exam questions

Exam SC-300 All Questions

View all questions & answers for the SC-300 exam

Exam SC-300 topic 1 question 34 discussion

Actual exam question from Microsoft's SC-300
Question #: 34
Topic #: 1
[All SC-300 Questions]

DRAG DROP
-

You have a Microsoft 365 E5 subscription that contains two users named User1 and User2.

You need to ensure that User1 can create access reviews for groups, and that User2 can review the history report for all the completed access reviews. The solution must use the principle of least privilege.

Which role should you assign to each user? To answer, drag the appropriate roles to the correct users. Each role may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Halwagy
Highly Voted 1 year, 11 months ago
User 1 : User Administrator User 2 : Security Reader
upvoted 50 times
klayytech
8 months, 2 weeks ago
https://learn.microsoft.com/en-us/entra/id-governance/deploy-access-reviews#who-will-create-and-manage-access-reviews Global Admin Global Reader security reader does not have permission to read the history for Azure resource roles
upvoted 4 times
...
klayytech
9 months, 1 week ago
Read access review of a group or of an app Least privileged role = Security Reader Additional roles= Security Administrator User Administrator https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/delegate-by-task#enterprise-applications
upvoted 4 times
HaubeRR89
3 weeks, 3 days ago
User 1 : User Administrator User 2 : Global Reader Global Administrator, Identity Governance Administrator, and Global Reader can see history reports for all access reviews. All other users are only allowed to see reports on access reviews that they generate. https://learn.microsoft.com/en-us/entra/id-governance/access-reviews-downloadable-review-history
upvoted 1 times
...
...
oscarpopi
1 year, 11 months ago
Correct
upvoted 3 times
...
...
doch
Highly Voted 1 year, 11 months ago
User Admin Security Reader Ref: https://learn.microsoft.com/en-us/azure/active-directory/roles/delegate-by-task
upvoted 25 times
oscarpopi
1 year, 11 months ago
Correct, that's a nice article, I'll bookmark it
upvoted 3 times
...
...
Frank9020
Most Recent 2 weeks, 6 days ago
User1: User administrator: Allows managing users, groups, and access reviews, but does not provide global admin rights. User2: Reports reader: Allows access to reports and analytics without administrative permissions, aligning with least privilege.
upvoted 1 times
...
ColdCut
2 months ago
The correct answer is: User1: User administrator User2: Global reader Explanation: User1 needs to create access reviews for groups. To create access reviews, the User administrator role is appropriate. The User administrator can manage user settings, including group memberships and access reviews. User2 needs to review the history report for all completed access reviews. The Global reader role allows users to view reports and other information across Microsoft 365 without granting them permissions to make any changes. This role aligns with the requirement for reviewing access review history, as it provides read-only access. Resource Links: For more details about roles and permissions: User Administrator role Global Reader role
upvoted 1 times
...
AlexBrazil
2 months, 1 week ago
According to https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/delegate-by-task, User1: User Administrator "Create, update, or delete access review of a group or of an app" User2: Security Reader "Read access review of a Microsoft Entra role"
upvoted 1 times
...
BRZSZCL
2 months, 2 weeks ago
To ensure the least privilege principle is followed for each user: User1 needs to create access reviews for groups. The appropriate role for this task is User Access Administrator because it allows users to create and manage access reviews in Azure AD. User2 needs to review the history report for all completed access reviews. The role required for this is Reports Reader, which allows viewing reports without granting the ability to create or manage the reviews themselves. Summary: User1: User Access Administrator User2: Reports Reader
upvoted 3 times
...
hml_2024
3 months, 3 weeks ago
To meet the requirements while adhering to the principle of least privilege, you should assign the following roles: - **User1**: Assign the **User Administrator** role. This role allows User1 to create access reviews for groups¹. - **User2**: Assign the **Global Reader** role. This role allows User2 to review the history report for all completed access reviews without granting any additional administrative permissions².
upvoted 1 times
...
cluocal
4 months ago
User1: User Admin (Create, update, or delete access review of a group or of an app) User 2: Security Reader (Read access review of a group or of an app) https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/delegate-by-task
upvoted 3 times
...
srysgbvjumozmail
5 months ago
User 1 : User Administrator User 2 : Security Reader https://learn.microsoft.com/en-us/entra/id-governance/deploy-access-reviews#who-will-create-and-manage-access-reviews
upvoted 2 times
...
klayytech
8 months, 2 weeks ago
https://learn.microsoft.com/en-us/entra/id-governance/deploy-access-reviews#who-will-create-and-manage-access-reviews Global Admin Global Reader security reader does not have permission to read the history for Azure resource roles
upvoted 1 times
Discuss4certi
6 months ago
Neither can a global reader. You need to be assigned the permissions for that resource. Therefore since it's not stated go for user admin for the creation of access review and security reader for the reports.
upvoted 1 times
...
...
ItzVerified
8 months, 3 weeks ago
User 1 : User Administrator User 2 : Security Reader
upvoted 3 times
...
jtlucas99
8 months, 3 weeks ago
Per Copilot: In Azure Active Directory (Azure AD), you can assign different roles to users to manage access reviews. For User1, you should assign the Access Review Contributor role. This role allows the user to create and manage access reviews, but it doesn’t allow them to make decisions on behalf of reviewers. For User2, you should assign the Access Review Reader role. This role allows the user to read access reviews and their decisions, but they can’t create, update, or delete access reviews. These roles follow the principle of least privilege, granting only the necessary permissions to each user for their specific tasks.
upvoted 1 times
...
klayytech
9 months, 1 week ago
Read access review of a group or of an app Least privileged role = Security Reader Additional roles= Security Administrator User Administrator https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/delegate-by-task#enterprise-applications
upvoted 2 times
...
emartiy
9 months, 1 week ago
User1: User Admin User 2: security Reader
upvoted 2 times
...
RahulX
10 months, 4 weeks ago
Create, update, or delete access review of a group or of an app (User Administrator) Read access review of a group or of an app (Security Reader). https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/delegate-by-task
upvoted 1 times
...
Er_01
1 year ago
The question states least privilege as a requirement so GA/GR is does fit this. User 1 : User Administrator User 2 : Security Reader
upvoted 1 times
...
poesklap
1 year, 1 month ago
https://learn.microsoft.com/en-us/entra/id-governance/access-reviews-downloadable-review-history Global Admin Global Reader
upvoted 3 times
curtmcgirt
1 year ago
no. that article is about __history reports__ for access reviews, rather than about access reviews themselves. the specific sentence you read is poorly written, and should probably read "Global Administrator and Global Reader can see --history reports of -- all access reviews."
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago