & answers for the SC-300 exam

Exam SC-300 topic 2 question 99 discussion

Actual exam question from Microsoft's SC-300
Question #: 99
Topic #: 2
[All SC-300 Questions]

HOTSPOT
-

You have an Azure subscription named Sub1.

You plan to use Microsoft Entra Permissions Management to manage Sub1.

You need to ensure that Permissions Management can perform the following tasks:

• Identify unused permissions assigned to applications and managed identities.
• Provide users with recommendations about which permissions to remove.
• Remove unused permissions.

The solution must follow the principle of least privilege.

Which role should you assign to the service principal of Permissions Management, and what should you use to provide recommendations and remove unused permissions? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
sn0rlaxxx
3 months ago
It should be 1. Permissions Management Administrator (User acess admin as a requirement has been updated). 2. Autopilot
upvoted 1 times
rvln7
2 months ago
The question is asking about the role assigned to the service principal of Microsoft Entra Permissions Management when registering the app in Azure—not the role required for a user to access Permissions Management. While Reader allows analysis, it does not provide permission to remove unused permissions. Since you need to identify, recommend, and remove unused permissions, the service principal of Microsoft Entra Permissions Management requires a role with write permissions as well. 1. Owner Grants full control over permissions management, allowing the service to analyze, recommend, and remove permissions as required. 2. Autopilot The owner role is also required for Autopilot to automatically remove permissions.
upvoted 1 times
...
...
northgaterebel
3 months, 2 weeks ago
1. User Access Administrator. AI search recommends Role Based Access Control Administrator but that is not an option. 2. An Autopilot rule. https://learn.microsoft.com/en-us/entra/permissions-management/ui-autopilot
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago