SC-300-KR 문제 141
Gateway1이라는 타사 웹 게이트웨이를 배포합니다.
Gateway1을 Microsoft Defender for Cloud Apps와 통합해야 합니다. 솔루션은 다음 요구 사항을 충족해야 합니다.
클라우드 앱용 Defender로 데이터가 자동으로 흐르는지 확인하세요.
행정적 노력을 최소화합니다.
가장 먼저 무엇을 해야 하나요?
Let's break this down step by step based on Microsoft Defender for Cloud Apps (MDCA)integration with third-party web gateways, as outlined in Microsoft Identity and Access Administrator documentation.
Understanding the Scenario and Requirements:
Microsoft 365 E5 subscription:This subscription includes Microsoft Defender for Cloud Apps, which provides the necessary licensing for integrating with third-party web gateways.
Third-party web gateway named Gateway1:A web gateway (e.g., a Secure Web Gateway like Zscaler, Netskope, or Symantec) is deployed to manage and secure internet traffic. The question does not specify the vendor, but the process for integration with MDCA is generally the same for supported gateways.
Requirement:Integrate Gateway1 with Microsoft Defender for Cloud Apps to ensure that data (e.g., traffic logs, events) flows automatically to MDCA for analysis, visibility, and policy enforcement. The solution must also minimize administrative effort.
Microsoft Defender for Cloud Apps supports integration with third-party web gateways to provide visibility into cloud app usage, detect shadow IT, and enforce security policies. This integration typically involves collecting logs from the gateway for analysis in MDCA.
How Microsoft Defender for Cloud Apps Integrates with Third-Party Web Gateways:
MDCA can integrate with third-party web gateways by collecting logs that contain traffic data (e.g., user activity, app usage, IP addresses). This allows MDCA to analyze the data and provide insights into cloud app usage, detect threats, and enforce policies.
The primary method for integrating a third-party web gateway with MDCA is toadd a log collector. This involves:
Configuring the web gateway to send logs to a log collector (e.g., via Syslog or FTP).
Setting up a log collector in MDCA to receive and process these logs.
Once configured, the log collector automatically pulls logs from the web gateway, ensuring that data flows to MDCA for analysis.
This method supports automatic data flow and minimizes administrative effort because, after the initial setup, the log collection process runs continuously without manual intervention.
Analyzing the Options:
A). Add a data source:
In Microsoft Defender for Cloud Apps, " data sources " typically refer to sources of user activity data, such as Microsoft Entra ID audit logs, Microsoft 365 audit logs, or other Microsoft services. Adding a data source in MDCA is used to import user activity data for correlation with cloud app usage, but it is not the mechanism for integrating a third-party web gateway.
Third-party web gateways are not considered " data sources " in MDCA; instead, they are integrated via log collectors.
Conclusion:This option is incorrect because adding a data source does not facilitate integration with a third- party web gateway like Gateway1.
B). Create an app registration:
Creating an app registration in Microsoft Entra ID is typically used to integrate cloud apps with MDCA for session control (e.g., via Conditional Access App Control) or to enable API-based logcollection for supported apps (e.g., Salesforce, Box).
However, a third-party web gateway like Gateway1 is not a cloud app that requires an app registration. Web gateways are network appliances or services that manage traffic, and their integration with MDCA involves log collection, not app registration.
Conclusion:This option is incorrect because creating an app registration is not relevant to integrating a web gateway with MDCA.
C). Create a snapshot report:
A snapshot report in MDCA is a manual process where an administrator uploads a log file (e.g., a CSV or JSON file) from a third-party service to analyze cloud app usage. This is a one-time, manual process used for discovery (e.g., to identify shadow IT).
The requirement specifies that data must flow " automatically " to Defender for Cloud Apps, and a snapshot report does not meet this requirement because it requires manual uploads each time. It also does not minimize administrative effort due to the ongoing manual intervention.
Conclusion:This option is incorrect because creating a snapshot report does not enable automatic data flow and increases administrative effort.
D). Add a log collector:
Adding a log collector in Microsoft Defender for Cloud Apps is the standard method for integrating third- party web gateways. MDCA supports log collection from many web gateways (e.g., Zscaler, Netskope, Symantec) via Syslog or FTP.
Process:
In the Microsoft Defender for Cloud Apps portal, navigate toSettings > Log collectors.
Add a new log collector, specifying the protocol (e.g., Syslog over TCP/UDP or FTP) and the details of the web gateway (e.g., IP address, port).
Configure Gateway1 to send logs to the log collector (this step is done on the Gateway1 side, typically by the network team).
Once set up, the log collector automatically collects logs from Gateway1 and processes them in MDCA for analysis.
Automatic Data Flow:The log collector ensures that data flows automatically to MDCA, meeting the first requirement.
Minimize Administrative Effort:After the initial setup, the log collector runs continuously without manual intervention, minimizing administrative effort.
Conclusion:This option is correct because adding a log collector is the first step to integrate Gateway1 with MDCA, ensuring automatic data flow and minimizing administrative effort.
Why " Add a log collector " is the First Step:
The question asks for the first step to integrate Gateway1 with Microsoft Defender for Cloud Apps. Adding a log collector is the initial action in MDCA to enable log collection from a third-party web gateway.
Subsequent steps (not asked in the question) would include configuring Gateway1 to send logs to the log collector, but this is done outside MDCA (e.g., in Gateway1's management console). The question focuses on the action in MDCA, making " Add a log collector " the correct first step.
Additional Considerations:
The question does not specify the vendor of Gateway1, but Microsoft Defender for Cloud Apps supports log collection from many third-party web gateways (e.g., Zscaler, Netskope, Symantec, Cisco Umbrella). The process is the same regardless of the vendor, as long as the gateway supports Syslog or FTP log export.
If Gateway1 were not a supported web gateway, additional steps (e.g., custom log parsing) might be required, but the question implies Gateway1 can be integrated using standard methods.
The Microsoft 365 E5 subscription includes Microsoft Defender for Cloud Apps, so no additional licensing is required.
Conclusion:To integrate Gateway1 with Microsoft Defender for Cloud Apps, ensuring that data flows automatically and minimizing administrative effort, the first step is toadd a log collectorin MDCA. This sets up the infrastructure to receive logs from Gateway1, enabling automatic data flow for analysis. Therefore, the correct answer isD.
References:
Microsoft Defender for Cloud Apps documentation: " Integrate with a third-party web gateway " (Microsoft Learn:https://learn.microsoft.com/en-us/defender-cloud-apps/connect-third-party-gateway) Microsoft Defender for Cloud Apps documentation: " Set up a log collector " (Microsoft Learn:https://learn.
microsoft.com/en-us/defender-cloud-apps/log-collector)
Microsoft Identity and Access Administrator (SC-300) exam study guide, which covers integrating Microsoft Defender for Cloud Apps with third-party services for cloud app visibility and control.
SC-300-KR 문제 142
다음 요구 사항을 충족하려면 테넌트에 대한 외부 협업 설정을 구성해야 합니다.
*게스트 사용자는 직원 이메일 주소를 조회하는 것이 금지되어야 합니다.
*게스트 사용자는 User1의 초대를 받은 경우에만 테넌트에 액세스할 수 있어야 합니다.
어떤 세 가지 설정을 구성해야 할까요? 답변하려면 답변 영역에서 적절한 설정을 선택하세요.


Explanation:
According to the Microsoft SC-300 Study Guide, Exam Ref SC-300, and Microsoft Entra External Collaboration (B2B) documentation, the configuration of External collaboration settings in Azure AD determines how guest users can access directory data and who can invite them into the tenant.
Let's analyze each requirement in context:
Requirement 1: "Guest users must be prevented from querying staff email addresses." To achieve this, Azure AD provides the setting Guest user access restrictions, which defines what a guest can see in the directory. The most restrictive setting ensures that guest users can only see their own profile details and no other users or groups.
# Therefore, select:
"Guest user access is restricted to properties and memberships of their own directory objects (most restrictive)." This prevents guests from discovering internal directory data such as email addresses of staff members or group memberships.
Requirement 2: "Guest users must be able to access the tenant only if they are invited by User1." User1 has the User Administrator role. This role is included among the "specific admin roles" allowed to invite guest users when the setting is configured appropriately.
To meet the requirement that only User1 (or other admins) can invite guests, you must configure:
# "Only users assigned to specific admin roles can invite guest users." This restricts invitation privileges to admin roles (such as Global Administrator, User Administrator, etc.) and prevents ordinary users or guests from inviting others.
Requirement 3: "Guests should not be able to self-enroll."
Azure AD B2B allows self-service sign-up through user flows (Identity Experience Framework). Enabling this feature would let external users sign up themselves - which violates the condition that guests must be invited by User1 only.
# Therefore, set Enable guest self-service sign-up via user flows = No.
Final Configuration Summary: Setting
Value
Guest user access restrictions
Guest user access is restricted to properties and memberships of their own directory objects (most restrictive) Guest invite restrictions Only users assigned to specific admin roles can invite guest users Enable guest self-service sign-up via user flows No
# Microsoft Official Documentation Reference (SC-300 Content):
"To prevent guests from seeing other users in the directory, configure guest user access restrictions to 'most restrictive.' To control who can invite guests, use the setting that limits invitations to users with admin roles.
To disallow self-service guest access, disable user flows for external sign-up."
SC-300-KR 문제 143
User1이라는 사용자에게 보안 관리자 역할이 할당되었습니다.
User1이 Microsoft Defender for Cloud Apps 세션 정책을 만들 수 있는지 확인해야 합니다.
가장 먼저 무엇을 해야 하나요?
SC-300-KR 문제 144
User1이 Vault1에 저장된 인증서, 키 및 비밀의 메타데이터를 읽을 수 있도록 해야 합니다. 솔루션은 최소 권한 원칙을 따라야 합니다.
User1에게 어떤 역할을 할당해야 할까요?
Let's break this down step by step based on Azure Key Vault roles, permissions, and the principle of least privilege, as outlined in Microsoft Identity and Access Administrator documentation.
Understanding Azure Key Vault and the Requirement:
Azure Key Vault is a service that securely stores and manages cryptographic keys, secrets, and certificates. It uses role-based access control (RBAC) to manage permissions for users, groups, and applications.
The question requires that User1 canread the metadataof certificates, keys, and secrets in Vault1. In Azure Key Vault, "metadata" refers to the properties of these objects (e.g., name, creation date, expiration date), not the actual content (e.g., the secret value, key value, or certificate private key).
The solution must follow theprinciple of least privilege, meaning User1 should be granted the minimum permissions necessary to perform the task, without access to unnecessary actions (e.g., modifying or deleting objects).
Azure Key Vault RBAC Roles and Permissions:
Azure Key Vault supports built-in RBAC roles that define specific permissions for managing keys, secrets, and certificates. Let's examine each role in the options:
Key Vault Crypto User:
This role allows a user to perform cryptographic operations using keys (e.g., encrypt, decrypt, sign, verify) and to read key metadata.
Permissions include: Microsoft.KeyVault/vaults/keys/read (read key metadata) and cryptographicoperations like encrypt, decrypt, etc.
However, this role does not grant permissions to read metadata for secrets or certificates, and it includes cryptographic operation permissions, which are not needed for the task.
Key Vault Crypto Officer:
This role is designed for managing keys and performing cryptographic operations. It includes permissions to create, delete, update, and read keys, as well as perform cryptographic operations.
Permissions include: Microsoft.KeyVault/vaults/keys/* (full control over keys).
This role does not grant access to secrets or certificates and provides more permissions than needed (e.g., create, delete), violating the principle of least privilege.
Key Vault Reader:
This role provides read-only access to the metadata of all objects in the Key Vault (keys, secrets, and certificates).
Permissions include: Microsoft.KeyVault/vaults/read (read vault properties) and Microsoft.KeyVault/vaults/*
/read (read metadata for keys, secrets, and certificates).
Importantly, this role does not allow access to the actual content of the objects (e.g., the secret value, key value, or certificate private key), only the metadata. It also does not allow write operations (e.g., create, update, delete).
This aligns perfectly with the requirement to "read the metadata" and follows the principle of least privilege.
Key Vault Secrets User:
This role allows a user to read the content of secrets (not just metadata) and perform operations like getting the secret value.
Permissions include: Microsoft.KeyVault/vaults/secrets/get (read secret values) and Microsoft.KeyVault
/vaults/secrets/read (read secret metadata).
This role does not grant access to keys or certificates, and it provides more access than needed (reading the secret value, not just metadata), violating the principle of least privilege.
Applying the Principle of Least Privilege:
The task requires User1 to read the metadata of certificates, keys, and secrets, but not to access their content or perform any write operations.
Key Vault Readeris the most appropriate role because:
It grants read-only access to the metadata of all objects (keys, secrets, certificates).
It does not allow access to the content of the objects (e.g., secret values), which is not required.
It does not allow write operations (e.g., create, delete), adhering to the principle of least privilege.
The other roles either provide too much access (e.g., Key Vault Crypto Officer, Key Vault Secrets User) or do not cover all required objects (e.g., Key Vault Crypto User, Key Vault Secrets User).
Analysis of the Options:
A). Key Vault Crypto User:
Incorrect. This role only allows reading key metadata and performing cryptographic operations, but it does not provide access to secrets or certificates metadata. It also grants unnecessarycryptographic permissions.
B). Key Vault Crypto Officer:
Incorrect. This role provides full control over keys, which is far more than needed, and does not grant access to secrets or certificates metadata.
C). Key Vault Reader:
Correct. This role provides read-only access to the metadata of keys, secrets, and certificates, exactly matching the requirement while following the principle of least privilege.
D). Key Vault Secrets User:
Incorrect. This role allows reading secret values (not just metadata) and does not provide access to keys or certificates metadata. It grants more access than needed.
Additional Considerations:
If the question had asked for User1 to read the content of secrets (not just metadata), the Key Vault Secrets User role might be considered, but it still wouldn't cover keys and certificates.
Custom RBAC roles could be created to fine-tune permissions, but the question asks for a built-in role, and Key Vault Reader is the best fit.
The question does not specify whether User1 needs to perform other actions (e.g., cryptographic operations, managing the vault). If additional permissions were needed, a combination of roles or a custom role might be required, but the principle of least privilege guides us to the minimal role.
Conclusion:To ensure User1 can read the metadata of certificates, keys, and secrets in Vault1 while following the principle of least privilege, theKey Vault Readerrole should be assigned. This role provides the exact permissions needed without granting unnecessary access. Therefore, the correct answer isC.
References:
Azure Key Vault documentation: "Azure Key Vault RBAC roles" (Microsoft Learn:https://learn.microsoft.
com/en-us/azure/key-vault/general/rbac-guide)
Azure Key Vault documentation: "Secure access to a key vault" (Microsoft Learn:https://learn.microsoft.com
/en-us/azure/key-vault/general/secure-your-key-vault)
Microsoft Identity and Access Administrator (SC-300) exam study guide, which covers Azure Key Vault access control and the principle of least privilege.
SC-300-KR 문제 145
The scenario specifies that trust relationships must NOT be established between adatum.com and litware.
com, but A. Datum must still sync the AD DS users and groups of litware.com to their existing Azure AD tenant (adatum.com).
The SC-300 training materials clarify:
"Azure AD Connect cloud sync enables syncing from multiple AD forests to a single Azure AD tenant without the need for forest trusts or a full Azure AD Connect installation in each forest." Unlike staging mode (which provides a standby sync server for failover) or extending the same Azure AD Connect instance to another domain (which requires trust relationships and network connectivity between forests), Azure AD Connect Cloud Sync uses lightweight agents and does not depend on forest trust.
Therefore, to meet the requirement of syncing Litware's AD DS to A. Datum's Azure AD tenant without creating a trust, the correct choice is to configure Azure AD Connect Cloud Sync between the Azure AD tenant and the litware.com domain.
- 다른 버전
- 462Microsoft.SC-300-KR.v2026-08-29.q204
- 1194Microsoft.SC-300-KR.v2026-06-08.q173
- 1894Microsoft.SC-300-KR.v2026-04-21.q141
- 1440Microsoft.SC-300-KR.v2026-03-16.q211
- 1161Microsoft.SC-300-KR.v2026-03-03.q165
- 1295Microsoft.SC-300-KR.v2025-11-24.q159
- 1155Microsoft.SC-300-KR.v2025-02-28.q117
- 최근 업로드
- 106Saviynt.SCAIP.v2026-09-07.q20
- 106ISC.CCSP-KR.v2026-09-07.q424
- 105Oracle.1Z0-1032-26.v2026-09-07.q23
- 105Nursing.PMHN-BC.v2026-09-07.q38
- 105Cisco.300-430.v2026-09-07.q266
- 176Oracle.1Z1-171.v2026-09-06.q38
- 181SAP.C_S4TM.v2026-09-06.q71
- 178Oracle.1Z0-1054-26.v2026-09-06.q65
- 231Huawei.H12-831_V1.0.v2026-09-06.q231
- 152Salesforce.Plat-Arch-205.v2026-09-06.q28
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. Microsoft.SC-300-KR.v2026-06-03.q151 모의시험 시험자료를 다운 받으세요.
