exam questions

Exam CSCP All Questions

View all questions & answers for the CSCP exam

Exam SC-300 topic 2 question 7 discussion

Actual exam question from APICS's CSCP
Question #: 7
Topic #: 1
[All CSCP Questions]

You have a Microsoft 365 tenant.
The Azure Active Directory (Azure AD) tenant is configured to sync with an on-premises Active Directory domain. The domain contains the servers shown in the following table.

The domain controllers are prevented from communicating to the internet.
You implement Azure AD Password Protection on Server1 and Server2.
You deploy a new server named Server4 that runs Windows Server 2019.
You need to ensure that Azure AD Password Protection will continue to work if a single server fails.
What should you implement on Server4?

  • A. Azure AD Connect
  • B. Azure AD Application Proxy
  • C. Password Change Notification Service (PCNS)
  • D. the Azure AD Password Protection proxy service
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
jhap
Highly Voted 2 years, 9 months ago
The AzureAD Password Protection proxy service initiates an outbound connection (Port 443) to Azure to pull the banned password list. The downloaded banned password list is pulled by the agent installed on DCs. Given answer is correct.
upvoted 36 times
...
Kronos
Most Recent 5 months, 1 week ago
There is only one server functioning as the AZ AD Connect which is Server 3. What if Server 3 goes down? This is a single point of failure which I think should Server 4 be configured to be doing. So I would have A as an answer.
upvoted 3 times
...
curtmcgirt
7 months ago
if Azure AD Password Protection requires an azure ad password protection proxy service server, and we only install that proxy service on server4, won't we still have a problem "if a single server fails" and that single server is named 'server4'? from the linked article: "You need network connectivity between at least one DC in each domain of the forest and one password protection proxy server." (so it breaks if single server4 goes down?) "We recommend at least two Microsoft Entra Password Protection proxy servers per forest for redundancy, " (we only have one, server4, right? ) am i missing the part of the question that says we already have a proxy service installed on a second server?
upvoted 2 times
NotanAdmin
1 month, 2 weeks ago
As usual, the correct answer isn't necessarily the best answer as a long term solution.
upvoted 1 times
...
...
EmnCours
11 months, 3 weeks ago
Selected Answer: D
Correct Answer: D
upvoted 2 times
EmnCours
10 months, 4 weeks ago
https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-password-ban-bad-on-premises-deploy
upvoted 1 times
...
...
mali1969
1 year ago
To ensure that Azure AD Password Protection will continue to work if a single server fails, you should implement D. the Azure AD Password Protection proxy service on Server4
upvoted 1 times
...
dule27
1 year, 1 month ago
Selected Answer: D
D. the Azure AD Password Protection proxy service
upvoted 1 times
...
ShoaibPKDXB
1 year, 2 months ago
Selected Answer: D
D correct
upvoted 1 times
...
Marian2023
1 year, 4 months ago
Selected Answer: A
two Azure AD Password Protection proxy servers is enough to ensure availability - https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-password-ban-bad-on-premises-deploy "What happens if my Azure AD Connect server goes offline?" https://www.ipswitch.com/blog/provide-high-availability-for-azure-ad-connect You already have two instance of Azure AD Password Protection on two different servers. There is no need to have third instance. But you can provide HA for Azure AD connect.
upvoted 1 times
...
Aquintero
1 year, 5 months ago
Selected Answer: D
D. el servicio de proxy de protección con contraseña de Azure AD
upvoted 2 times
...
[Removed]
1 year, 7 months ago
Selected Answer: D
The answer given is a correct answer. Azure AD Password Protection proxy service.
upvoted 2 times
...
den5_pepito83
1 year, 7 months ago
ON EXAM 14/11/2022
upvoted 3 times
SangSang
1 year, 7 months ago
which one do you choose in your exam?
upvoted 1 times
...
...
Imee
1 year, 9 months ago
on the exam 09222022, i answered the same. Passed the exam, btw.
upvoted 1 times
...
Zubairr13
1 year, 11 months ago
On the exam, 7/23/2022.
upvoted 1 times
...
rachee
2 years ago
would the answer not be A. Azure AD Connect? there are 2 domain controllers both configured with Azure AD Password Protection. The question is to ensure Azure AD Password protection will continue if a "single" server fails. If one of the DCs fail, the other will still be availble. There is only 1 Azure AD Connect server; I would think you would configure a HA Azure AD connect server. Bad question, because the password list is cached on the DCs and only a single server failure.
upvoted 1 times
rachee
2 years ago
Reading the link where it says Azure AD Password Protection proxy for HA, I change the answer to D.
upvoted 3 times
...
...
sapien45
2 years ago
https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-password-ban-bad-on-premises-deploy Choose one or more servers to host the Azure AD Password Protection proxy service. The following considerations apply for the server(s): The host machine must be joined to any domain in that forest
upvoted 2 times
...
shine98
2 years ago
On the exam - June 12, 2022
upvoted 1 times
...
Nilz76
2 years, 2 months ago
This question was in the exam 28/April/2022
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago