Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CSCP All Questions

View all questions & answers for the CSCP exam

Exam AZ-500 topic 2 question 103 discussion

Actual exam question from APICS's CSCP
Question #: 103
Topic #: 1
[All CSCP Questions]

You have an Azure AD tenant that contains three users named User1, User2, and User3.

You configure Azure AD Password Protection as shown in the following exhibit.



The users perform the following tasks:

• User1 attempts to reset her password to C0nt0s0.
• User2 attempts to reset her password to F@brikamHQ.
• User3 attempts to reset her password to Pr0duct123.

Which password reset attempts fail?

  • A. User1 only
  • B. User2 only
  • C. User3 only
  • D. User1 and User 3 only
  • E. User1, User2, and User3
Show Suggested Answer Hide Answer
Suggested Answer: E 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Alexbz
Highly Voted 1 year, 5 months ago
Selected Answer: E
Confirmed in my lab, you'll get " Unfortunately, you can't use that password because it contains words or characters that have been blocked by your administrator. Please try again with a different password." when you select either of those password.
upvoted 13 times
...
d3N
Highly Voted 1 year, 3 months ago
Audit or not it doesn't matter in this scenario. The question is about Azure AD users where Password Protection is enabled. PP is composed by 2 lists: Microsoft and Custom Banned Password list. Evaluating proccess will be: C0nt0s0. - contoso will get 1 point as it is in Custom Banned Password list + 1 point for "." = 2 points F@brikamHQ. - fabrikam will get 1 point as it is in Custom Banned Password list + 2 points for HQ + 1 point for "." = 4 points. You need 5 for password to be accepted. Product123. - product will get 1 point as it is in Custom Banned Password list + 1 point for each character in 123 + 1 point for "." = 5 points. So I will say that the password for User3 might be accepted but as we don't have the option for "User1 and User2 only", I suppose that "123" is a combination included in Microsoft Banned Password list and if it so - this fact sucks as nobody knows what it contains, you have to test it because you won't find it in any documentation.
upvoted 5 times
...
Pamban
Most Recent 6 months, 4 weeks ago
Selected Answer: E
It is Normalization guys.. Answer is E Link https://learn.microsoft.com/en-us/entra/identity/authentication/concept-password-ban-bad#how-are-passwords-evaluated
upvoted 1 times
...
Apptech
8 months, 2 weeks ago
The custom banned password list considers common character substitution, such as "o" and "0", or "a" and "@". For that reason all three are banned. https://learn.microsoft.com/en-us/entra/identity/authentication/tutorial-configure-custom-password-protection#what-are-banned-password-lists
upvoted 2 times
...
flafernan
1 year ago
Selected Answer: E
This is because Azure AD Password Protection is designed to check passwords for patterns including sequences of prohibited characters, even when some letters are stripped for numbers or special characters. It performs a thorough check of passwords against a list of banned words and common patterns to improve password security. In this case, the passwords "C0nt0s0", "F@brikamHQ", and "Pr0duct123" contain variations of prohibited words in the custom list, such as "Contoso", "Fabrikam", and "Product", and are therefore considered insecure by Azure AD password protection. The tool is sensitive to substitutions of letters for numbers, special characters and other variations, as these practices still result in predictable and insecure passwords.
upvoted 3 times
...
Self_Study
1 year, 3 months ago
Selected Answer: E
On exam 7/8/23. Answers are correct as audit mode only.
upvoted 4 times
Self_Study
1 year, 3 months ago
Oh, in my test it was audit mode only. Read carefully what you get.
upvoted 2 times
...
...
ESAJRR
1 year, 3 months ago
Selected Answer: E
E. User1, User2, and User3
upvoted 1 times
...
Mahavijay
1 year, 4 months ago
I think all attempts will pass thr successfully as the setting enable password protection on Windows AD is set to NO but in answers there is no such option. Something is wrong here Can some one please verify?
upvoted 3 times
hellboycze
1 year, 4 months ago
Windows Server AD is related to onpremise ADDS and not Azure AD. Users1-3 are from Azure AD.
upvoted 2 times
...
...
Mahavijay
1 year, 4 months ago
Set the option for Enable password protection on Windows Server Active Directory to Yes. When this setting is set to No, all deployed Azure AD Password Protection DC agents go into a quiescent mode where all passwords are accepted as-is. No validation activities are performed, and audit events aren't generated.
upvoted 3 times
...
Ario
1 year, 4 months ago
https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-password-ban-bad-on-premises-operations
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...