exam questions

Exam SC-300 All Questions

View all questions & answers for the SC-300 exam

Exam SC-300 topic 2 question 71 discussion

Actual exam question from Microsoft's SC-300
Question #: 71
Topic #: 2
[All SC-300 Questions]

You have an Azure AD tenant that has multi-factor authentication (MFA) enforced and self-service password reset (SSPR) enabled.

You enable combined registration in interrupt mode.

You create a new user named User1.

Which two authentication methods can User1 use to complete the combined registration process? Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point.

  • A. a FIDO2 security key
  • B. a hardware token
  • C. a one-time passcode email
  • D. Windows Hello for Business
  • E. the Microsoft Authenticator app
Show Suggested Answer Hide Answer
Suggested Answer: CE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
penatuna
Highly Voted 1 year, 5 months ago
Selected Answer: CE
A. FIDO2 security keys, can only be added in Manage mode. Question says "You enable combined registration in interrupt mode." B. Hardware token – You cannot register with hardware token. C. Email is supported. D. Windows Hello for Business is not supported. E. Microsoft Authenticator app is supported.
upvoted 13 times
Alcpt
10 months, 3 weeks ago
Passkey (FIDO2), can only be added in Manage mode on https://aka.ms/mysecurityinfo. A is not an option in interrupt mode
upvoted 1 times
...
...
Nyamnyam
Highly Voted 1 year, 5 months ago
AE is NOT correct. CE is the only possibility. Why? A. FIDO2 security keys, can only be added in Manage mode B. Hardware tokens cannot be used in combined registration. D. Windows Hello for business cannot be used in combined registration. In fact, this is a passwordless authentication platform (with PIN and biometric methods) Read the table and the Notes sections here: https://learn.microsoft.com/en-us/entra/identity/authentication/concept-registration-mfa-sspr-combined#methods-available-in-combined-registration
upvoted 6 times
...
Labelfree
Most Recent 5 months, 1 week ago
Selected Answer: CE
E. is given, C. is only other option since a OTP (One Time Passcode) is generated from Email. FIDO2 is supported for Combined Registration Mode, but not for Interrupt mode. Reference this doc about 2/5 to 1/2 way down: https://learn.microsoft.com/en-us/entra/identity/authentication/concept-registration-mfa-sspr-combined Reference
upvoted 2 times
...
methosgr
8 months, 3 weeks ago
Selected Answer: AE
Methods available in combined registration https://learn.microsoft.com/en-us/entra/identity/authentication/concept-registration-mfa-sspr-combined
upvoted 1 times
Labelfree
5 months, 1 week ago
Correct article, but wrong answer. If you scroll down a little further of where you found that answer (you are looking at combined, but not interrupt specifically), then you'll see this comment for interrupt - When the user chooses to register, two methods are required: The user is shown Microsoft Authenticator app and phone by default. The user can choose to register email instead of Authenticator app or phone. So, aside from the given E/Authenticator app, has to be C. OTP (generated from email)
upvoted 2 times
...
...
a6792d4
11 months, 2 weeks ago
https://learn.microsoft.com/en-us/entra/identity/authentication/tutorial-enable-sspr Choose the Methods available to users that your organization wants to allow. For this tutorial, check the boxes to enable the following methods: Mobile app notification Mobile app code Email Mobile phone
upvoted 1 times
...
curtmcgirt
1 year, 4 months ago
redundant comment, just voting to correct the distribution: Read the table and the Notes sections here: https://learn.microsoft.com/en-us/entra/identity/authentication/concept-registration-mfa-sspr-combined#methods-available-in-combined-registration
upvoted 2 times
...
JCkD4Ni3L
1 year, 6 months ago
Selected Answer: AE
As per Microsoft's documentation, A and E in the available choices. https://learn.microsoft.com/en-us/entra/identity/authentication/concept-registration-mfa-sspr-combined#methods-available-in-combined-registration
upvoted 1 times
JCkD4Ni3L
1 year, 6 months ago
I stand corrected, A is not valid, as stated by others, FIDO2 security keys, can only be added in Manage mode on https://aka.ms/mysecurityinfo. So correct Answer would be C & E.
upvoted 2 times
...
...
syougun200x
1 year, 6 months ago
I think the answer C & E is correct. On the link page, it goes like this. FIDO2 security keys, can only be added in Manage mode on https://aka.ms/mysecurityinfo. https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-registration-mfa-sspr-combined Meaning I think through the combined registration process the user cannot choose FIDO2 but only on their own 365 security page.
upvoted 4 times
...
cgonIT
1 year, 6 months ago
As per the official documentation: https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-registration-mfa-sspr-combined - Hardware token is not an option to register. - a one-time passcode email is not even listed. - Windows Hello for Bussines is not even listed. Correct responses: - A. a FIDO2 security key - E. the Microsoft Authenticator app
upvoted 3 times
curtmcgirt
1 year, 4 months ago
as per the link you provided: the exact words "one time passcode email" are not listed, but "email" definitely is. and right below the table that says "FIDO2 security keys: YES*" (note the asterisk) there is a big purple box that says "*FIDO2 security keys can only be added in Manage mode on https://aka.ms/mysecurityinfo." CE
upvoted 1 times
...
JimboJones99
1 year, 6 months ago
Agree with this based off the documentation
upvoted 1 times
...
...
666Forest
1 year, 6 months ago
Selected Answer: AE
A. a FIDO2 security key: Users can use a FIDO2 security key, which is a hardware device that provides strong authentication, typically in the form of a USB key or a biometric-enabled key. E. the Microsoft Authenticator app: Users can use the Microsoft Authenticator app, which supports multi-factor authentication (MFA) and can generate one-time passcodes or be used for push notifications for MFA approval. So, User1 can use these two methods to complete the combined registration process.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago