Microsoft Identity and Access Administrator (SC-300 Korean Version) - SC-300 Korean Exam Practice Test
contoso.com이라는 Azure AD(Azure Active Directory) 테넌트가 있으며 여기에 Azure AD Identity Protection 정책이 적용됩니다.
Azure Sentinel 인스턴스를 만들고 Azure Active Directory 커넥터를 구성합니다.
Azure Sentinel이 Azure AD Identity Protection에서 발생한 위험 경고에 따라 인시던트를 생성할 수 있는지 확인해야 합니다.
가장 먼저 무엇을 해야 할까요?
Azure Sentinel 인스턴스를 만들고 Azure Active Directory 커넥터를 구성합니다.
Azure Sentinel이 Azure AD Identity Protection에서 발생한 위험 경고에 따라 인시던트를 생성할 수 있는지 확인해야 합니다.
가장 먼저 무엇을 해야 할까요?
Correct Answer: B
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
위임 요구 사항을 충족하려면 Azure AD에서 앱 등록을 구성해야 합니다.
어떻게 해야 할까요? 답변하려면 답변란에서 적절한 옵션을 선택하세요.
참고: 정답 하나당 1점입니다.

어떻게 해야 할까요? 답변하려면 답변란에서 적절한 옵션을 선택하세요.
참고: 정답 하나당 1점입니다.

Correct Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/azure/active-directory/roles/delegate-app-roles
귀하의 Azure 구독에는 다음 표에 표시된 리소스가 포함되어 있습니다.
Vault1에 대한 액세스 권한을 구성해야 합니다. 솔루션은 다음 요구 사항을 충족해야 합니다.
* User1이 Vault1에서 키를 관리하고 생성할 수 있는지 확인하십시오.
* User2가 Vault1에 저장된 인증서에 접근할 수 있는지 확인하십시오.
* 최소 권한 원칙을 적용하십시오.
각 사용자에게 어떤 역할을 부여해야 할까요? 답변란에서 적절한 옵션을 선택하세요.
참고: 정답 하나당 1점입니다.

Vault1에 대한 액세스 권한을 구성해야 합니다. 솔루션은 다음 요구 사항을 충족해야 합니다.
* User1이 Vault1에서 키를 관리하고 생성할 수 있는지 확인하십시오.
* User2가 Vault1에 저장된 인증서에 접근할 수 있는지 확인하십시오.
* 최소 권한 원칙을 적용하십시오.
각 사용자에게 어떤 역할을 부여해야 할까요? 답변란에서 적절한 옵션을 선택하세요.
참고: 정답 하나당 1점입니다.

Correct Answer:

Explanation:
User1: Key Vault Crypto Officer
User2: Key Vault Certificates Officer
As detailed in Microsoft documentation and the Exam Ref SC-300: Microsoft Identity and Access Administrator , Azure Key Vault provides role-based access control (RBAC) to manage keys, secrets, and certificates independently. The built-in roles are designed with the principle of least privilege - granting users only the permissions necessary to perform their tasks.
According to the Microsoft Learn module "Manage access to Key Vault using Azure RBAC" , the relevant built-in roles are:
* Key Vault Crypto Officer - This role allows users to manage cryptographic keys in a key vault.
Specifically, the Crypto Officer can create, import, delete, and manage keys , as well as perform cryptographic operations such as encrypt, decrypt, sign, and verify. This aligns perfectly with the requirement that User1 must manage and create keys in Vault1.
* Key Vault Certificates Officer - This role allows a user to manage and retrieve certificates within a key vault. It provides access to read, import, and delete certificates but not to manage or create keys or secrets. This satisfies the requirement that User2 must access a certificate stored in Vault1.
The Exam Ref SC-300 emphasizes that the least privilege principle requires assigning users the lowest possible role that meets their operational needs. Therefore, assigning Key Vault Crypto Officer to User1 and Key Vault Certificates Officer to User2 ensures compliance, minimal access exposure, and operational
새로운 Microsoft 36S 테넌트를 구성하여 기본 도메인 이름으로 contosso.com을 사용하도록 설정합니다.
조건부 액세스 정책을 사용하여 Microsoft 365 리소스에 대한 액세스를 제어할 수 있도록 해야 합니다.
무엇을 먼저 해야 할까요?
조건부 액세스 정책을 사용하여 Microsoft 365 리소스에 대한 액세스를 제어할 수 있도록 해야 합니다.
무엇을 먼저 해야 할까요?
Correct Answer: C
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
귀하는 User1과 User2라는 두 명의 사용자가 포함된 Microsoft 365 E5 구독을 보유하고 있습니다.
User1이 그룹에 대한 액세스 검토를 생성할 수 있고, User2가 완료된 모든 액세스 검토 기록 보고서를 볼 수 있도록 해야 합니다. 이 솔루션은 최소 권한 원칙을 따라야 합니다.
각 사용자에게 어떤 역할을 할당해야 할까요? 정답을 맞추려면 적절한 역할을 해당 사용자에게 드래그하세요. 각 역할은 한 번, 여러 번 또는 전혀 사용되지 않을 수 있습니다. 콘텐츠를 보려면 창 사이의 분할 막대를 드래그하거나 스크롤해야 할 수도 있습니다. 참고: 정답 하나당 1점입니다.

User1이 그룹에 대한 액세스 검토를 생성할 수 있고, User2가 완료된 모든 액세스 검토 기록 보고서를 볼 수 있도록 해야 합니다. 이 솔루션은 최소 권한 원칙을 따라야 합니다.
각 사용자에게 어떤 역할을 할당해야 할까요? 정답을 맞추려면 적절한 역할을 해당 사용자에게 드래그하세요. 각 역할은 한 번, 여러 번 또는 전혀 사용되지 않을 수 있습니다. 콘텐츠를 보려면 창 사이의 분할 막대를 드래그하거나 스크롤해야 할 수도 있습니다. 참고: 정답 하나당 1점입니다.

Correct Answer:

Explanation:
< User1: User administrator
User2: Reports reader
According to the Microsoft SC-300: Identity and Access Administrator Study Guide and the Exam Ref SC-
300: Microsoft Identity and Access Administrator , Azure AD includes several predefined roles that control delegated administrative permissions in the directory. Access reviews in Azure AD (part of Identity Governance ) can be created and managed by specific roles, depending on their intended task.
The User administrator role is designed for managing users and groups. It allows the user to create and manage access reviews for groups and applications within the organization. This includes the ability to start new reviews, modify existing ones, and manage reviewers. Therefore, User1 , who must create access reviews, requires this role.
On the other hand, the Reports reader role is a read-only administrative role that allows viewing of all audit logs, sign-in logs, and reports, including access review history reports . This role cannot create or modify reviews but can access and review the outcomes of completed reviews. Therefore, User2 , who needs to review historical access review reports, should be assigned the Reports reader role.
Microsoft Learn's "Manage access reviews in Azure AD Identity Governance" module and the SC-300 Learning Path confirm:
"User administrators can create and manage access reviews for users, groups, and applications. Reports readers can view the access review results and history reports but cannot create or modify them
Sub1이라는 Azure 구독이 있고, 그 안에 VM1이라는 가상 머신이 있습니다.
VM1에 대해 Microsoft Entra 로그인을 활성화하고 VM1이 Sub1의 리소스에 액세스할 수 있도록 구성해야 합니다.
VM1에 어떤 유형의 ID를 할당해야 합니까?
VM1에 대해 Microsoft Entra 로그인을 활성화하고 VM1이 Sub1의 리소스에 액세스할 수 있도록 구성해야 합니다.
VM1에 어떤 유형의 ID를 할당해야 합니까?
Correct Answer: C
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
User1이라는 사용자가 Microsoft Defender for Cloud Apps 포털에 액세스하려고 하면 오류 메시지가 나타납니다.
오류의 원인을 파악해야 합니다. 해결책은 관리 노력을 최소화해야 합니다.
무엇을 사용해야 하나요?
오류의 원인을 파악해야 합니다. 해결책은 관리 노력을 최소화해야 합니다.
무엇을 사용해야 하나요?
Correct Answer: C
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
다음 표에 표시된 사용자가 포함된 Azure AD 테넌트가 있습니다.

각 사용자의 역할 권한을 비교해야 합니다. 솔루션은 관리 노력을 최소화해야 합니다.
무엇을 사용해야 하나요?

각 사용자의 역할 권한을 비교해야 합니다. 솔루션은 관리 노력을 최소화해야 합니다.
무엇을 사용해야 하나요?
Correct Answer: C
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Microsoft 365 E5 테넌트를 보유하고 계십니다.
App1이라는 클라우드 앱을 구매하셨습니다.
Microsoft Defender for Cloud Apps를 사용하여 App1에 대한 실시간 세션 수준 모니터링을 활성화해야 합니다.
어떤 순서로 작업을 수행해야 할까요? 정답을 맞추려면 작업 목록에서 적절한 작업을 선택하여 정답 영역으로 옮긴 후, 올바른 순서대로 배열하세요.

App1이라는 클라우드 앱을 구매하셨습니다.
Microsoft Defender for Cloud Apps를 사용하여 App1에 대한 실시간 세션 수준 모니터링을 활성화해야 합니다.
어떤 순서로 작업을 수행해야 할까요? 정답을 맞추려면 작업 목록에서 적절한 작업을 선택하여 정답 영역으로 옮긴 후, 올바른 순서대로 배열하세요.

Correct Answer:

Explanation:
Register App1 in Microsoft Entra ID.
Create a conditional access policy that has session controls configured.
From Microsoft Defender for Cloud Apps, modify the Connected apps settings for App1.
From Microsoft Defender for Cloud Apps, create a session policy.
Let's break this down step by step based on Microsoft Defender for Cloud Apps (MDCA) and Microsoft Entra ID integration for enabling real-time session-level monitoring, as outlined in Microsoft Identity and Access Administrator documentation.
Understanding the Goal: Real-Time Session-Level Monitoring with Microsoft Defender for Cloud Apps:
Microsoft Defender for Cloud Apps (MDCA) is a Cloud Access Security Broker (CASB) solution that provides visibility, control, and threat protection for cloud applications.
Real-time session-level monitoring allows MDCA to inspect and control user activities within a cloud app (App1 in this case) during active sessions. This requires integration with Microsoft Entra ID and the use of Conditional Access policies to route sessions through MDCA for monitoring.
The Microsoft 365 E5 tenant includes licenses for Microsoft Entra ID P2 and Microsoft Defender for Cloud Apps, which are necessary for this functionality.
Step-by-Step Analysis of the Actions:To enable real-time session-level monitoring, the actions must be performed in a logical order that aligns with Microsoft's recommended workflow for integrating a cloud app with MDCA.
Step 1: Register App1 in Microsoft Entra ID.
Before App1 can be monitored by MDCA, it must be registered as an application in Microsoft Entra ID. This step involves adding App1 to the tenant's enterprise applications, which allows Microsoft Entra ID to manage authentication and authorization for the app.
Registering the app in Microsoft Entra ID enables single sign-on (SSO) and allows the app to be governed by Conditional Access policies, which is a prerequisite for session-level monitoring.
This is the first step because none of the other actions can proceed without App1 being recognized by Microsoft Entra ID.
Step 2: Create a conditional access policy that has session controls configured.
Microsoft Defender for Cloud Apps integrates with Microsoft Entra ID Conditional Access to enforce session- level monitoring. A Conditional Access policy must be created to target App1 and include session controls that route user sessions through MDCA.
In the Conditional Access policy, under " Session " controls, you enable the option " Use Conditional Access App Control, " which integrates with MDCA. This allows MDCA to monitor and control the session in real time.
This step must come after registering the app in Microsoft Entra ID because the Conditional Access policy needs to target an existing app. It must also precede the MDCA-specific steps because the session control integration sets up the connection between Microsoft Entra ID and MDCA.
Step 3: From Microsoft Defender for Cloud Apps, modify the Connected apps settings for App1.
After the Conditional Access policy routes sessions to MDCA, you need to configure App1within MDCA by modifying its Connected apps settings. This step involves ensuring that App1 is properly connected to MDCA, which may include configuring API connectors or verifying that MDCA can monitor the app's activities.
This step is necessary to ensure MDCA has the necessary permissions and configurations to monitor App1. It comes after the Conditional Access policy because the policy enables the integration, and now MDCA needs to be set up to handle the app.
Step 4: From Microsoft Defender for Cloud Apps, create a session policy.
Finally, you create a session policy in MDCA to define the real-time monitoring and control rules for App1. A session policy in MDCA allows you to monitor user activities (e.g., file downloads, data sharing) and apply actions (e.g., block, notify) based on predefined conditions.
This step is the last because it relies on the previous steps: the app must be registered, the Conditional Access policy must route sessions to MDCA, and the Connected apps settings must be configured for MDCA to recognize App1. Only then can you define session policies to enforce real-time monitoring.
Why This Order?
The order ensures a logical flow:
Registering the app in Microsoft Entra ID establishes the app's identity in the tenant.
The Conditional Access policy enables the integration with MDCA by routing sessions through it.
Modifying the Connected apps settings in MDCA ensures the app is properly set up for monitoring.
Creating a session policy in MDCA defines the specific monitoring and control rules for real-time session- level monitoring.
Deviating from this order would result in errors. For example, creating a session policy in MDCA before registering the app in Microsoft Entra ID would fail because MDCA wouldn't recognize the app.
Additional Considerations:
The Microsoft 365 E5 license includes Microsoft Entra ID P2 and Microsoft Defender for Cloud Apps, so no additional licensing is required for this scenario.
If App1 is not a supported app for MDCA's app connectors, additional steps (e.g., using a custom app connector) might be needed, but the question implies App1 can be monitored with the standard process.
Session policies in MDCA can include actions like blocking downloads or requiring step-up authentication, which are applied in real time during the user's session.
Conclusion:The correct order to enable real-time session-level monitoring of App1 using Microsoft Defender for Cloud Apps is:
Register App1 in Microsoft Entra ID.
Create a conditional access policy that has session controls configured.
From Microsoft Defender for Cloud Apps, modify the Connected apps settings for App1.
From Microsoft Defender for Cloud Apps, create a session policy.
References:
Microsoft Defender for Cloud Apps documentation: " Session control with Microsoft Defender for Cloud Apps " (Microsoft Learn:https://learn.microsoft.com/en-us/defender-cloud-apps/session-policy) Microsoft Entra ID Conditional Access documentation: " Session controls in Conditional Access " (Microsoft Learn:https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-conditional-access-session) Microsoft Identity and Access Administrator (SC-300) exam study guide, which covers integrating Microsoft Defender for Cloud Apps with Microsoft Entra ID for session-level monitoring.
다중 요소 인증(MFA)이 활성화된 Azure Active Directory(Azure AD) 테넌트가 있습니다.
계정 잠금 설정은 다음 그림과 같이 구성됩니다.

아래 그림에 제시된 정보를 바탕으로 각 문장을 완성하는 답을 드롭다운 메뉴에서 선택하세요.
참고: 정답 하나당 1점입니다.

계정 잠금 설정은 다음 그림과 같이 구성됩니다.

아래 그림에 제시된 정보를 바탕으로 각 문장을 완성하는 답을 드롭다운 메뉴에서 선택하세요.
참고: 정답 하나당 1점입니다.

Correct Answer:

Explanation:
According to the Microsoft SC-300: Identity and Access Administrator Official Study Guide and Microsoft Learn module "Configure Azure AD Multi-Factor Authentication settings", the Account Lockout settings in Azure AD MFA define how the service reacts to repeated failed MFA verification attempts.
From the exhibit:
* Number of MFA denials to trigger account lockout: 3
* Minutes until account lockout counter is reset: 60
* Minutes until account is automatically unblocked: 30
1. Lockout trigger type:
The lockout applies to MFA denials - specifically, failed verification attempts using methods such as the Microsoft Authenticator app (OTP code) or phone call verification. It does not apply to incorrect usernames or passwords, as those are handled by Azure AD sign-in risk policies.
The official Microsoft documentation states:
"Account lockout in Azure AD Multi-Factor Authentication occurs after the configured number of denied MFA verification attempts. This setting applies to users entering an incorrect PIN or app verification code." Therefore, after three incorrect Microsoft Authenticator app codes, the account is temporarily locked.
2. Lockout duration:
The setting "Minutes until account is automatically unblocked: 30" means that once an account is locked due to too many failed MFA attempts, it will automatically unlock after 30 minutes without administrator intervention.
This aligns with Microsoft's MFA service behavior:
"When the account lockout threshold is reached, the account remains locked for the configured duration before being automatically unlocked."
# Final Correct Answers:
* Wrong input type causing lockout: Microsoft Authenticator app code
* Unlock duration: 30 minutes