Microsoft Certified: Identity and Access Administrator Associate Exam Prep
Free practice questions

Free SC-300 Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

These 10 free SC-300 questions are organized by exam domain, so you can see how each part of the Microsoft Certified: Identity and Access Administrator Associate blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Implement and manage user identities (20-25%)

Question 1

A regional support technician has User Administrator scoped only to the North administrative unit. That unit contains the North-Staff security group, but none of its user objects. The technician can change the group description but cannot update the department of a nonadministrator who belongs to the group. The user is cloud-only. What change restores the intended regional delegation without granting tenant-wide authority?

Show answer & explanation

Correct answer: B - Add the North-Staff user objects directly to the North administrative unit.

Question 2

An organization uses pass-through authentication with password hash synchronization already enabled. During disaster-recovery planning, the team models an outage in which no authentication agent can reach AD DS, while Entra ID remains available. Which proposed recovery assumption should be rejected?

Show answer & explanation

Correct answer: C - Password hash synchronization would automatically take over when pass-through authentication became unavailable.

Question 3

While investigating repeated Microsoft 365 sign-in prompts, a technician runs dsregcmd /status in the affected user's Windows session and captures: AzureAdJoined : YES DomainJoined : YES AzureAdPrt : NO What can the technician conclude from these values, without assuming a device-compliance state?

Show answer & explanation

Correct answer: D - The device is Microsoft Entra hybrid joined, but the user has no Primary Refresh Token.

Domain 2: Implement authentication and access management (25-30%)

Question 4

A payroll sign-in matches three Conditional Access policies: Access-1: On; require either multifactor authentication OR a compliant device. Access-2: On; require a Microsoft Entra hybrid joined device. Access-3: Report-only; block access. The employee has completed MFA. The device is hybrid joined but is not compliant, and its device identity is available during policy evaluation. Application assignment is valid, and no other policy applies. How should this request be evaluated?

Show answer & explanation

Correct answer: B - Allow access: both enforced policies are satisfied; the report-only block is not enforced.

Question 5

Microsoft Entra ID Protection reports High user risk for a cloud-only employee after a leaked-credentials detection. The employee's latest sign-in is Low risk and successfully completes MFA. The password has not been changed. The organization wants registered users to remediate this type of account risk during access rather than wait for an administrator to unblock them. Which Conditional Access configuration addresses the unresolved risk?

Show answer & explanation

Correct answer: A - Target High user risk and select Require risk remediation.

Question 6

A company is deploying Microsoft Entra Private Access for two private services: a maintenance host on TCP 3389 and an inventory server on TCP 1433. Contractors need only the maintenance host; employees need only the inventory server. Each population must have its own Conditional Access requirements. The licensed clients and private network connectors are ready, and neither service is published yet. Which design provides the required access separation?

Show answer & explanation

Correct answer: C - Publish a separate per-app enterprise application for each service, with its own segment, assignments, and Conditional Access policy.

Domain 3: Plan and implement workload identities (20-25%)

Question 7

An Azure workload runs on virtual machines that are deleted and recreated during deployments. Every replacement must use the same preauthorized identity. The application reads blobs from one container through Microsoft Entra authentication; it must not write blobs or manage the storage account. No application-managed secrets or certificates are permitted. Which identity and role assignment meet all of these requirements?

Show answer & explanation

Correct answer: D - A user-assigned managed identity with Storage Blob Data Reader scoped to the container.

Question 8

A nightly export uses the OAuth 2.0 client-credentials flow to call a custom Records API without a signed-in user. The API defines Records.Read as a delegated scope for records the signed-in user may read, and Records.Read.All as an application role for app-only exports. Only Records.Read has been consented. The API accepts the token's signature and audience but rejects the read request; the token has no roles claim. What should be corrected in the authorization configuration?

Show answer & explanation

Correct answer: B - Grant admin consent to Records.Read.All as an application permission, then obtain a new token.

Domain 4: Plan and automate identity governance (20-25%)

Question 9

An access review denies a consultant's membership in a cloud-managed, assigned-membership group used by a procurement application. The review shows Result applied, and the consultant is no longer a group member. Nevertheless, a fresh sign-in still reaches the application. Its enterprise application has Assignment required set to Yes; the consultant's only assignment paths were that group and a separate direct assignment. The consultant must retain access to unrelated projects. Select the targeted correction.

Show answer & explanation

Correct answer: A - Remove the consultant's direct assignment to the procurement enterprise application.

Question 10

A role-assignable group has an active Microsoft Entra User Administrator assignment. Through PIM for Groups, an engineer is eligible for both group membership and group ownership. The engineer activates ownership only, then cannot reset an ordinary cloud user's password. No other administrator role is assigned to the engineer. To perform the task through the approved, time-limited elevation path, the engineer needs to:

Show answer & explanation

Correct answer: C - Activate the eligible membership assignment for the role-assignable group.

That's 10 of 1,030

The full bank has 1,020 more SC-300 questions with explanations.

Continue in the free practice test →

View plans