exam questions

Exam SC-300 All Questions

View all questions & answers for the SC-300 exam

Exam SC-300 topic 1 question 18 discussion

Actual exam question from Microsoft's SC-300
Question #: 18
Topic #: 1
[All SC-300 Questions]

HOTSPOT -
Your network contains an on-premises Active Directory domain named contoso.com. The domain contains the objects shown in the following table.

You install Azure AD Connect. You configure the Domain and OU filtering settings as shown in the Domain and OU Filtering exhibit. (Click the Domain and OU
Filtering tab.)

You configure the Filter users and devices settings as shown in the Filter Users and Devices exhibit. (Click the Filter Users and Devices tab.)

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Only direct members of Group1 are synced. Group2 will sync as it is a direct member of Group1 but the members of Group2 will not sync.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-install-custom

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Jhill777
Highly Voted 1 year, 12 months ago
This is a dumb question that only some dude at MSFT would write. Tested in lab because you'll never do something this dumb in real life. The answer is correct even though the wizard specifically states "Nested groups are not supported and will be ignored." They are not ignored. User1, Group1 and Group2 were created in Azure AD. User2 was not.
upvoted 32 times
its_tima
1 year, 10 months ago
well depends on what type of group: Security or Office 365? If not them. perhaps the question makes you assume it's a Dynamic Group.
upvoted 1 times
its_tima
1 year, 10 months ago
I take my word back, it's security so the question should get blame
upvoted 2 times
...
...
...
DrMe
Highly Voted 3 years, 1 month ago
Correct: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-install-custom#:~:text=When%20you%20add%20a%20group%20as%20a%20member%2C%20only%20the%20group%20itself%20is%20added.%20Its%20members%20aren%27t%20added.
upvoted 22 times
...
RahulX
Most Recent 9 months, 1 week ago
YES NO YES
upvoted 1 times
...
Nivos23
1 year ago
YES NO YES
upvoted 1 times
...
EmnCours
1 year, 3 months ago
Correct: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-install-custom#:~:text=When%20you%20add%20a%20group%20as%20a%20member%2C%20only%20the%20group%20itself%20is%20added.%20Its%20members%20aren%27t%20added
upvoted 1 times
...
dule27
1 year, 5 months ago
YES NO YES
upvoted 1 times
...
Efficia
2 years, 4 months ago
The given answer is correct. Group 2 is a member of Group 1, so only Group 2 will sync, its members won't sync. https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-install-custom#sync-filtering-based-on-groups "All objects that you want to synchronize must be direct members of the group. Users, groups, contacts, and computers or devices must all be direct members. Nested group membership isn't resolved. **When you add a group as a member, only the group itself is added. Its members aren't added.**"
upvoted 5 times
...
Tokiki
2 years, 4 months ago
Correct, YNY
upvoted 1 times
...
rachee
2 years, 4 months ago
In the "Filter Users and Devices" exhibit it states "Nested groups are not supported and will be ignored." So does this mean only the the users and devices in a nested group won't sync, or the group won't sync either?
upvoted 2 times
...
RandomNickname
2 years, 5 months ago
See articles pasted by other members and on answer sections for refereance as to why. 1:Y - User1 is a member of Group 1, and a direct member so as the group is synced, so will this. 2:N - User 2 is not a member of group1, and filtering is in place for G1. 3:Y - G2 will be synced becaused it's a direct member of G1, however any nested, for example, members of G2 will not be synced, so direct users or groups of G1 will. For reference see below excert from MS article "All objects that you want to synchronize must be direct members of the group. Users, groups, contacts, and computers or devices must all be direct members. Nested group membership isn't resolved. When you add a group as a member, only the group itself is added. Its members aren't added."
upvoted 10 times
...
TP447
2 years, 7 months ago
At first i thought this should be Y/N/N but having confirmed in the article, Group 2 will sync as a Direct Member of Group 1 delegated for the pilot. Therefore Y/N/Y is correct.
upvoted 4 times
...
SnottyPudding
2 years, 8 months ago
Q3 is NO: "When using OU-based filtering in conjunction with group-based filtering, the OU(s) where the group and its members are located must be included." Synchronization is selected only for OU2, and Group2 is in OU1. Therefore, Group2 WILL NOT sync to Azure AD. https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sync-configure-filtering#group-based-filtering
upvoted 3 times
kanew
1 year, 6 months ago
I initially thought that but on reflection agree with the Y,N,Y . Think of the group filter as a subset of the OU's selected. So all members of OU1 and OU1 are in scope then the filter removes (filters!) anyone not in Group 1. It doesn't matter which OU Group 2 is in. It synchs as is part of the OUs in scope and not filtered out as is a first level member of Group1. Jeez I did a bad job of explaining that. terrible scenario - it was talked about many years ago but I've never seen any organization ever use it!
upvoted 1 times
...
...
gugamotarj
2 years, 8 months ago
Group 2 is Nested and it will be ignored. Y, N, N is the correct.
upvoted 4 times
SnottyPudding
2 years, 8 months ago
Also, Group2 is in OU1 and will be ignored. "When using OU-based filtering in conjunction with group-based filtering, the OU(s) where the group and its members are located must be included." Synchronization is selected only for OU2, and Group2 is in OU1. Therefore, Group2 WILL NOT sync to Azure AD. https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sync-configure-filtering#group-based-filtering
upvoted 1 times
...
...
lime568
2 years, 8 months ago
All objects that you want to synchronize must be direct members of the group. Users, groups, contacts, and computers or devices must all be direct members. Nested group membership isn't resolved. When you add a group as a member, only the group itself is added. Its members aren't added.
upvoted 3 times
...
GPerez73
2 years, 9 months ago
In my opinion, user2 also syncs to AAD. it is located in OU1, and OU1 syncs to AAD
upvoted 2 times
A_K99
2 years, 9 months ago
OU1 doesn't sync to the AAD, just Group1 and OU2
upvoted 1 times
GPerez73
2 years, 8 months ago
It is true, you are right.
upvoted 1 times
...
teriaavibes
2 years, 8 months ago
OU2 doesn't sync, that is just path to group one in the pilot, if you want to sync the whole OU you don't run pilot.
upvoted 1 times
...
...
...
btk_1
2 years, 9 months ago
If Filter users and devices (for a pilot deployment) further refines the Domain and OU filtering, then only Group1 (OU2) syncs. YES - User1 is a member of Group1, NO - User2 is not a member of Group1, NO - Group2 is a member of Group1, but nested groups are ignored in Filter users and devices.
upvoted 3 times
valgaw
2 years, 9 months ago
According to DrMe link, answers is correct Group2 will be added / synced as a member of Group1, but not members of that group: " When you add a group as a member, only the group itself is added. Its members aren't added"
upvoted 2 times
...
...
summut
2 years, 10 months ago
Actually to be honest this would probably cause Azure Connect to fail for Group 1 and Group 2 because by what I can see there is circular Group nesting in place. But if you ignore that then the answer is correct.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago