SC-300 Exam QuestionsBrowse all questions from this exam

SC-300 Exam - Question 310


Case Study -

Overview -

ADatum Corporation is a consulting company in Montreal.

ADatum recently acquired a Vancouver-based company named Litware, Inc.

Existing Environment. ADatum Environment

The on-premises network of ADatum contains an Active Directory Domain Services (AD DS) forest named adatum.com.

ADatum has a Microsoft 365 E5 subscription. The subscription contains a verified domain that syncs with the adatum.com AD DS domain by using Azure AD Connect.

ADatum has an Azure Active Directory (Azure AD) tenant named adatum.com. The tenant has Security defaults disabled.

The tenant contains the users shown in the following table.

The tenant contains the groups shown in the following table.

Existing Environment. Litware Environment

Litware has an AD DS forest named litware.com

Existing Environment. Problem Statements

ADatum identifies the following issues:

• Multiple users in the sales department have up to five devices. The sales department users report that sometimes they must contact the support department to join their devices to the Azure AD tenant because they have reached their device limit.

• A recent security incident reveals that several users leaked their credentials, a suspicious browser was used for a sign-in, and resources were accessed from an anonymous IP address.

• When you attempt to assign the Device Administrators role to IT_Group1, the group does NOT appear in the selection list.

• Anyone in the organization can invite guest users, including other guests and non-administrators.

• The helpdesk spends too much time resetting user passwords.

• Users currently use only passwords for authentication.

Requirements. Planned Changes -

ADatum plans to implement the following changes:

• Configure self-service password reset (SSPR).

• Configure multi-factor authentication (MFA) for all users.

• Configure an access review for an access package named Package1.

• Require admin approval for application access to organizational data.

• Sync the AD DS users and groups of litware.com with the Azure AD tenant.

• Ensure that only users that are assigned specific admin roles can invite guest users.

• Increase the maximum number of devices that can be joined or registered to Azure AD to 10.

Requirements. Technical Requirements

ADatum identifies the following technical requirements:

• Users assigned the User administrator role must be able to request permission to use the role when needed for up to one year.

• Users must be prompted to register for MFA and provided with an option to bypass the registration for a grace period.

• Users must provide one authentication method to reset their password by using SSPR. Available methods must include:

- Email

- Phone

- Security questions

- The Microsoft Authenticator app

• Trust relationships must NOT be established between the adatum.com and litware.com AD DS domains.

• The principle of least privilege must be used.

You need to modify the settings of the User administrator role to meet the technical requirements.

Which two actions should you perform for the role? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Show Answer
Correct Answer: CD

To meet the technical requirements for the User administrator role, you should take two actions. First, you need to modify the 'Expire eligible assignments after' setting to ensure that users can request permission to use the role for up to one year. This setting allows you to define an expiration period during which eligible assignments can be activated. Second, you should set all assignments to 'Eligible,' which ensures that users with the User administrator role can request activation as needed, rather than having the role constantly active. This approach aligns with the principle of least privilege, granting elevated permissions only when required.

Discussion

6 comments
Sign in to comment
TanidanindoOptions: CD
Jul 26, 2023

correct

ServerBrainOptions: CD
Sep 1, 2023

no debate on this answer

Logitech
Sep 28, 2023

Where can i find the "Expire eligible assignments after setting." ?

cgonITOptions: CD
Oct 13, 2023

C. Modify the Expire eligible assignments after setting. "Users assigned the User administrator role must be able to request permission to use the role when needed " It's the only way to "be able to request permission", making it Eleible. If it were "active", there won't be able to "ask for" anything. D. Set all assignments to Eligible. " up to one year." So there is needed to set an expiration date to be elegible and not active all time.

2c53bdd
Sep 27, 2024

Users assigned the User administrator role must be able to request permission to use the role hence A should be included

Obi_Wan_JacobyOptions: CD
May 5, 2025

C. Modify the Expire eligible assignments after setting. This allows you to set the maximum duration for which a user can be eligible to activate the role. Since the requirement is "up to one year," you would configure this setting accordingly. D. Set all assignments to Eligible. This ensures that users do not have permanent access to the role but can activate it when needed, aligning with the principle of least privilege.