Microsoft Identity and Access Administrator (SC-300 Korean Version) - SC-300 Korean Exam Practice Test
귀하는 다음 표에 표시된 사용자가 포함된 Microsoft Entra 테넌트를 보유하고 있습니다.

사용자 관리자 역할에 다음 할당을 추가합니다.
* 범위 유형: 디렉터리
* 선정된 구성원: 그룹1
* 과제 유형: 활성
* 과제 제출 시작일: 2022년 8월 15일
과제 종료일: 2022년 12월 15일
Exchange 관리자 역할에 다음 할당을 추가합니다.
* 범위 유형: 디렉터리
* 선정된 멤버: 그룹2
* 과제 유형: 적격
* 과제 제출 시작일: 2022년 10월 15일
* 과제 종료일: 2023년 1월 15일
다음 각 문장에 대해, 문장이 사실이면 '예'를 선택하고, 그렇지 않으면 '아니요'를 선택하십시오.
참고: 정답 하나당 1점입니다.


사용자 관리자 역할에 다음 할당을 추가합니다.
* 범위 유형: 디렉터리
* 선정된 구성원: 그룹1
* 과제 유형: 활성
* 과제 제출 시작일: 2022년 8월 15일
과제 종료일: 2022년 12월 15일
Exchange 관리자 역할에 다음 할당을 추가합니다.
* 범위 유형: 디렉터리
* 선정된 멤버: 그룹2
* 과제 유형: 적격
* 과제 제출 시작일: 2022년 10월 15일
* 과제 종료일: 2023년 1월 15일
다음 각 문장에 대해, 문장이 사실이면 '예'를 선택하고, 그렇지 않으면 '아니요'를 선택하십시오.
참고: 정답 하나당 1점입니다.

Correct Answer:

Explanation:
< On November 15, 2022, Admin1 can reset the password of Admin2. = Yes
On October 15, 2022, Admin2 signs in and can administer Exchange Online. = No On September 1, 2022, Admin3 can reset the password of Admin1. = Yes
\
In SC-300 materials, Microsoft Entra Privileged Identity Management (PIM) distinguishes Active and Eligible assignments. An Active assignment "grants the role immediately until it expires," whereas an Eligible assignment "does not grant permissions until the user activates the role for a limited time." Group-based role assignment applies the role to all members of the group within the configured start/end dates. The User Administrator role is documented as being able to "manage users and groups, including reset passwords for most admin roles except highly privileged roles." Applying these rules to the scenario:
* User Administrator # Group1 (Active 8/15-12/15) : Admin1 and Admin3 are members of Group1, so both hold User Administrator actively on 9/1 and 11/15. Therefore, Admin1 can reset Admin2's password on 11/15 , and Admin3 can reset Admin1's password on 9/1 .
* Exchange Administrator # Group2 (Eligible 10/15-1/15) : Admin2 (member of Group2) is only eligible starting 10/15 ; eligibility alone does not grant Exchange admin permissions until he activates the role (which typically requires justification/MFA and sets a time-bound active window). Thus, simply signing in on 10/15 does not let Admin2 administer Exchange Online.
These behaviors are emphasized in SC-300 guidance on PIM: active assignment = immediate permissions ; eligible assignment = must activate before permissions apply ; group assignment = role applies to all group members for the assignment window .
사용자 User1과 Vault1이라는 Azure Key Vault가 포함된 Azure 구독이 있습니다.
User1이 Vault1에 저장된 인증서, 키 및 비밀 정보의 메타데이터를 읽을 수 있도록 해야 합니다. 이 솔루션은 최소 권한 원칙을 준수해야 합니다.
User1에게 어떤 역할을 부여해야 할까요?
User1이 Vault1에 저장된 인증서, 키 및 비밀 정보의 메타데이터를 읽을 수 있도록 해야 합니다. 이 솔루션은 최소 권한 원칙을 준수해야 합니다.
User1에게 어떤 역할을 부여해야 할까요?
Correct Answer: D
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
Microsoft 365 테넌트가 있습니다.
모든 사용자는 Microsoft 365 서비스에 액세스할 때 다단계 인증(MFA)을 위해 Microsoft Authenticator 앱을 사용해야 합니다.
일부 사용자는 로그인 요청을 시작하지 않았는데도 Microsoft Authenticator 앱에서 MFA(다단계 인증) 메시지가 표시되었다고 보고했습니다.
사용자가 본인이 시작하지 않은 MFA 요청을 신고할 경우 자동으로 해당 사용자를 차단해야 합니다.
해결 방법: Azure 포털에서 다단계 인증(MFA)에 대한 사용자 차단/차단 해제 설정을 구성합니다.
이것이 목표를 달성합니까?
모든 사용자는 Microsoft 365 서비스에 액세스할 때 다단계 인증(MFA)을 위해 Microsoft Authenticator 앱을 사용해야 합니다.
일부 사용자는 로그인 요청을 시작하지 않았는데도 Microsoft Authenticator 앱에서 MFA(다단계 인증) 메시지가 표시되었다고 보고했습니다.
사용자가 본인이 시작하지 않은 MFA 요청을 신고할 경우 자동으로 해당 사용자를 차단해야 합니다.
해결 방법: Azure 포털에서 다단계 인증(MFA)에 대한 사용자 차단/차단 해제 설정을 구성합니다.
이것이 목표를 달성합니까?
Correct Answer: B
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
귀사는 Microsoft 365 ES 구독 2개와 App이라는 이름의 앱 1개를 새로 구매했습니다.
App1에 대한 Microsoft Defender for Cloud Apps 액세스 정책을 생성해야 합니다.
무엇을 먼저 해야 할까요? (microsoft.com의 Microsoft ID 및 액세스 관리자 정보를 바탕으로 정답을 선택하세요.)
App1에 대한 Microsoft Defender for Cloud Apps 액세스 정책을 생성해야 합니다.
무엇을 먼저 해야 할까요? (microsoft.com의 Microsoft ID 및 액세스 관리자 정보를 바탕으로 정답을 선택하세요.)
Correct Answer: A
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
참고: 이 질문은 동일한 시나리오를 제시하는 일련의 질문 중 일부입니다. 이 시리즈의 각 질문에는 명시된 목표를 충족할 수 있는 고유한 솔루션이 포함되어 있습니다. 일부 질문 세트에는 두 개 이상의 정답이 있을 수 있고, 다른 세트에는 정답이 없을 수 있습니다.
이 섹션의 질문에 답한 후에는 다시 돌아갈 수 없습니다. 따라서 이러한 질문은 검토 화면에 나타나지 않습니다.
Azure Active Directory(Azure AD) 테넌트와 동기화되는 Active Directory 포리스트가 있습니다.
Active Directory에서 사용자 계정이 비활성화된 경우에도 비활성화된 사용자는 최대 30분 동안 Azure AD에 인증할 수 있다는 것을 알게 되었습니다.
Active Directory에서 사용자 계정이 비활성화되면 해당 사용자 계정이 Azure AD에 인증되지 않도록 즉시 설정해야 합니다.
해결 방법: Azure AD 암호 보호를 구성합니다.
이것이 목표를 달성하는가?
이 섹션의 질문에 답한 후에는 다시 돌아갈 수 없습니다. 따라서 이러한 질문은 검토 화면에 나타나지 않습니다.
Azure Active Directory(Azure AD) 테넌트와 동기화되는 Active Directory 포리스트가 있습니다.
Active Directory에서 사용자 계정이 비활성화된 경우에도 비활성화된 사용자는 최대 30분 동안 Azure AD에 인증할 수 있다는 것을 알게 되었습니다.
Active Directory에서 사용자 계정이 비활성화되면 해당 사용자 계정이 Azure AD에 인증되지 않도록 즉시 설정해야 합니다.
해결 방법: Azure AD 암호 보호를 구성합니다.
이것이 목표를 달성하는가?
Correct Answer: A
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
귀하의 Azure 구독에는 다음 표에 표시된 리소스가 포함되어 있습니다.

어떤 리소스에 대해 접근 권한 검토를 생성할 수 있나요?

어떤 리소스에 대해 접근 권한 검토를 생성할 수 있나요?
Correct Answer: B
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
다음 표에 표시된 사용자가 포함된 Azure AD 테넌트가 있습니다.

각 사용자의 역할 권한을 비교해야 합니다. 솔루션은 관리 노력을 최소화해야 합니다.
무엇을 사용해야 하나요?

각 사용자의 역할 권한을 비교해야 합니다. 솔루션은 관리 노력을 최소화해야 합니다.
무엇을 사용해야 하나요?
Correct Answer: D
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
contoso.com이라는 Azure AD 테넌트가 있으며, 해당 테넌트에는 다음 표에 표시된 리소스가 포함되어 있습니다.
Admin 1이라는 이름의 사용자를 생성합니다.

관리자가 contoso.com에 대한 보안 기본 설정을 활성화할 수 있도록 해야 합니다.
무엇을 먼저 해야 할까요?
Admin 1이라는 이름의 사용자를 생성합니다.

관리자가 contoso.com에 대한 보안 기본 설정을 활성화할 수 있도록 해야 합니다.
무엇을 먼저 해야 할까요?
Correct Answer: B
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
네트워크에는 Microsoft Enterprise 테넌트와 동기화되는 온프레미스 Active Directory 도메인 서비스(AD DS) 도메인이 있습니다. 사용자 인증이 항상 AD DS 도메인에 대한 암호 유효성 검사를 통해 이루어지도록 해야 합니다. 어떤 설정을 구성하고 어떤 도구를 사용해야 할까요? 정답을 선택하려면 답변 영역에서 적절한 옵션을 선택하십시오. 참고: 각 선택 항목은 1점입니다.


Correct Answer:

Explanation:

According to the Microsoft SC-300: Identity and Access Administrator Study Guide and Microsoft Learn module "Implement and Manage Microsoft Entra Connect" , when organizations need authentication to always validate user passwords directly against the on-premises Active Directory Domain Services (AD DS) environment, the correct configuration is Pass-through Authentication (PTA).
Here's why:
* Pass-through Authentication (PTA) ensures that when a user attempts to sign in to Microsoft Entra ID (formerly Azure AD), their credentials are not validated in the cloud. Instead, the authentication request is securely passed to an on-premises authentication agent, which validates the credentials against the on- premises AD DS domain controller in real time.
* This configuration provides an immediate reflection of on-premises account states - if an account is disabled, locked, or the password is changed, those changes take effect instantly for cloud authentication as well.
To configure PTA, you must use Microsoft Entra Connect, which is the hybrid identity synchronization tool that links on-premises directories to Microsoft Entra ID. During Entra Connect setup, administrators can choose between Password Hash Synchronization, Pass-through Authentication, or Federation as the sign-in method.
Microsoft documentation explicitly states:
"Pass-through Authentication allows users to sign in to both on-premises and cloud-based applications using the same passwords. Authentication occurs against your on-premises Active Directory." Therefore, to meet the requirement that authentication always validates passwords against the on-premises AD DS domain:
귀하는 Microsoft 365 E5 구독을 보유하고 있습니다.
Gateway1이라는 이름의 타사 웹 게이트웨이를 배포합니다.
Gateway1을 Microsoft Defender for Cloud Apps와 통합해야 합니다. 솔루션은 다음 요구 사항을 충족해야 합니다.
데이터가 Defender for Cloud Apps로 자동으로 전송되도록 하십시오.
행정적 노력을 최소화하십시오.
무엇을 먼저 해야 할까요?
Gateway1이라는 이름의 타사 웹 게이트웨이를 배포합니다.
Gateway1을 Microsoft Defender for Cloud Apps와 통합해야 합니다. 솔루션은 다음 요구 사항을 충족해야 합니다.
데이터가 Defender for Cloud Apps로 자동으로 전송되도록 하십시오.
행정적 노력을 최소화하십시오.
무엇을 먼저 해야 할까요?
Correct Answer: A
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).