exam questions

Exam AZ-304 All Questions

View all questions & answers for the AZ-304 exam

Exam AZ-304 topic 2 question 56 discussion

Actual exam question from Microsoft's AZ-304
Question #: 56
Topic #: 2
[All AZ-304 Questions]

HOTSPOT -
You have the Free edition of a hybrid Azure Active Directory (Azure AD) tenant. The tenant uses password hash synchronization.
You need to recommend a solution to meet the following requirements:
✑ Prevent Active Directory domain user accounts from being locked out as the result of brute force attacks targeting Azure AD user accounts.
✑ Block legacy authentication attempts to Azure AD integrated apps.
✑ Minimize costs.
What should you recommend for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: Smart lockout -
Smart lockout helps lock out bad actors that try to guess your users' passwords or use brute-force methods to get in. Smart lockout can recognize sign-ins that come from valid users and treat them differently than ones of attackers and other unknown sources. Attackers get locked out, while your users continue to access their accounts and be productive.
Box 2: Conditional access policies
If your environment is ready to block legacy authentication to improve your tenant's protection, you can accomplish this goal with Conditional Access.
How can you prevent apps using legacy authentication from accessing your tenant's resources? The recommendation is to just block them with a Conditional
Access policy. If necessary, you allow only certain users and specific network locations to use apps that are based on legacy authentication.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-password-smart-lockout https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/block-legacy-authentication

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
MrRandom
Highly Voted 3 years, 8 months ago
GIven answers are not correct, as they are using Azure AD Free. -Smart Lockout requires Azure AD P1 or higher (Source: https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/concept-fundamentals-security-defaults) -Conditional Access Policies requires Azure AD P1 or higher (Source: https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/concept-fundamentals-security-defaults) Correct answers are Pass-Through Authentication (PTA) and Security Defaults PTA Rationale: Authentication and password policy is handled by OnPrem DCs. We can configure security policies OnPrem to disable and account for X amount of minutes for password spray attacks. Security Defaults: Blocking legacy authentication protocols (Source: https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/concept-fundamentals-security-defaults) This also minimizes cost.
upvoted 51 times
kilowd
2 years, 9 months ago
Smart lockout Security defaults Smart lockout is always on, for all Azure AD customers, with these default settings that offer the right mix of security and usability. CUSTOMIZATION of the smart lockout settings, with values specific to your organization, requires Azure AD Premium P1 or higher licenses for your users.
upvoted 3 times
...
sapien45
2 years, 10 months ago
Thank you for the smart explanations
upvoted 1 times
...
[Removed]
3 years, 8 months ago
Smart lockout is always on, for all Azure AD customers, with these default settings that offer the right mix of security and usability. Customization of the smart lockout settings, with values specific to your organization, requires Azure AD Premium P1 or higher licenses for your users. Pass through auth wont stop on prem accounts being locked out, quite the opposite. Smart lockout and Security Defaults make the most sense for Azure AD Free customers
upvoted 44 times
kktamang
3 years, 1 month ago
No. Read question carefully. It says infra runs with Azure free license. Smart lock and conditional access need AAD premium P1 license.
upvoted 1 times
ninjaTT
3 years ago
you can use Smart Lock with Azure AD for no extra cost
upvoted 4 times
...
...
...
SanjSL
3 years, 3 months ago
Smart lockout is always on, for all Azure AD customers, with these default settings that offer the right mix of security and usability. Customization of the smart lockout settings, with values specific to your organization, requires Azure AD Premium P1 or higher licenses for your users. https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-password-smart-lockout#how-smart-lockout-works Microsoft is making security defaults available to everyone. https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/concept-fundamentals-security-defaults#availability Smart lockout and Security Defaults
upvoted 18 times
kktamang
3 years, 1 month ago
No. Read question carefully. It says infra runs with Azure free license. Smart lock and conditional access need AAD premium P1 license.
upvoted 2 times
JayBee65
2 years, 10 months ago
Please review this link https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-password-smart-lockout which clearly states that statement to be wrong. "Smart lockout is always on, for ***ALL*** Azure AD customers,". P1 is required to customise the settings, again as stated on the link.
upvoted 2 times
...
...
...
...
dkltruong88
Highly Voted 3 years, 7 months ago
Was in exam today 1-10-2021. I passed with score 896. I chose smart lockout for 1 and Enable Security Defaults for 2
upvoted 36 times
...
Cg007
Most Recent 1 year ago
1. To protect against brute force attacks: Smart lockout should be recommended. Azure AD has a smart lockout feature that can recognize sign-ins coming from valid users and treat them differently than ones that are likely from attackers. Smart lockout can lock out attackers while letting valid users continue to access their accounts. 2. To block legacy authentication attempts: Enable Security defaults should be recommended. Security defaults in Azure AD make it easier to help protect your organization with preconfigured security settings for common attacks. This includes blocking legacy authentication protocols that can be used with guessing simple passwords or are not capable of doing multi-factor authentication. Both options are available in the free edition of Azure AD and do not incur additional costs, which satisfies the requirement to minimise costs.
upvoted 1 times
Cg007
1 year ago
For the Free edition of Azure AD, full Conditional Access policy functionality is not available. Conditional Access requires Azure AD Premium P1 or P2, which are paid versions.
upvoted 1 times
...
...
rana9371
2 years, 5 months ago
Smart Lockout is always enable for all versions of Azure AD. In this question Azure AD free version is used so smart lockout is enabled by default but can't make any changes to setting of smart lockout. So, if there is a need to make changes in the setting of Smart Lockout then it requires AAD P1 or higher license. So, Smart Lockout is correct answer.
upvoted 1 times
...
kmeena
2 years, 10 months ago
Smart lockout https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-password-smart-lockout#how-smart-lockout-works Enable security defaults https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/concept-fundamentals-security-defaults
upvoted 1 times
...
g6singh
2 years, 11 months ago
1. Smart Lockout Smart lockout is always on, for all Azure AD customers, with these default settings that offer the right mix of security and usability. Customization of the smart lockout settings, with values specific to your organization, requires Azure AD Premium P1 or higher licenses for your users. 2. Security Default Security defaults: Available versions of Azure AD Multi-Factor Authentication Azure AD Multi-Factor Authentication can be used, and licensed, in a few different ways depending on your organization's needs. All tenants are entitled to basic multifactor authentication features via Security Defaults.
upvoted 1 times
...
cloudera
3 years, 1 month ago
With an AAD Free license, I would say: 1. SMART LOCKOUT with default setting (Customization require AAD Premium P1 as explained here: https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-password-smart-lockout#:~:text=Customization%20of%20the%20smart%20lockout,user%20is%20never%20locked%20out. Azure AD > Security > Authentication Methods 2. DEFAULT SECURITY SETTING (also available to AAD free version) Azure AD > Properties > Manage Security Defaults > Toggle to YES > Save https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/concept-fundamentals-security-defaults
upvoted 3 times
...
kktamang
3 years, 1 month ago
Question is very confusing. Smart Lock protects from Brute Force attack but requires AAD P1 or higher license but Question says company has free AAD license.
upvoted 1 times
JayBee65
2 years, 10 months ago
No, you are wrong, read the information above and stop saying everyone is wrong when you are wrong :)
upvoted 1 times
...
...
exnaniantwort
3 years, 1 month ago
Conditional access and Security defaults both can do see Conditional access https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/block-legacy-authentication Security defaults: Available versions of Azure AD Multi-Factor Authentication Azure AD Multi-Factor Authentication can be used, and licensed, in a few different ways depending on your organization's needs. All tenants are entitled to basic multifactor authentication features via Security Defaults. But conditonal access is rejected because the question states it's free subscription. Security default is available for free version (stated above)
upvoted 1 times
...
AdamHarrison
3 years, 1 month ago
Can confirm Smart Lockout and Security Defaults based on the course I just finished, which had this question in the practice tests.
upvoted 1 times
...
plmmsg
3 years, 1 month ago
1. Smart Lockout 2. Security Default
upvoted 1 times
...
ixl2pass
3 years, 3 months ago
Smart Lock and Security defaults https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/concept-fundamentals-security-defaults
upvoted 2 times
...
qerem
3 years, 3 months ago
Smart Lockout & Security Defaults : Smart lockout helps lock out bad actors that try to guess your users' passwords or use brute-force methods to get in. Smart lockout can recognize sign-ins that come from valid users and treat them differently than ones of attackers and other unknown sources. Attackers get locked out, while your users continue to access their accounts and be productive.
upvoted 2 times
...
student22
3 years, 6 months ago
1. Smart lockout 2. Security defaults
upvoted 11 times
...
syu31svc
3 years, 7 months ago
https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-password-smart-lockout Smart lockout helps lock out bad actors that try to guess your users' passwords or use brute-force methods to get in https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/concept-fundamentals-security-defaults#blocking-legacy-authentication Protect brute force using mart lockout and block legacy using security defaults
upvoted 1 times
...
nkv
3 years, 7 months ago
came in exam on 20-sep-21, I passed, i choose pass through and enable default
upvoted 2 times
...
souvik123
3 years, 7 months ago
1. Smart Lockout 2. Security Default
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago