Azure · SC-300

SC-300 · Identity test

25 scenario-based questions about Microsoft Entra, hybrid identity, authentication, Conditional Access, applications, PIM and identity governance.

25 questions4 domainsEstimated 30–40 min

Reviewed · 13 July 2026

0 / 25 answered

Question 1: A regional IT administrator should manage users only in their part of the organization, without access to other tenant users. What should be used?
Question 2: The security team wants to classify service accounts and use the classification in dynamic rules and access control. What is most relevant?
Question 3: A supplier user should access resources with an existing identity and appear as a guest in the tenant. Which feature is used?
Question 4: Two organizations want to automatically create, update and remove agreed B2B users from a source tenant into a target tenant. What should be configured?
Question 5: A hybrid organization wants cloud authentication to continue if connectivity to on-premises domain controllers fails. Which primary sign-in method provides the strongest resilience?
Question 6: What is a key difference between Entra Connect Sync and Cloud Sync?
Question 7: A new employee without an existing authentication method must securely register a passkey or Authenticator at first sign-in. What can the administrator issue?
Question 8: The organization requires a phishing-resistant authentication method for administrators. Which choice is best suited?
Question 9: A new Conditional Access policy could lock out many users. How should its impact be validated first?
Question 10: How should emergency access accounts be treated in a Conditional Access design?
Question 11: What does sign-in risk express in Entra ID Protection?
Question 12: What is the purpose of Continuous Access Evaluation?
Question 13: An Azure Function must call Storage without credentials, and the identity should follow the Function resource lifecycle. What should be used?
Question 14: The same workload identity should be shared by several Azure resources and remain when one resource is deleted. Which type fits?
Question 15: An interactive client calls an API on behalf of the signed-in user. Which permission type is normally used?
Question 16: An API wants application-specific roles such as Admin and Reader in the token. What should be defined in the app registration?
Question 17: A daemon application needs high-risk Microsoft Graph application permissions. Who normally approves access?
Question 18: An on-premises web application should be securely published to external users with Entra preauthentication and no inbound firewall port. What fits best?
Question 19: A team wants to limit user consent to verified publishers and low-risk permissions. Which mechanism controls this?
Question 20: A project manager wants one package of group, application and SharePoint access that users request with approval and expiry. What is used?
Question 21: Owners should confirm quarterly that members still need access to a sensitive group. Which feature is designed for this?
Question 22: An administrator role should be available on demand but require activation for at most one hour with MFA and justification. What is configured?
Question 23: A group grants many resources, and membership should be time-limited and approval-controlled. What can be used?
Question 24: The security team wants to analyze Entra sign-in and audit logs with KQL over time. What must be configured?
Question 25: A consultant access package expires. The organization wants to block or remove guest accounts with no other assignments. Which area handles this?