exam questions

Exam SC-300 All Questions

View all questions & answers for the SC-300 exam

Exam SC-300 topic 2 question 14 discussion

Actual exam question from Microsoft's SC-300
Question #: 14
Topic #: 2
[All SC-300 Questions]

HOTSPOT -
You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table.

You plan to implement Azure AD Identity Protection.
Which users can configure the user risk policy, and which users can view the risky users report? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/overview-identity-protection

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
oberte007
Highly Voted 2 years, 8 months ago
Given answers are not right. Users who can set up policies have the security or global admin role. According to given Link https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/overview-identity-protection, security operator can view all Identity Protection reports and Overview blade, Dismiss user risk, confirm safe sign-in and confirm compromise but can't Configure or change policies, and Configure alerts So the first box should be User3 only because he is security admin and the second one User3 and User4.
upvoted 60 times
JCkD4Ni3L
6 months, 1 week ago
Answers are right, it's already User3 for box 1 and User3 and User4 for Box 2... you must have seen an older version of this questions... (2 years ago I guess)
upvoted 8 times
...
jack987
1 year, 4 months ago
I agree with oberte007.
upvoted 1 times
...
DaBummer
2 years, 7 months ago
Currently, the Security Operator role cannot access the Risky sign-ins report. https://docs.microsoft.com/en-us/learn/modules/manage-azure-active-directory-identity-protection/2-review-identity-protection-basics
upvoted 5 times
Dipronil
2 years, 5 months ago
Risky sign in report, but in the question it is saying as Risky users report. So User 3 and $ both can view this report
upvoted 4 times
...
...
Anju18
2 years, 7 months ago
agree your point
upvoted 2 times
...
...
007Ali
Highly Voted 2 years, 3 months ago
Configure user risk policy: User3 (Security Administrator) View the Risky Users Report: User3 and User4 (Security Administrator and Security Operator) Conditional Access Administrator - Does not have access to Identity Protection | User risk policy - Does not have "Grants access to Risky Users Report" Authentication Administrator - Does not have access to Identity Protection | User risk policy - Does not have "Grants access to Risky Users Report" Security Administrator - Has update access to Identity Protection | User risk policy microsoft.directory/identityProtection/allProperties/update = Update all resources in Azure AD Identity Protection - Grants access to Risky Users Report Security Operator - Has only read access to Identity Protection | User risk policy microsoft.directory/identityProtection/allProperties/allTasks = Create and delete all resources, and read and update standard properties in Azure AD Identity Protection - Grants access to Risky Users Report
upvoted 38 times
...
59e8fdb
Most Recent 1 month, 3 weeks ago
This is managed with conditional access policies now, and will be deprecated in 2026 so not sure if it's still relevant...
upvoted 1 times
...
anonymousarpanch
2 months, 3 weeks ago
if you see this link 'https://learn.microsoft.com/en-us/entra/id-protection/overview-identity-protection', you will notice that in the table you will see Security Administrator as having full access on ID protection and security operator as having access to reports except risky sign-ins report. NOTE: below the table you will see 'Conditional Access administrators can create policies that factor in user or sign-in risk as a condition. Find more information in the article Conditional Access: Conditions.' which clarifies that User 1, User 3 should be for box 1 and user1, 3, 4 for box 2.
upvoted 1 times
anonymousarpanch
2 months, 3 weeks ago
in addition to the above, you can also look at this URL. https://learn.microsoft.com/en-us/entra/id-protection/howto-identity-protection-configure-risk-policies . The step by step instructions calls out that you have to sign in as 'Conditional Access Administrator'
upvoted 1 times
...
...
dule27
10 months, 3 weeks ago
Configure the user risk policy: User 3 only View the risky users report: User 3 and User 4 only
upvoted 3 times
...
LeTrinh
1 year, 2 months ago
It is correct, See the link: https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/overview-identity-protection
upvoted 2 times
...
Aquintero
1 year, 3 months ago
configurar la politica solo el Usuario 3 y luego 3 y 4.
upvoted 2 times
...
[Removed]
1 year, 4 months ago
Oberte is correct User 3 and then 3 and 4.
upvoted 2 times
...
Zubairr13
1 year, 9 months ago
On the exam, 7/23/2022.
upvoted 3 times
...
Silent_Muzinde
2 years ago
Sec admin can configure and view all reports but cannot reset passwords Sec operate - can view reports but cannot change policies or reset passwords
upvoted 3 times
...
Jun143
2 years, 1 month ago
just pass the exam today. This came in the question.
upvoted 1 times
...
stromnessian
2 years, 1 month ago
Tested to confirm: Configure: User 3 only Read report: Users 3 and 4
upvoted 6 times
...
TonytheTiger
2 years, 1 month ago
On the exam today - March 4, 2022
upvoted 2 times
...
GPerez73
2 years, 2 months ago
First box: User3 // Second box: User3 and User4 Tested!
upvoted 4 times
...
KennethYY
2 years, 2 months ago
Configure policy:User3 (Security Administrator) View : tried granted Eligible Security Operator cannot see the security blade, but if change to active, it can see Security Blade and see the report
upvoted 1 times
...
Pravda
2 years, 3 months ago
On the exam 1/20/2022
upvoted 1 times
...
NawafAli
2 years, 3 months ago
Tested in Lab, correct answer is - Configure the user risk policy - user3 View the risky users report - user3 & user4
upvoted 9 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago