exam questions

Exam AZ-301 All Questions

View all questions & answers for the AZ-301 exam

Exam AZ-301 topic 10 question 2 discussion

Actual exam question from Microsoft's AZ-301
Question #: 2
Topic #: 10
[All AZ-301 Questions]

HOTSPOT -
To meet the authentication requirements of Fabrikam, what should you include in the solution? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
MadhuG
Highly Voted 5 years, 3 months ago
require 2 policies: one for specific location and second is for enabling MFA for Administrative access
upvoted 37 times
RStover
5 years, 1 month ago
This can all be done with one policy.
upvoted 8 times
...
juri
4 years, 11 months ago
no specific location is necessary: "All administrative access to the Azure portal must be secured by using multi-factor authentication." Id go with only one conditional access policy
upvoted 2 times
...
asdfgh1234567
4 years, 11 months ago
"only available within the company" is not talking about physical location it's talking about user location. if it said "data cannot be accessed outside of the company network" then we can control that with a CAP. However, it is talking about Guest access, which can be controlled with a CAP. A Blocking policy would be implemented which targets guest accounts, i.e. no guest users can access the Azure AD tenancy, but further to this that would be a blanket rule of "no guest users" and in which case this would be better configured by disabling guest access to Azure AD entirely, i.e. no CAP required. My answer is 1, 1, 1 - CAP only reqiured to enforce MFA for Admin accounts.
upvoted 5 times
levianthan
4 years, 9 months ago
It actually doesn't say this nor that. The requirement "outside the company" is too ambiguous.
upvoted 3 times
...
...
...
AS007
Highly Voted 5 years, 2 months ago
1 1 1 Not 2 policies
upvoted 14 times
...
glam
Most Recent 4 years, 3 months ago
1 1 0 ( because we can use the pre-defined polices in conditional access policy)
upvoted 2 times
j888
4 years, 3 months ago
I agree with 0 as conditional policy - data cannot be accessed outside of the company network (this is not restricted through conditional access. I suspect it's through policy) 2. admin group must be secured by using multi-factor authentication (there is nothing specify of condition a such from offsite address, so it must be the priviledge management.)
upvoted 1 times
...
...
azurecert2021
4 years, 4 months ago
given answer is correct answer is 1,1,2 We just need one Azure AD tenant to host the information for corp.fabrikam.com,Since there is only one forest that needs to be synced with Azure AD, one can opt for having one Azure AD tenant. We just need one custom domain to be created for corp.fabrikam.com Conditional access : 1. data cannot be accessed outside of the company network (Condition based on Location name or IP) 2. admin group must be secured by using multi-factor authentication ( Condition based on user/group membership) https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/howto-conditional-access-policy-admin-mfa https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/howto-conditional-access-policy-location
upvoted 2 times
sejalo
4 years, 4 months ago
But question is asking for authentication. To meet the authentication requirements of Fabrikam, what should you include in the solution?
upvoted 1 times
...
...
sanketshah
4 years, 5 months ago
1, 1, 2 are correct answer.
upvoted 2 times
...
Edhotp
4 years, 7 months ago
1,1,2 Conditional access : 1. data cannot be accessed outside of the company network (Condition based on Location name or IP) 2. admin group must be secured by using multi-factor authentication ( Condition based on user/group membership)
upvoted 2 times
...
citizen_zero
4 years, 7 months ago
"All R&D operations will remain on-premises." why do you need 2nd domain on Azure?
upvoted 2 times
...
David_986969
4 years, 8 months ago
Shouldn´t be two domains "The network contains two Active Directory forests named corp.fabrikam.com and rd.fabrikam.com. There are no trust relationships between the forests."
upvoted 3 times
...
smsulai
4 years, 10 months ago
dont go with high upvoted for this question....you dont need to create any new policies . You can try use the free policy Baseline hence i would go with 1,1,0
upvoted 2 times
ro_yahoo
4 years, 10 months ago
Baseline policies are now deprecated, below is what you get when you click on the baseline policy "This policy has been deprecated and is no longer being enforced. If you are looking to enable similar functionality, we recommend enabling security defaults or configuring the equivalent conditional access policies." So we have to create a new policy for controlling admin access.
upvoted 1 times
tmurfet
4 years, 9 months ago
No, you can enable security defaults instead which enforces MFA for admins. If your tenant was created after Nov 2919, then security defaults are likely enabled by default.
upvoted 2 times
...
...
...
eug45
4 years, 11 months ago
the correct answer: 1, 1, 0 There is already a policy with the name of “Baseline policy: Require MFA for admins” that comes along with even the Free tier of Azure AD. This enables multi-factor authentication for all types of administrators. You can just enable this policy. There is no need to create a new policy.
upvoted 4 times
...
NKnab
4 years, 11 months ago
Go straight to MadhuG comment
upvoted 3 times
gboyega
4 years, 11 months ago
No he is wrong. 1 1 0 ( because we can use the pre-defined polices in conditional access policy)
upvoted 7 times
Kaawa
4 years, 11 months ago
you always need to create a policy!
upvoted 1 times
gboyega
4 years, 11 months ago
No you dont, Have you used CAP before and have you taken the time to review the default policies? Take time to check that in your lab
upvoted 2 times
...
...
saran1987
4 years, 9 months ago
Where do you see pre-defined policy ? I dont find any policy pre-defined if I open conditional access. This feature is depricated
upvoted 1 times
...
...
gboyega
4 years, 11 months ago
No dont bother going there. He is wrong. Answer is 1,1,0
upvoted 2 times
...
...
dev2dev
4 years, 12 months ago
"All administrative access to the Azure portal must be secured by using multi-factor authentication." how does this achevied without conditional access policiy?
upvoted 2 times
...
DeveshSolanki
5 years ago
Answer is 1, 1 , 0
upvoted 5 times
...
ssrr
5 years ago
So what was the answer for point 3 here do we need 1 policy or 2 policies? I am totally confused
upvoted 5 times
superbutt
5 years ago
Not only you... xD I will go with the general answer (1 1 2)
upvoted 7 times
...
...
ruval
5 years, 1 month ago
why we need to add a custom domain to Azure AD? Is the Azure domain controller requiring custom domain?
upvoted 2 times
asdfgh1234567
4 years, 11 months ago
users need to authenticate with their corp UPN which includes a custom domain.
upvoted 4 times
...
...
pandeya442
5 years, 1 month ago
given ans is correct
upvoted 1 times
...
Shiven
5 years, 1 month ago
Correct answers are 1 1 0
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...