exam questions

Exam SC-300 All Questions

View all questions & answers for the SC-300 exam

Exam SC-300 topic 2 question 5 discussion

Actual exam question from Microsoft's SC-300
Question #: 5
Topic #: 2
[All SC-300 Questions]

You have a Microsoft 365 tenant.
All users have computers that run Windows 10. Most computers are company-owned and joined to Azure Active Directory (Azure AD). Some computers are user- owned and are only registered in Azure AD.
You need to prevent users who connect to Microsoft SharePoint Online on their user-owned computer from downloading or syncing files. Other users must NOT be restricted.
Which policy type should you create?

  • A. a Microsoft Cloud App Security activity policy that has Microsoft Office 365 governance actions configured
  • B. an Azure AD conditional access policy that has session controls configured
  • C. an Azure AD conditional access policy that has client apps conditions configured
  • D. a Microsoft Cloud App Security app discovery policy that has governance actions configured
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Val_0
Highly Voted 3 years, 11 months ago
B is the correct answer imo - https://docs.microsoft.com/en-us/sharepoint/control-access-from-unmanaged-devices - You need to use "Use app enforced restrictions" from the "Session" control of the CA
upvoted 38 times
melatocaroca
3 years, 9 months ago
Most computers are company-owned and joined to Azure Active Directory (Azure AD). You need to prevent users who connect to Microsoft SharePoint Online on their user-owned computer https://docs.microsoft.com/en-us/mem/intune/protect/conditional-access-intune-common-ways-use https://docs.microsoft.com/en-us/mem/intune/protect/app-based-conditional-access-intune-create
upvoted 1 times
melatocaroca
3 years, 9 months ago
IMHO After review this on a real tenant first you need to select SPO in Cloud apps or actions that action will enable in session settings App enforced restrictions might require additional admin configurations within the cloud apps. The restrictions will only take effect for new sessions. So because first action is configure the application that will be affected by sessions settings, choosing C, instead B can the option to select as demoxyl told 2 months, 1 week ago C is the answer
upvoted 5 times
...
...
...
Beitran
Highly Voted 3 years, 11 months ago
So, first step is to create a Conditional Access Policy with Session configured in Azure AD, then create a Session Policy in Cloud App Security: https://techcommunity.microsoft.com/t5/itops-talk-blog/step-by-step-blocking-data-downloads-via-microsoft-cloud-app/ba-p/326357 So I'd say that since the first step is the Azure one the correct answer is B, since none of the other options for Cloud App Security make sense.
upvoted 14 times
Azurefox79
3 years, 10 months ago
Nope, for this question you need to first configured settings in SP and EXO admin centers which creates CA policies that enforce these. I just had a client project with this. Also, to do session controls for an app, first register it in AzAd, 2nd connect the app in CAS, 3rd create a session policy in CAS and lastly create a CA policy referencing session control policy in step 3.
upvoted 5 times
...
JerryGolais
3 years, 11 months ago
This is right. Link explains everything.
upvoted 2 times
...
...
jim85
Most Recent 10 months, 1 week ago
Selected Answer: C
C - https://learn.microsoft.com/en-us/sharepoint/control-access-from-unmanaged-devices 1) you select what apps (as answer C says) 2) select Conditions > Filter devices
upvoted 2 times
...
RemmyT
10 months, 4 weeks ago
Selected Answer: B
Answer: B Target resources Cloud apps -> Select apps Office 365 SharePoint Online Session Use Conditional Access App Control Block downloads (Preview) Grant access Require Microsoft Entra hybrid joined device
upvoted 4 times
...
Siraf
1 year, 4 months ago
Correct Answer is B: Within a Conditional Access policy, an administrator can make use of session controls to enable limited experiences within specific cloud applications. Organizations can use this control to require Microsoft Entra ID to pass device information to the selected cloud apps. The device information allows cloud apps to know if a connection is from a compliant or domain-joined device and update the session experience. This control only supports Office 365, SharePoint Online, and Exchange Online as selected cloud apps. When selected, the cloud app uses the device information to provide users with a limited or full experience. Limited when the device isn't managed or compliant and full when the device is managed and compliant. https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-conditional-access-session
upvoted 1 times
...
haazybanj
1 year, 5 months ago
Selected Answer: B
The correct answer is B. an Azure AD conditional access policy that has session controls configured. Azure AD conditional access policies allow you to control who can access your Azure AD resources and under what conditions. You can use conditional access policies to block users from downloading or syncing files from SharePoint Online on their user-owned computers.
upvoted 3 times
...
haazybanj
1 year, 5 months ago
Selected Answer: B
The answer is: B. an Azure AD conditional access policy that has session controls configured Azure AD Conditional Access policies allow you to control user access to cloud apps based on conditions such as user identity, device state, and location. In this case, you can create a Conditional Access policy that prevents users from downloading or syncing files from SharePoint Online when they are using a user-owned device.
upvoted 2 times
...
ACSC
1 year, 7 months ago
Selected Answer: B
You need to use "Use app enforced restrictions" from the "Session" control of the CA and then "Use conditional access App Control". After that configure Conditional Access App Control app.
upvoted 3 times
...
EmnCours
1 year, 8 months ago
Selected Answer: B
Correct Answer is: B
upvoted 3 times
...
sehlohomoletsane
1 year, 8 months ago
https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/concept-conditional-access-conditions
upvoted 1 times
...
hellawaits111
1 year, 9 months ago
Selected Answer: B
B is the answer https://learn.microsoft.com/en-us/sharepoint/control-access-from-unmanaged-devices
upvoted 2 times
...
dule27
1 year, 9 months ago
Selected Answer: C
Correction C. an Azure AD conditional access policy that has client apps conditions configured
upvoted 1 times
...
mali1969
1 year, 10 months ago
Based on this information, the policy type that should be created is C. an Azure AD conditional access policy that has client apps conditions configured. This policy type allows you to control access to cloud apps based on specific conditions such as device platform and client app
upvoted 2 times
mali1969
1 year, 8 months ago
Correct answer is an Azure AD conditional access policy that has session controls configured to prevent users who connect to SharePoint Online on their user-owned computer from downloading or syncing files. Session controls allow you to restrict access to content based on device state, such as whether it is company-owned or user-owned.
upvoted 2 times
...
...
venumurki
1 year, 10 months ago
C is the answer: https://learn.microsoft.com/en-us/defender-cloud-apps/proxy-intro-aad
upvoted 1 times
...
dule27
1 year, 10 months ago
Selected Answer: B
B. an Azure AD conditional access policy that has session controls configured
upvoted 2 times
...
ShoaibPKDXB
1 year, 11 months ago
Selected Answer: B
B correct
upvoted 2 times
...
jojoseph
2 years, 3 months ago
Selected Answer: B
B or C could be right. But I am inclined to B
upvoted 2 times
Holii
1 year, 10 months ago
You need to use session control because you need access to 'use app-enforced restrictions'. Only via the SharePoint admin center can you edit that ability to sync files to OneDrive and SharePoint. Settings -> Sync -> Allow syncing only on computer joined to specific domains Questions asks to "Restrict download and sync"
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago