exam questions

Exam SC-300 All Questions

View all questions & answers for the SC-300 exam

Exam SC-300 topic 4 question 37 discussion

Actual exam question from Microsoft's SC-300
Question #: 37
Topic #: 4
[All SC-300 Questions]

HOTSPOT
-

You have an Azure AD tenant that contains the groups shown in the following exhibit.



Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
wsrudmen
Highly Voted 2 years, 4 months ago
It seems correct. Here my thinking: - Managed identity to Security group only. The security group can't be Dynamic or sync from OnPremise - AD User Cloud can be added to Security and M365 groups ○ Not the dynamic (Group3) as it's using a query to get members Not Group4 as it's synch from OnPrem
upvoted 14 times
Labelfree
7 months ago
Why can't the security group be dynamic?
upvoted 1 times
Arash123
6 months, 3 weeks ago
Security group can be dynamic but you cannot directly assign a user to a dynamic group.
upvoted 3 times
...
...
...
Obi_Wan_Jacoby
Most Recent 1 month, 1 week ago
Given answers are correct. Microsoft 365 groups (even with security enabled) ONLY support users and devices. They do not support managed identities or service principals. You cannot sync Managed identies to groups synced from on-prem. You cannot add a managed identity, service principal or even a regular user to a dynamic group as they are members due only based on attributes. As for Security groups (in-cloud) you can add the managed identity. This is the case as the security group assigns Roles and/or grants permissions to resources.
upvoted 1 times
...
Arash123
6 months, 3 weeks ago
1st question: you can only add a managed identity to a Security group. You cannot add it to a 365 group by changing "SecurityEnabled" to True. Tested!
upvoted 1 times
...
Sc300ExamDemo
1 year ago
-Tested in azure and office admin portal. Managed Identity can only be seen in security groups. Not mailed enabled , distribution or m365 -On-premise and dynamic group cannot allow manually assignment of users
upvoted 4 times
Labelfree
7 months ago
The question doesn't ask for "manual" assignment - so they can be included
upvoted 1 times
...
...
penatuna
1 year, 2 months ago
The managed identity answer seems right. However, in the second question, there's no right answer to choose: The question only asks if you can add the cloud user to group. You can add Azure AD cloud user also to Group3. You can do it with dynamic membership rule. For example, you can use this rule to add user name clouduser to group: (user.displayName -eq "clouduser") For Group4, I tried it with both Microsoft Entra Cloud Sync and Microsoft Entra Connect. As far as I can see, you cannot add members to on-premises group in the cloud. Groups synced from on-premises Active Directory can be managed only in on-premises Active Directory.
upvoted 2 times
...
EmnCours
1 year, 10 months ago
Group 2 only All company, Group 1 and Group 2 only
upvoted 2 times
...
dule27
1 year, 11 months ago
Group 2 only All company, Group 1 and Group 2 only
upvoted 2 times
...
dejo
2 years, 4 months ago
2) Cloud users CAN be added to the dynamic cloud security group (like Group3)! Also, I think that cloud users can be added to the security group synced from the on-prem, but only if the group writeback is enabled for that group. That user will be visible as a group member in the Azure AD, but won't be synced back to the on-prem AD group Not tested but here is more info: - https://identity-man.eu/2022/07/05/using-the-new-group-writeback-functionality-in-azure-ad/ "Users which are ‘cloud only’ and are a member of the group are therefore not written back as member." - https://practical365.com/azure-ad-connect-group-writeback-deep-dive/ "If you add any Azure AD cloud-only identities, they will not show up in Active Directory and your group membership will not be consistent."
upvoted 2 times
...
Halwagy
2 years, 4 months ago
The given answer is correct
upvoted 2 times
...
BRoald
2 years, 4 months ago
second answer is correct, allcompany, group 1 & 2, im not sure about the first question. I looked up and i only can find something about security groups, but not about dynamic groups
upvoted 2 times
CheMetto
1 year, 11 months ago
I follow this idea: You can't add any members to any dynamic group manually! You have to change roles of the group to make it happen, so answer is no
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...