Skip to content
Oluma Cyber Security Awareness
Microsoft Identity & Access Administrator (SC-300) — Practice Exam | Oluma Digital
Cert Zone · Identity & Access Management

Microsoft Identity & Access Administrator

SC-300

Microsoft Certified: Identity and Access Administrator Associate

The SC-300 validates your ability to design, implement, and operate an organization’s identity and access management using Microsoft Entra ID — managing users and groups, securing authentication with MFA and Conditional Access, protecting workload identities, and governing access with PIM, access reviews, and entitlement management.

Managed by
Microsoft
Exam code
SC-300
Level
Associate (role-based)
Delivery
Pearson VUE — online proctored or test center
Length
~100 minutes
Exam fee
~US$165 (varies by region)
Renewal
Annually — free online renewal
Questions here
100 practice items
Format
Multiple choice
🔗 Official exam page — learn.microsoft.com → SC-300

What the exam covers

The official skills are grouped into these domains.

01

Implement and manage user identities

Tenants, users & groups, external (B2B) identities, hybrid identity and device join.

02

Implement authentication & access management

MFA, passwordless, Conditional Access, SSPR, and Entra ID Protection.

03

Plan and implement workload identities

App registrations, service principals, managed identities, and permissions/consent.

04

Plan and implement identity governance

Entitlement management, access reviews, PIM, terms of use and lifecycle workflows.

Domain weightings shift slightly between exam refreshes — always confirm the current skills outline on the official exam page above.

Practice questions

Number of questions:

Pick a length, then choose an answer for instant feedback. Your score tracks below and counts only the questions you can see.

User identities

What is a Microsoft Entra tenant?

✓ Access granted.  A tenant is an organization's own isolated Entra ID directory instance.
✗ Access denied.  Correct answer: A dedicated, isolated instance of Entra ID for an organization. A tenant is an organization's own isolated Entra ID directory instance.
User identities

Which group membership type adds and removes users automatically based on attribute rules?

✓ Authenticated.  Dynamic groups use membership rules to update membership automatically (requires Entra ID P1).
✗ Access denied.  Correct answer: Dynamic group. Dynamic groups use membership rules to update membership automatically (requires Entra ID P1).
User identities

An 'Assigned' group differs from a dynamic group because it:

✓ Identity verified.  Assigned (static) groups have members added/removed manually by an admin.
✗ Access denied.  Correct answer: Requires members to be added manually. Assigned (static) groups have members added/removed manually by an admin.
User identities

To let an external partner collaborate using their own organization's credentials, you use:

✓ Trust established.  B2B collaboration invites external users as guests who sign in with their home credentials.
✗ Access denied.  Correct answer: B2B collaboration (guest invitation). B2B collaboration invites external users as guests who sign in with their home credentials.
User identities

Which solution is designed for customer-facing sign-up/sign-in (consumer identity)?

✓ Privilege confirmed.  B2C / Microsoft Entra External ID handles consumer (CIAM) identities separate from workforce users.
✗ Access denied.  Correct answer: Azure AD B2C / Entra External ID. B2C / Microsoft Entra External ID handles consumer (CIAM) identities separate from workforce users.
User identities

Self-Service Password Reset (SSPR) allows users to:

✓ Token validated.  SSPR reduces helpdesk load by letting users securely reset/unlock their own passwords.
✗ Access denied.  Correct answer: Reset or unlock their own account after verifying identity. SSPR reduces helpdesk load by letting users securely reset/unlock their own passwords.
User identities

Which license tier is required for dynamic groups and Conditional Access?

✓ Session secured.  Dynamic membership and Conditional Access require at least Microsoft Entra ID P1.
✗ Access denied.  Correct answer: Entra ID P1. Dynamic membership and Conditional Access require at least Microsoft Entra ID P1.
User identities

The hybrid identity method that syncs a hash of the on-prem password hash to the cloud is:

✓ Policy enforced.  PHS synchronizes a hash of the password hash so users can sign in to Entra ID with the same password.
✗ Access denied.  Correct answer: Password Hash Synchronization (PHS). PHS synchronizes a hash of the password hash so users can sign in to Entra ID with the same password.
User identities

Which hybrid method validates passwords against on-prem AD in real time via an agent?

✓ Threat neutralized.  PTA uses lightweight agents to validate sign-ins directly against on-prem AD.
✗ Access denied.  Correct answer: Pass-through Authentication (PTA). PTA uses lightweight agents to validate sign-ins directly against on-prem AD.
User identities

Which tool synchronizes on-premises AD objects into Entra ID?

✓ Clean scan.  Entra Connect (and Cloud Sync) synchronize on-prem AD identities to the cloud tenant.
✗ Access denied.  Correct answer: Microsoft Entra Connect. Entra Connect (and Cloud Sync) synchronize on-prem AD identities to the cloud tenant.
User identities

The lightweight, agent-based alternative to Entra Connect Sync is:

✓ Root of trust intact.  Cloud Sync uses a lightweight agent managed from the cloud, good for multiple/disconnected forests.
✗ Access denied.  Correct answer: Entra Connect Cloud Sync. Cloud Sync uses a lightweight agent managed from the cloud, good for multiple/disconnected forests.
User identities

To delegate administration over only a subset of users (e.g., one region), you use:

✓ Credentials accepted.  Administrative units scope admin roles to a defined set of users, groups, or devices.
✗ Access denied.  Correct answer: Administrative units. Administrative units scope admin roles to a defined set of users, groups, or devices.
User identities

Following least privilege, which role manages users and groups but not global settings?

✓ Access granted.  User Administrator is scoped to user/group management, avoiding excessive Global Admin rights.
✗ Access denied.  Correct answer: User Administrator. User Administrator is scoped to user/group management, avoiding excessive Global Admin rights.
User identities

The most efficient way to assign licenses to many users is:

✓ Authenticated.  Group-based licensing assigns licenses to a group so members inherit them automatically.
✗ Access denied.  Correct answer: Group-based licensing. Group-based licensing assigns licenses to a group so members inherit them automatically.
User identities

A soft-deleted Entra user can be restored for how long before permanent deletion?

✓ Identity verified.  Deleted users remain in a recoverable state for 30 days by default.
✗ Access denied.  Correct answer: 30 days. Deleted users remain in a recoverable state for 30 days by default.
User identities

A recommended design for emergency 'break-glass' accounts is that they are:

✓ Trust established.  Break-glass accounts are cloud-only, excluded from policies that could lock them out, and monitored.
✗ Access denied.  Correct answer: Cloud-only, excluded from lock-out-causing CA, and closely monitored. Break-glass accounts are cloud-only, excluded from policies that could lock them out, and monitored.
User identities

Registering a personal BYOD device for SSO/Conditional Access without full org join is:

✓ Privilege confirmed.  Entra registered (workplace join) supports BYOD scenarios with device-based access.
✗ Access denied.  Correct answer: Entra registered. Entra registered (workplace join) supports BYOD scenarios with device-based access.
User identities

A corporate Windows device fully managed and joined directly to the cloud is:

✓ Token validated.  Entra joined devices are cloud-managed and support seamless sign-in and CA.
✗ Access denied.  Correct answer: Entra joined. Entra joined devices are cloud-managed and support seamless sign-in and CA.
User identities

Which device state combines on-prem AD domain join with Entra registration?

✓ Session secured.  Hybrid joined devices are AD domain-joined and also registered in Entra ID.
✗ Access denied.  Correct answer: Entra hybrid joined. Hybrid joined devices are AD domain-joined and also registered in Entra ID.
User identities

Which attribute uniquely identifies a user object even if their UPN changes?

✓ Policy enforced.  The immutable Object ID (GUID) is the stable identifier; UPN and other attributes can change.
✗ Access denied.  Correct answer: Object ID (GUID). The immutable Object ID (GUID) is the stable identifier; UPN and other attributes can change.
User identities

To create many users at once from a spreadsheet in the portal, you use:

✓ Threat neutralized.  Bulk create uses a CSV template to provision multiple users at once.
✗ Access denied.  Correct answer: Bulk operations / CSV import. Bulk create uses a CSV template to provision multiple users at once.
User identities

Cross-tenant access settings primarily control:

✓ Clean scan.  Cross-tenant access settings govern how your tenant trusts and collaborates with other tenants.
✗ Access denied.  Correct answer: Inbound/outbound B2B trust between Entra tenants. Cross-tenant access settings govern how your tenant trusts and collaborates with other tenants.
User identities

Entra Password Protection helps by:

✓ Root of trust intact.  Password Protection enforces banned-password lists to stop weak/common passwords.
✗ Access denied.  Correct answer: Blocking weak and banned passwords (cloud and optionally on-prem). Password Protection enforces banned-password lists to stop weak/common passwords.
User identities

A user's sign-in name in Entra (UPN) typically looks like:

✓ Credentials accepted.  The User Principal Name is an email-like identifier used for sign-in.
✗ Access denied.  Correct answer: An email-style name (user@domain). The User Principal Name is an email-like identifier used for sign-in.
User identities

To force users to re-register their security (MFA/SSPR) info, an admin can:

✓ Access granted.  Admins can revoke/require re-registration of a user's combined MFA/SSPR methods.
✗ Access denied.  Correct answer: Require re-registration of combined security info. Admins can revoke/require re-registration of a user's combined MFA/SSPR methods.
Authentication & access

Conditional Access works by evaluating signals and then applying:

✓ Authenticated.  CA evaluates conditions (user, location, device, risk) and enforces grant/session controls.
✗ Access denied.  Correct answer: Access controls such as grant/block, require MFA, or session limits. CA evaluates conditions (user, location, device, risk) and enforces grant/session controls.
Authentication & access

Which Conditional Access mode lets you observe policy impact without enforcing it?

✓ Identity verified.  Report-only logs what a policy would do, so you can validate before enforcing.
✗ Access denied.  Correct answer: Report-only. Report-only logs what a policy would do, so you can validate before enforcing.
Authentication & access

Sign-in frequency and persistent browser session are examples of:

✓ Trust established.  These are Conditional Access session controls that shape the session experience.
✗ Access denied.  Correct answer: Session controls. These are Conditional Access session controls that shape the session experience.
Authentication & access

A policy that reacts to a risky sign-in relies on which capability?

✓ Privilege confirmed.  Sign-in risk comes from Entra ID Protection and requires Entra ID P2.
✗ Access denied.  Correct answer: Entra ID Protection sign-in risk (P2). Sign-in risk comes from Entra ID Protection and requires Entra ID P2.
Authentication & access

A user-risk policy responds to:

✓ Token validated.  User risk reflects account compromise likelihood and often requires a secure password change.
✗ Access denied.  Correct answer: The likelihood the account itself is compromised (e.g., leaked credentials). User risk reflects account compromise likelihood and often requires a secure password change.
Authentication & access

Which is a phishing-resistant, passwordless hardware method?

✓ Session secured.  FIDO2 keys (WebAuthn/CTAP) provide phishing-resistant passwordless authentication.
✗ Access denied.  Correct answer: FIDO2 security key. FIDO2 keys (WebAuthn/CTAP) provide phishing-resistant passwordless authentication.
Authentication & access

Windows passwordless sign-in using biometrics or a PIN bound to the device is:

✓ Policy enforced.  Windows Hello for Business uses device-bound credentials with biometric/PIN unlock.
✗ Access denied.  Correct answer: Windows Hello for Business. Windows Hello for Business uses device-bound credentials with biometric/PIN unlock.
Authentication & access

Microsoft Authenticator's passwordless sign-in option is called:

✓ Threat neutralized.  Authenticator phone sign-in approves logins with number matching, no password needed.
✗ Access denied.  Correct answer: Phone sign-in. Authenticator phone sign-in approves logins with number matching, no password needed.
Authentication & access

Which feature reduces MFA-fatigue attacks by showing a number to type in the app?

✓ Clean scan.  Number matching forces the user to enter a displayed number, defeating blind push approvals.
✗ Access denied.  Correct answer: Number matching. Number matching forces the user to enter a displayed number, defeating blind push approvals.
Authentication & access

A time-limited passcode used to onboard a user or recover passwordless access is a:

✓ Root of trust intact.  A TAP is a short-lived passcode for onboarding and passwordless recovery.
✗ Access denied.  Correct answer: Temporary Access Pass (TAP). A TAP is a short-lived passcode for onboarding and passwordless recovery.
Authentication & access

Conditional Access 'authentication strengths' let you:

✓ Credentials accepted.  Authentication strengths enforce which credential combinations satisfy a policy.
✗ Access denied.  Correct answer: Require a specific set of stronger methods (e.g., phishing-resistant) for sensitive access. Authentication strengths enforce which credential combinations satisfy a policy.
Authentication & access

Named locations in Conditional Access are used to:

✓ Access granted.  Named locations classify IPs/countries so policies can key off location.
✗ Access denied.  Correct answer: Define trusted/known IP ranges or countries as conditions. Named locations classify IPs/countries so policies can key off location.
Authentication & access

To stop legacy authentication protocols that can't do MFA, you should:

✓ Authenticated.  Blocking legacy auth removes a common bypass of modern MFA controls.
✗ Access denied.  Correct answer: Create a CA policy that blocks legacy authentication. Blocking legacy auth removes a common bypass of modern MFA controls.
Authentication & access

Smart lockout protects against:

✓ Identity verified.  Smart lockout throttles attackers while trying not to lock out the genuine user.
✗ Access denied.  Correct answer: Brute-force/password-spray by locking after failed attempts while sparing the real user. Smart lockout throttles attackers while trying not to lock out the genuine user.
Authentication & access

Combined security information registration means users:

✓ Trust established.  Combined registration lets users set up MFA and SSPR methods together.
✗ Access denied.  Correct answer: Register MFA and SSPR methods in one experience. Combined registration lets users set up MFA and SSPR methods together.
Authentication & access

The recommended way to require MFA for administrators is:

✓ Privilege confirmed.  CA targeting privileged roles is the flexible, modern way to enforce admin MFA.
✗ Access denied.  Correct answer: A Conditional Access policy targeting admin roles that requires MFA. CA targeting privileged roles is the flexible, modern way to enforce admin MFA.
Authentication & access

Security defaults are best suited for:

✓ Token validated.  Security defaults give baseline enforced MFA registration for orgs without CA/P1.
✗ Access denied.  Correct answer: Smaller orgs needing baseline protection without P1. Security defaults give baseline enforced MFA registration for orgs without CA/P1.
Authentication & access

Continuous Access Evaluation (CAE) provides:

✓ Session secured.  CAE lets resources react quickly to security events instead of waiting for token expiry.
✗ Access denied.  Correct answer: Near-real-time revocation of access on critical events (disable, password reset). CAE lets resources react quickly to security events instead of waiting for token expiry.
Authentication & access

Which license is required for risk-based Conditional Access and Identity Protection?

✓ Policy enforced.  Risk-based policies and Identity Protection require Entra ID P2.
✗ Access denied.  Correct answer: Entra ID P2. Risk-based policies and Identity Protection require Entra ID P2.
Authentication & access

Entra ID Protection classifies risk into:

✓ Threat neutralized.  Identity Protection separates sign-in risk (this login) from user risk (the account).
✗ Access denied.  Correct answer: Sign-in risk and user risk. Identity Protection separates sign-in risk (this login) from user risk (the account).
Authentication & access

A grant control that requires a healthy device is:

✓ Clean scan.  CA can require the device be marked compliant (Intune) or hybrid Entra joined.
✗ Access denied.  Correct answer: Require compliant or hybrid Entra joined device. CA can require the device be marked compliant (Intune) or hybrid Entra joined.
Authentication & access

Between legacy per-user MFA and Conditional Access MFA, the recommended approach is:

✓ Root of trust intact.  CA-based MFA is contextual and preferred over blanket per-user MFA.
✗ Access denied.  Correct answer: Conditional Access (contextual and flexible). CA-based MFA is contextual and preferred over blanket per-user MFA.
Authentication & access

OATH tokens provide:

✓ Credentials accepted.  OATH TOTP tokens generate rotating one-time codes as a second factor.
✗ Access denied.  Correct answer: Time-based one-time passcodes (hardware or software). OATH TOTP tokens generate rotating one-time codes as a second factor.
Authentication & access

Which of these is NOT a valid Conditional Access condition?

✓ Access granted.  CA conditions include identity, location, device, app and risk — not arbitrary attributes like shoe size.
✗ Access denied.  Correct answer: The user's shoe size. CA conditions include identity, location, device, app and risk — not arbitrary attributes like shoe size.
Authentication & access

Requiring users to accept a policy document before access uses:

✓ Authenticated.  Terms of Use can be enforced as a Conditional Access grant control.
✗ Access denied.  Correct answer: Terms of Use as a CA grant control. Terms of Use can be enforced as a Conditional Access grant control.
Authentication & access

FIDO2 passwordless authentication is built on which standards?

✓ Identity verified.  FIDO2 uses the WebAuthn and CTAP standards for phishing-resistant sign-in.
✗ Access denied.  Correct answer: WebAuthn/CTAP. FIDO2 uses the WebAuthn and CTAP standards for phishing-resistant sign-in.
Authentication & access

To investigate why Conditional Access allowed or blocked a sign-in, you check:

✓ Trust established.  Sign-in logs show which CA policies applied; the What If tool models policy outcomes.
✗ Access denied.  Correct answer: Entra sign-in logs (Conditional Access details) / the What If tool. Sign-in logs show which CA policies applied; the What If tool models policy outcomes.
Authentication & access

A good layered defense against password spray includes:

✓ Privilege confirmed.  Combining banned-password protection, lockout, and strong auth blunts spray attacks.
✗ Access denied.  Correct answer: Password Protection + smart lockout + MFA/passwordless. Combining banned-password protection, lockout, and strong auth blunts spray attacks.
Authentication & access

The Authentication methods policy lets admins:

✓ Token validated.  It controls which authentication methods are available and to whom.
✗ Access denied.  Correct answer: Enable, disable, and scope methods like Authenticator, FIDO2, or SMS. It controls which authentication methods are available and to whom.
Authentication & access

Excluding break-glass accounts from an MFA-enforcing CA policy is important because:

✓ Session secured.  If MFA infrastructure fails, excluded (monitored) emergency accounts preserve access.
✗ Access denied.  Correct answer: It prevents an outage from locking every admin out. If MFA infrastructure fails, excluded (monitored) emergency accounts preserve access.
Workload identities

Registering an application in Entra creates:

✓ Policy enforced.  App registration yields an app object (globally) and a service principal (locally) for sign-in and permissions.
✗ Access denied.  Correct answer: An application object plus a service principal in your tenant. App registration yields an app object (globally) and a service principal (locally) for sign-in and permissions.
Workload identities

A service principal is:

✓ Threat neutralized.  The service principal represents the app instance in a tenant.
✗ Access denied.  Correct answer: The local identity of an app in a tenant used to authenticate and hold permissions. The service principal represents the app instance in a tenant.
Workload identities

The main benefit of a managed identity is:

✓ Clean scan.  Managed identities remove the need to handle secrets in code by letting Azure manage them.
✗ Access denied.  Correct answer: Azure manages the credentials so code needn't store secrets. Managed identities remove the need to handle secrets in code by letting Azure manage them.
Workload identities

A system-assigned managed identity's lifecycle is:

✓ Root of trust intact.  System-assigned identities are created with, and destroyed alongside, their resource.
✗ Access denied.  Correct answer: Tied to a single Azure resource and deleted with it. System-assigned identities are created with, and destroyed alongside, their resource.
Workload identities

A user-assigned managed identity is:

✓ Credentials accepted.  User-assigned identities exist independently and can be attached to many resources.
✗ Access denied.  Correct answer: A standalone identity reusable across multiple resources. User-assigned identities exist independently and can be attached to many resources.
Workload identities

Delegated permissions let an app act:

✓ Access granted.  Delegated permissions are exercised in the context of a signed-in user.
✗ Access denied.  Correct answer: On behalf of the signed-in user. Delegated permissions are exercised in the context of a signed-in user.
Workload identities

Application permissions let an app act:

✓ Authenticated.  Application permissions run without a user and usually need admin consent.
✗ Access denied.  Correct answer: As the application itself, typically requiring admin consent. Application permissions run without a user and usually need admin consent.
Workload identities

Admin consent is required when an app requests:

✓ Identity verified.  Sensitive/app permissions require an administrator to consent on behalf of the org.
✗ Access denied.  Correct answer: High-privilege or application-level permissions. Sensitive/app permissions require an administrator to consent on behalf of the org.
Workload identities

For production apps, the more secure credential type is:

✓ Trust established.  Certificate credentials are preferred over client secrets for production workloads.
✗ Access denied.  Correct answer: A certificate. Certificate credentials are preferred over client secrets for production workloads.
Workload identities

OpenID Connect (OIDC) primarily provides:

✓ Privilege confirmed.  OIDC adds an identity/authentication layer (ID tokens) over OAuth 2.0.
✗ Access denied.  Correct answer: Authentication (an ID token) on top of OAuth 2.0. OIDC adds an identity/authentication layer (ID tokens) over OAuth 2.0.
Workload identities

OAuth 2.0 primarily provides:

✓ Token validated.  OAuth 2.0 issues access tokens that authorize delegated access to resources.
✗ Access denied.  Correct answer: Authorization via access tokens for delegated access. OAuth 2.0 issues access tokens that authorize delegated access to resources.
Workload identities

An 'enterprise application' in Entra represents:

✓ Session secured.  Enterprise apps are the tenant's instances of applications, where you configure SSO and provisioning.
✗ Access denied.  Correct answer: A service principal instance of an app used in your tenant (SSO, provisioning). Enterprise apps are the tenant's instances of applications, where you configure SSO and provisioning.
Workload identities

To give a group access to an enterprise application, you:

✓ Policy enforced.  User/group assignment on the enterprise app controls who can access it.
✗ Access denied.  Correct answer: Assign users/groups on the enterprise app. User/group assignment on the enterprise app controls who can access it.
Workload identities

App roles are used to:

✓ Threat neutralized.  App roles let an application implement its own RBAC via role claims in the token.
✗ Access denied.  Correct answer: Define app-specific roles/claims for authorization inside the app. App roles let an application implement its own RBAC via role claims in the token.
Workload identities

Conditional Access for workload identities can restrict:

✓ Clean scan.  CA for workload identities limits where/how service principals can authenticate.
✗ Access denied.  Correct answer: Service principal sign-ins by location or risk. CA for workload identities limits where/how service principals can authenticate.
Workload identities

Consent phishing is best mitigated by:

✓ Root of trust intact.  Limiting user consent and routing risky requests to admin approval reduces illicit consent grants.
✗ Access denied.  Correct answer: Restricting user consent (e.g., verified publishers) and using an admin consent workflow. Limiting user consent and routing risky requests to admin approval reduces illicit consent grants.
Workload identities

Where do you review and revoke permissions an app was granted?

✓ Credentials accepted.  The enterprise app's Permissions blade shows and lets you revoke granted permissions.
✗ Access denied.  Correct answer: Enterprise app > Permissions (admin consent). The enterprise app's Permissions blade shows and lets you revoke granted permissions.
Workload identities

Automated user provisioning to SaaS apps in Entra uses:

✓ Access granted.  Entra app provisioning uses the SCIM standard to create/update/deprovision accounts in SaaS apps.
✗ Access denied.  Correct answer: SCIM-based provisioning. Entra app provisioning uses the SCIM standard to create/update/deprovision accounts in SaaS apps.
Workload identities

Workload identity federation lets external workloads:

✓ Authenticated.  Federation trusts tokens from an external IdP (e.g., GitHub, another cloud) so no secret is stored.
✗ Access denied.  Correct answer: Access Entra-protected resources without managing secrets by trusting external IdP tokens. Federation trusts tokens from an external IdP (e.g., GitHub, another cloud) so no secret is stored.
Workload identities

A 'verified publisher' badge on an app indicates:

✓ Identity verified.  Verified publisher status confirms the developer's identity, aiding consent decisions.
✗ Access denied.  Correct answer: Microsoft has verified the developer's identity (a trust signal). Verified publisher status confirms the developer's identity, aiding consent decisions.
Identity governance

Entitlement management packages related access into:

✓ Trust established.  Access packages bundle groups, apps, and sites so users can request a meaningful set of access.
✗ Access denied.  Correct answer: Access packages. Access packages bundle groups, apps, and sites so users can request a meaningful set of access.
Identity governance

A catalog in entitlement management is:

✓ Privilege confirmed.  Catalogs organize the resources that access packages can grant.
✗ Access denied.  Correct answer: A container of resources (groups, apps, sites) used by access packages. Catalogs organize the resources that access packages can grant.
Identity governance

Connected organizations in entitlement management enable:

✓ Token validated.  Connected organizations let defined external orgs request access via B2B governance.
✗ Access denied.  Correct answer: External partner users to request access packages under governance. Connected organizations let defined external orgs request access via B2B governance.
Identity governance

Access reviews are used to:

✓ Session secured.  Access reviews have owners attest whether access is still required.
✗ Access denied.  Correct answer: Periodically recertify that users still need their access. Access reviews have owners attest whether access is still required.
Identity governance

Access reviews can target:

✓ Policy enforced.  Reviews can cover groups, applications, and privileged role assignments.
✗ Access denied.  Correct answer: Group memberships, app assignments, and privileged roles. Reviews can cover groups, applications, and privileged role assignments.
Identity governance

Recurring access reviews primarily help with:

✓ Threat neutralized.  Recurring reviews maintain continuous compliance rather than a single cleanup.
✗ Access denied.  Correct answer: Ongoing recertification cadence for compliance. Recurring reviews maintain continuous compliance rather than a single cleanup.
Identity governance

Privileged Identity Management (PIM) provides:

✓ Clean scan.  PIM reduces standing privilege via on-demand, time-limited role activation.
✗ Access denied.  Correct answer: Just-in-time, time-bound activation of privileged roles. PIM reduces standing privilege via on-demand, time-limited role activation.
Identity governance

In PIM, an 'eligible' assignment differs from 'active' because eligible:

✓ Root of trust intact.  Eligible roles require activation (often with MFA/justification); active roles are always on.
✗ Access denied.  Correct answer: Must be activated when needed. Eligible roles require activation (often with MFA/justification); active roles are always on.
Identity governance

PIM role activation can be configured to require:

✓ Credentials accepted.  Activation controls can enforce MFA, business justification, approval, and expiry.
✗ Access denied.  Correct answer: MFA, justification, approval, and a time limit. Activation controls can enforce MFA, business justification, approval, and expiry.
Identity governance

PIM alerts help detect:

✓ Access granted.  PIM surfaces risks like too many privileged roles or unused assignments.
✗ Access denied.  Correct answer: Excessive global admins or stale standing privilege. PIM surfaces risks like too many privileged roles or unused assignments.
Identity governance

Terms of Use in governance are typically enforced through:

✓ Authenticated.  ToU acceptance is enforced as a CA grant control before access is allowed.
✗ Access denied.  Correct answer: A Conditional Access grant control. ToU acceptance is enforced as a CA grant control before access is allowed.
Identity governance

Lifecycle workflows automate:

✓ Identity verified.  Lifecycle workflows run automated tasks at join, move, and leave events.
✗ Access denied.  Correct answer: Joiner-mover-leaver tasks such as onboarding and offboarding. Lifecycle workflows run automated tasks at join, move, and leave events.
Identity governance

Separation of Duties in access packages prevents:

✓ Trust established.  SoD stops incompatible access combinations that could enable fraud or error.
✗ Access denied.  Correct answer: A user from holding conflicting packages/roles that create risk. SoD stops incompatible access combinations that could enable fraud or error.
Identity governance

Which license is required for PIM, access reviews, and entitlement management?

✓ Privilege confirmed.  These identity governance features require Entra ID P2 (or the Governance add-on).
✗ Access denied.  Correct answer: Entra ID P2. These identity governance features require Entra ID P2 (or the Governance add-on).
Identity governance

Privileged access groups allow:

✓ Token validated.  Privileged access groups extend just-in-time activation to group membership.
✗ Access denied.  Correct answer: PIM-style just-in-time membership for a group. Privileged access groups extend just-in-time activation to group membership.
Identity governance

Reviewers in an access review can be:

✓ Session secured.  Access reviews support owner review, designated reviewers, or self-attestation.
✗ Access denied.  Correct answer: Resource owners, selected users, or the users themselves (self-review). Access reviews support owner review, designated reviewers, or self-attestation.
Identity governance

'Auto-apply results' in an access review means:

✓ Policy enforced.  Auto-apply enforces the review's decisions, removing access that reviewers denied.
✗ Access denied.  Correct answer: Denied access is automatically removed when the review ends. Auto-apply enforces the review's decisions, removing access that reviewers denied.
Identity governance

Guest (external user) access is best governed with:

✓ Threat neutralized.  Reviewing guests and expiring their access keeps external access from lingering.
✗ Access denied.  Correct answer: Access reviews for guests plus access-package expiration. Reviewing guests and expiring their access keeps external access from lingering.
Identity governance

The approval workflow for an access request is configured in:

✓ Clean scan.  Access package assignment policies define requestors, approvers, and lifecycle.
✗ Access denied.  Correct answer: Access package policies. Access package assignment policies define requestors, approvers, and lifecycle.
Identity governance

The overarching goal of identity governance is to ensure:

✓ Root of trust intact.  Governance balances access with oversight and auditable compliance.
✗ Access denied.  Correct answer: The right people have the right access at the right time, with visibility and compliance. Governance balances access with oversight and auditable compliance.
Identity governance

An access package assignment can be set to automatically:

✓ Credentials accepted.  Assignments can expire, requiring renewal so access does not persist indefinitely.
✗ Access denied.  Correct answer: Expire after a set duration, prompting re-request/renewal. Assignments can expire, requiring renewal so access does not persist indefinitely.
Identity governance

Which pairing best supports audit and compliance evidence?

✓ Access granted.  Review outcomes and PIM activation history provide the audit trail auditors expect.
✗ Access denied.  Correct answer: Access reviews + PIM activation records. Review outcomes and PIM activation history provide the audit trail auditors expect.
Identity governance

To grant least-privilege admin access only when needed, combine:

✓ Authenticated.  Eligible-only roles activated via PIM achieve least privilege for administrators.
✗ Access denied.  Correct answer: Eligible PIM roles activated just-in-time. Eligible-only roles activated via PIM achieve least privilege for administrators.
Identity governance

Entitlement management is especially useful for:

✓ Identity verified.  Access packages streamline governed self-service access at scale, including for partners.
✗ Access denied.  Correct answer: Scaling access requests/approvals for many users and external partners. Access packages streamline governed self-service access at scale, including for partners.
Identity governance

A key benefit of just-in-time access over standing privilege is:

✓ Trust established.  JIT removes persistent privileged rights, shrinking what an attacker can abuse.
✗ Access denied.  Correct answer: Reduced attack surface — no always-on rights to steal or misuse. JIT removes persistent privileged rights, shrinking what an attacker can abuse.

Ready for the real thing?

You’ve been practicing the SC-300 objectives. When you’re scoring well, book the official exam and make it count.

Unofficial practice questions created by Oluma Digital for study purposes. Not affiliated with or endorsed by Microsoft. Always verify current objectives on the official exam page.

Correct Answered
Restart