Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

Task 9

You need to ensure that when users in the Sg-Operations group go to the My Apps portal a tab named Operations appears that contains only the following applications:

• Unkedln

• Box

Task 7

You need to lock out accounts for five minutes when they have 10 failed sign-in attempts.

Task 6

You need to implement additional security checks before the members of the Sg-Executive can access any company apps. The members must meet one of the following conditions:

• Connect by using a device that is marked as compliant by Microsoft Intune.

• Connect by using client apps that are protected by app protection policies.

You have an Azure subscription that contains the users shown in the following table.

You need to implement Azure AD Privileged Identity Management (PIM).

Which users can use PIM to activate their role permissions?

A.

Admin! only

B.

Admin2 only

C.

Admin3 only

D.

Admin1 and Admin2 only

E.

Admin2 and Admin3 only

F.

Admin1, Admin2, and Admin3

You have a Microsoft Entra tenant that contains the users shown in the following table:

Admin4 creates a Conditional Access policy named Policy1 by using the " Require multifactor authentication for Azure management " template.

Which users will be required to use multi-factor authentication (MFA) the next time they sign in?

A.

Admin2 and Admin3 only

B.

Admin1 and Admin4 only

C.

Admin1, Admin2, and Admin3 only

D.

Admin1, Admin2, Admin3, and Admin4

You configure a new Microsoft 36S tenant to use a default domain name of contosso.com.

You need to ensure that you can control access to Microsoft 365 resource-, by using conditional access policy.

What should you do first?

A.

Disable the User consent settings.

B.

Disable Security defaults.

C.

Configure a multi-factor authentication (Ml A) registration policy1.

D.

Configure password protection for Windows Server Active Directory.

Your company requires that users request access before they can access corporate applications.

You register a new enterprise application named MyApp1 in Azure Active Dilatory (Azure AD) and configure single sign-on (SSO) for MyApp1.

Which settings should you configure next for MyApp1?

A.

Self-service

B.

Provisioning

C.

Roles and administrators

D.

Application proxy

You have a Microsoft 365 subscription that uses Microsoft Defender for Cloud Apps.

You have multiple third-party apps that access the resources in the subscription.

You need to monitor the access of the third-party apps.

What should you create?

A.

an OAuth app policy

B.

an endpoint protection policy

C.

an app permission policy

D.

an access policy

You have an Azure Active Directory (Azure AD) tenant that contains a user named SecAdmin1. SecAdmin1 is

assigned the Security administrator role.

SecAdmin1 reports that she cannot reset passwords from the Azure AD Identity Protection portal.

You need to ensure that SecAdmin1 can manage passwords and invalidate sessions on behalf of nonadministrative

users. The solution must use the principle of least privilege.

Which role should you assign to SecAdmin1?

A.

Authentication administrator

B.

Helpdesk administrator

C.

Privileged authentication administrator

D.

Security operator

You have a Microsoft Entra tenant that contains the identities shown in the following table.

Group1 has the following configurations:

• Owners: User1, User4

• Members: User1, Managed2, Gioup2

You create an access review that has the following settings:

• Name: Review1

• Review scope: Select Teams + Groups

• Group: Group1

• Scope: All users

• Select reviewers: Group owner(s)

The Fallback reviewers: setting is NOT configured.