Microsoft SC-300 Privileged Identity Management and Emergency Access Practice Test
Topic 15 covers privileged identity management and emergency access for the Microsoft Certified: Identity and Access Administrator Associate certification. These original practice questions apply the verified SC-300 objectives to practical decisions and troubleshooting. Select one answer unless a fixed number is requested. For broader preparation, visit the SC-300 Exam Dumps page. Each option includes an explanation of the relevant behavior and scenario constraints.
Question 1
A change request for an administrator who should activate privilege only when needed will be accepted only when the following is true: the correct eligible-versus-active Microsoft Entra role assignment. General network connectivity outside the identity path is already verified. Which action best satisfies the requirement?
Correct Answer: E
Correct Answer
Answer E is correct because This action directly provides the appropriate eligible versus active Entra role assignment. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is diagnosis of activation propagation versus resource permission. The scenario instead requires the appropriate eligible versus active Entra role assignment, so this option would solve an adjacent identity problem rather than the documented gap.
Answer B is incorrect because This action is appropriate when the requirement is correct interpretation of inherited resource-role assignment scope. The scenario instead requires the appropriate eligible versus active Entra role assignment, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is traceability of privileged action to activation history. The scenario instead requires the appropriate eligible versus active Entra role assignment, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is a clear distinction between permanent assignment and eligible schedule. The scenario instead requires the appropriate eligible versus active Entra role assignment, so this option would solve an adjacent identity problem rather than the documented gap.
Question 2
The implementation of a contractor with time-limited administrative duties is complete except for this requirement: the required setting for assignment duration for contractor administrator. Resource permissions outside the identity control are already correct. Which action best satisfies the requirement?
Correct Answer: C
Correct Answer
Answer C is correct because This action directly provides the required setting for assignment duration for contractor administrator. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is onboard Azure resource scope for PIM management. The scenario instead requires the required setting for assignment duration for contractor administrator, so this option would solve an adjacent identity problem rather than the documented gap.
Answer B is incorrect because This action is appropriate when the requirement is removal of excessive active assignment after PIM validation. The scenario instead requires the required setting for assignment duration for contractor administrator, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is submit activation request with required evidence. The scenario instead requires the required setting for assignment duration for contractor administrator, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is a clear distinction between assignment change and activation event. The scenario instead requires the required setting for assignment duration for contractor administrator, so this option would solve an adjacent identity problem rather than the documented gap.
Question 3
The support team has ruled out unrelated causes in a privileged role activation with MFA and approval. The remaining issue is: enforcement of MFA or authentication context at activation. The administrator must verify the effective result from Microsoft Entra evidence. Which action best satisfies the requirement?
Correct Answer: E
Correct Answer
Answer E is correct because This action directly provides enforcement of MFA or authentication context at activation. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is the appropriate eligible role at least required Azure scope. The scenario instead requires enforcement of MFA or authentication context at activation, so this option would solve an adjacent identity problem rather than the documented gap.
Answer B is incorrect because This action is appropriate when the requirement is correct configuration of eligible group membership for privileged access. The scenario instead requires enforcement of MFA or authentication context at activation, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is route approval to authorized approver. The scenario instead requires enforcement of MFA or authentication context at activation, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is identify persistent privilege through PIM reports. The scenario instead requires enforcement of MFA or authentication context at activation, so this option would solve an adjacent identity problem rather than the documented gap.
Question 4
A readiness check of a privileged-access workflow leaves one unresolved condition: the required setting for justification and notification requirements. The organization requires a supported Microsoft-managed control. Which action best satisfies the requirement?
Correct Answer: C
Correct Answer
Answer C is correct because This action directly provides the required setting for justification and notification requirements. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is correct configuration of eligible ownership separately from membership. The scenario instead requires the required setting for justification and notification requirements, so this option would solve an adjacent identity problem rather than the documented gap.
Answer B is incorrect because This action is appropriate when the requirement is handling of request expiration without assuming activation. The scenario instead requires the required setting for justification and notification requirements, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is the required setting for resource-role activation duration and approval. The scenario instead requires the required setting for justification and notification requirements, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is export of audit evidence for specific time window. The scenario instead requires the required setting for justification and notification requirements, so this option would solve an adjacent identity problem rather than the documented gap.
Question 5
Testing of a privileged role activation with MFA and approval is successful except for this condition: diagnosis of activation blocked by role settings. The current population and assignment scope must be preserved. Which action best satisfies the requirement?
Correct Answer: B
Correct Answer
Answer B is correct because This action directly provides diagnosis of activation blocked by role settings. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is a design that addresses emergency access independent of normal dependencies. The scenario instead requires diagnosis of activation blocked by role settings, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is assessment of group type and role-assignable constraints. The scenario instead requires diagnosis of activation blocked by role settings, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is diagnosis of Azure RBAC authority versus Entra role authority. The scenario instead requires diagnosis of activation blocked by role settings, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is resolution of denied activation under separation-of-duties constraint. The scenario instead requires diagnosis of activation blocked by role settings, so this option would solve an adjacent identity problem rather than the documented gap.
Question 6
The organization wants the least-disruptive correction to an administrator who should activate privilege only when needed. It must provide: a clear distinction between permanent assignment and eligible schedule. Existing working access outside the stated scope must remain unchanged. Choose TWO actions that together implement and verify the requirement.
Correct Answers: A, F
Correct Answers
Answer A is correct because This action directly provides a clear distinction between permanent assignment and eligible schedule at the correct Microsoft Entra control boundary.
Answer F is correct because This verification step confirms that the selected control changes effective behavior for the intended pilot and exposes policy, assignment, propagation, or evidence problems before wider rollout.
Incorrect Answers
Answer B is incorrect because This action is appropriate when the requirement is protection of emergency credentials using current guidance. It does not implement or verify a clear distinction between permanent assignment and eligible schedule in this scenario.
Answer C is incorrect because This action is appropriate when the requirement is traceability of privileged action to activation history. It does not implement or verify a clear distinction between permanent assignment and eligible schedule in this scenario.
Answer D is incorrect because This action is appropriate when the requirement is diagnosis of activation propagation versus resource permission. It does not implement or verify a clear distinction between permanent assignment and eligible schedule in this scenario.
Answer E is incorrect because This action is appropriate when the requirement is correct interpretation of inherited resource-role assignment scope. It does not implement or verify a clear distinction between permanent assignment and eligible schedule in this scenario.
Question 7
A design review of a subscription role that should be just-in-time identifies one remaining requirement: onboard Azure resource scope for PIM management. The change will be piloted before broader enforcement. Which action best satisfies the requirement?
Correct Answer: B
Correct Answer
Answer B is correct because This action directly provides onboard Azure resource scope for PIM management. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is removal of excessive active assignment after PIM validation. The scenario instead requires onboard Azure resource scope for PIM management, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is submit activation request with required evidence. The scenario instead requires onboard Azure resource scope for PIM management, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is monitoring of and test emergency account usage. The scenario instead requires onboard Azure resource scope for PIM management, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is a clear distinction between assignment change and activation event. The scenario instead requires onboard Azure resource scope for PIM management, so this option would solve an adjacent identity problem rather than the documented gap.
Question 8
Current evidence from an administrator who should activate privilege only when needed shows that this requirement is not yet met: the appropriate eligible role at least required Azure scope. The tenant has the licensing required for the named capability. Which action best satisfies the requirement?
Correct Answer: E
Correct Answer
Answer E is correct because This action directly provides the appropriate eligible role at least required Azure scope. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is identify persistent privilege through PIM reports. The scenario instead requires the appropriate eligible role at least required Azure scope, so this option would solve an adjacent identity problem rather than the documented gap.
Answer B is incorrect because This action is appropriate when the requirement is correct configuration of eligible group membership for privileged access. The scenario instead requires the appropriate eligible role at least required Azure scope, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is recover access during policy or federation outage. The scenario instead requires the appropriate eligible role at least required Azure scope, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is route approval to authorized approver. The scenario instead requires the appropriate eligible role at least required Azure scope, so this option would solve an adjacent identity problem rather than the documented gap.
Question 9
Before expanding a privileged role activation with MFA and approval, the administrator must satisfy this condition: the required setting for resource-role activation duration and approval. The correction must address the named control boundary rather than reset unrelated tenant settings. Which action best satisfies the requirement?
Correct Answer: D
Correct Answer
Answer D is correct because This action directly provides the required setting for resource-role activation duration and approval. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is correct configuration of eligible ownership separately from membership. The scenario instead requires the required setting for resource-role activation duration and approval, so this option would solve an adjacent identity problem rather than the documented gap.
Answer B is incorrect because This action is appropriate when the requirement is handling of request expiration without assuming activation. The scenario instead requires the required setting for resource-role activation duration and approval, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is the appropriate eligible versus active Entra role assignment. The scenario instead requires the required setting for resource-role activation duration and approval, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is export of audit evidence for specific time window. The scenario instead requires the required setting for resource-role activation duration and approval, so this option would solve an adjacent identity problem rather than the documented gap.
Question 10
The administrator is preparing a privileged-access workflow for production. The required condition is: diagnosis of Azure RBAC authority versus Entra role authority. No new standing administrator privilege may be introduced. Which action best satisfies the requirement?
Correct Answer: C
Correct Answer
Answer C is correct because This action directly provides diagnosis of Azure RBAC authority versus Entra role authority. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is assessment of group type and role-assignable constraints. The scenario instead requires diagnosis of Azure RBAC authority versus Entra role authority, so this option would solve an adjacent identity problem rather than the documented gap.
Answer B is incorrect because This action is appropriate when the requirement is resolution of denied activation under separation-of-duties constraint. The scenario instead requires diagnosis of Azure RBAC authority versus Entra role authority, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is the required setting for assignment duration for contractor administrator. The scenario instead requires diagnosis of Azure RBAC authority versus Entra role authority, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is a design that addresses emergency access independent of normal dependencies. The scenario instead requires diagnosis of Azure RBAC authority versus Entra role authority, so this option would solve an adjacent identity problem rather than the documented gap.
Question 11
A production issue involving a privileged-access workflow has been narrowed to this requirement: correct interpretation of inherited resource-role assignment scope. General network connectivity outside the identity path is already verified. Which action best satisfies the requirement?
Correct Answer: D
Correct Answer
Answer D is correct because This action directly resolves interpret inherited resource-role assignment scope at the evidence or control boundary described by the scenario, rather than substituting a neighboring identity workflow.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is traceability of privileged action to activation history. The scenario instead requires correct interpretation of inherited resource-role assignment scope, so this option would solve an adjacent identity problem rather than the documented gap.
Answer B is incorrect because This action is appropriate when the requirement is protection of emergency credentials using current guidance. The scenario instead requires correct interpretation of inherited resource-role assignment scope, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is diagnosis of activation propagation versus resource permission. The scenario instead requires correct interpretation of inherited resource-role assignment scope, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is enforcement of MFA or authentication context at activation. The scenario instead requires correct interpretation of inherited resource-role assignment scope, so this option would solve an adjacent identity problem rather than the documented gap.
Question 12
The security review of a privileged-access workflow focuses on one acceptance criterion: removal of excessive active assignment after PIM validation. Resource permissions outside the identity control are already correct. Choose TWO actions that together implement and verify the requirement.
Correct Answers: B, F
Correct Answers
Answer B is correct because This action directly provides removal of excessive active assignment after PIM validation at the correct Microsoft Entra control boundary.
Answer F is correct because This verification step confirms that the selected control changes effective behavior for the intended pilot and exposes policy, assignment, propagation, or evidence problems before wider rollout.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is monitoring of and test emergency account usage. It does not implement or verify removal of excessive active assignment after PIM validation in this scenario.
Answer C is incorrect because This action is appropriate when the requirement is a clear distinction between assignment change and activation event. It does not implement or verify removal of excessive active assignment after PIM validation in this scenario.
Answer D is incorrect because This action is appropriate when the requirement is submit activation request with required evidence. It does not implement or verify removal of excessive active assignment after PIM validation in this scenario.
Answer E is incorrect because This action is appropriate when the requirement is the required setting for justification and notification requirements. It does not implement or verify removal of excessive active assignment after PIM validation in this scenario.
Question 13
The team is validating a role-assignable group managed through PIM for Groups. The decisive requirement is: correct configuration of eligible group membership for privileged access. The administrator must verify the effective result from Microsoft Entra evidence. Which action best satisfies the requirement?
Correct Answer: C
Correct Answer
Answer C is correct because This action directly provides correct configuration of eligible group membership for privileged access. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is route approval to authorized approver. The scenario instead requires correct configuration of eligible group membership for privileged access, so this option would solve an adjacent identity problem rather than the documented gap.
Answer B is incorrect because This action is appropriate when the requirement is recover access during policy or federation outage. The scenario instead requires correct configuration of eligible group membership for privileged access, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is diagnosis of activation blocked by role settings. The scenario instead requires correct configuration of eligible group membership for privileged access, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is identify persistent privilege through PIM reports. The scenario instead requires correct configuration of eligible group membership for privileged access, so this option would solve an adjacent identity problem rather than the documented gap.
Question 14
Operations staff investigating an administrator who should activate privilege only when needed have isolated the issue to: correct configuration of eligible ownership separately from membership. The organization requires a supported Microsoft-managed control. Which action best satisfies the requirement?
Correct Answer: D
Correct Answer
Answer D is correct because This action directly provides correct configuration of eligible ownership separately from membership. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is a clear distinction between permanent assignment and eligible schedule. The scenario instead requires correct configuration of eligible ownership separately from membership, so this option would solve an adjacent identity problem rather than the documented gap.
Answer B is incorrect because This action is appropriate when the requirement is export of audit evidence for specific time window. The scenario instead requires correct configuration of eligible ownership separately from membership, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is handling of request expiration without assuming activation. The scenario instead requires correct configuration of eligible ownership separately from membership, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is the appropriate eligible versus active Entra role assignment. The scenario instead requires correct configuration of eligible ownership separately from membership, so this option would solve an adjacent identity problem rather than the documented gap.
Question 15
The administrator must correct a role-assignable group managed through PIM for Groups without changing adjacent controls. The target condition is: assessment of group type and role-assignable constraints. The current population and assignment scope must be preserved. Which action best satisfies the requirement?
Correct Answer: B
Correct Answer
Answer B is correct because This action directly provides assessment of group type and role-assignable constraints. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is the required setting for assignment duration for contractor administrator. The scenario instead requires assessment of group type and role-assignable constraints, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is resolution of denied activation under separation-of-duties constraint. The scenario instead requires assessment of group type and role-assignable constraints, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is a design that addresses emergency access independent of normal dependencies. The scenario instead requires assessment of group type and role-assignable constraints, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is onboard Azure resource scope for PIM management. The scenario instead requires assessment of group type and role-assignable constraints, so this option would solve an adjacent identity problem rather than the documented gap.
Question 16
An audit of a privileged role activation with MFA and approval identifies this control gap: diagnosis of activation propagation versus resource permission. Existing working access outside the stated scope must remain unchanged. Which action best satisfies the requirement?
Correct Answer: E
Correct Answer
Answer E is correct because This action directly provides diagnosis of activation propagation versus resource permission. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is protection of emergency credentials using current guidance. The scenario instead requires diagnosis of activation propagation versus resource permission, so this option would solve an adjacent identity problem rather than the documented gap.
Answer B is incorrect because This action is appropriate when the requirement is the appropriate eligible role at least required Azure scope. The scenario instead requires diagnosis of activation propagation versus resource permission, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is enforcement of MFA or authentication context at activation. The scenario instead requires diagnosis of activation propagation versus resource permission, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is traceability of privileged action to activation history. The scenario instead requires diagnosis of activation propagation versus resource permission, so this option would solve an adjacent identity problem rather than the documented gap.
Question 17
The documented success criterion for a privileged role activation with MFA and approval is: submit activation request with required evidence. The change will be piloted before broader enforcement. Which action best satisfies the requirement?
Correct Answer: A
Correct Answer
Answer A is correct because This action directly provides submit activation request with required evidence. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer B is incorrect because This action is appropriate when the requirement is monitoring of and test emergency account usage. The scenario instead requires submit activation request with required evidence, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is the required setting for resource-role activation duration and approval. The scenario instead requires submit activation request with required evidence, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is the required setting for justification and notification requirements. The scenario instead requires submit activation request with required evidence, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is a clear distinction between assignment change and activation event. The scenario instead requires submit activation request with required evidence, so this option would solve an adjacent identity problem rather than the documented gap.
Question 18
The current configuration of a privileged-access workflow is otherwise acceptable. The unresolved requirement is: route approval to authorized approver. The tenant has the licensing required for the named capability. Choose TWO actions that together implement and verify the requirement.
Correct Answers: B, D
Correct Answers
Answer B is correct because This action directly provides route approval to authorized approver at the correct Microsoft Entra control boundary.
Answer D is correct because This verification step confirms that the selected control changes effective behavior for the intended pilot and exposes policy, assignment, propagation, or evidence problems before wider rollout.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is recover access during policy or federation outage. It does not implement or verify route approval to authorized approver in this scenario.
Answer C is incorrect because This action is appropriate when the requirement is diagnosis of activation blocked by role settings. It does not implement or verify route approval to authorized approver in this scenario.
Answer E is incorrect because This action is appropriate when the requirement is diagnosis of Azure RBAC authority versus Entra role authority. It does not implement or verify route approval to authorized approver in this scenario.
Answer F is incorrect because This action is appropriate when the requirement is identify persistent privilege through PIM reports. It does not implement or verify route approval to authorized approver in this scenario.
Question 19
A troubleshooting review of a privileged role activation with MFA and approval confirms that the next action must address: handling of request expiration without assuming activation. The correction must address the named control boundary rather than reset unrelated tenant settings. Which action best satisfies the requirement?
Correct Answer: A
Correct Answer
Answer A is correct because This action directly provides handling of request expiration without assuming activation. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer B is incorrect because This action is appropriate when the requirement is the appropriate eligible versus active Entra role assignment. The scenario instead requires handling of request expiration without assuming activation, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is export of audit evidence for specific time window. The scenario instead requires handling of request expiration without assuming activation, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is correct interpretation of inherited resource-role assignment scope. The scenario instead requires handling of request expiration without assuming activation, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is a clear distinction between permanent assignment and eligible schedule. The scenario instead requires handling of request expiration without assuming activation, so this option would solve an adjacent identity problem rather than the documented gap.
Question 20
A staged rollout of a privileged role activation with MFA and approval cannot proceed until the team can demonstrate: resolution of denied activation under separation-of-duties constraint. No new standing administrator privilege may be introduced. Which action best satisfies the requirement?
Correct Answer: E
Correct Answer
Answer E is correct because This action directly provides resolution of denied activation under separation-of-duties constraint. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is a design that addresses emergency access independent of normal dependencies. The scenario instead requires resolution of denied activation under separation-of-duties constraint, so this option would solve an adjacent identity problem rather than the documented gap.
Answer B is incorrect because This action is appropriate when the requirement is onboard Azure resource scope for PIM management. The scenario instead requires resolution of denied activation under separation-of-duties constraint, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is removal of excessive active assignment after PIM validation. The scenario instead requires resolution of denied activation under separation-of-duties constraint, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is the required setting for assignment duration for contractor administrator. The scenario instead requires resolution of denied activation under separation-of-duties constraint, so this option would solve an adjacent identity problem rather than the documented gap.
Question 21
The team compares supported controls for a privileged role activation with MFA and approval. The deciding condition is: traceability of privileged action to activation history. General network connectivity outside the identity path is already verified. Which action best satisfies the requirement?
Correct Answer: C
Correct Answer
Answer C is correct because This action directly provides traceability of privileged action to activation history. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is correct configuration of eligible group membership for privileged access. The scenario instead requires traceability of privileged action to activation history, so this option would solve an adjacent identity problem rather than the documented gap.
Answer B is incorrect because This action is appropriate when the requirement is protection of emergency credentials using current guidance. The scenario instead requires traceability of privileged action to activation history, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is enforcement of MFA or authentication context at activation. The scenario instead requires traceability of privileged action to activation history, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is the appropriate eligible role at least required Azure scope. The scenario instead requires traceability of privileged action to activation history, so this option would solve an adjacent identity problem rather than the documented gap.
Question 22
The identity architect is reviewing a privileged role activation with MFA and approval. The required outcome is: a clear distinction between assignment change and activation event. Resource permissions outside the identity control are already correct. Which action best satisfies the requirement?
Correct Answer: D
Correct Answer
Answer D is correct because This action directly provides a clear distinction between assignment change and activation event. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is the required setting for justification and notification requirements. The scenario instead requires a clear distinction between assignment change and activation event, so this option would solve an adjacent identity problem rather than the documented gap.
Answer B is incorrect because This action is appropriate when the requirement is monitoring of and test emergency account usage. The scenario instead requires a clear distinction between assignment change and activation event, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is correct configuration of eligible ownership separately from membership. The scenario instead requires a clear distinction between assignment change and activation event, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is the required setting for resource-role activation duration and approval. The scenario instead requires a clear distinction between assignment change and activation event, so this option would solve an adjacent identity problem rather than the documented gap.
Question 23
The change owner has limited the remediation for a privileged-access workflow to this outcome: identify persistent privilege through PIM reports. The administrator must verify the effective result from Microsoft Entra evidence. Which action best satisfies the requirement?
Correct Answer: B
Correct Answer
Answer B is correct because This action directly provides identify persistent privilege through PIM reports. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is recover access during policy or federation outage. The scenario instead requires identify persistent privilege through PIM reports, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is diagnosis of Azure RBAC authority versus Entra role authority. The scenario instead requires identify persistent privilege through PIM reports, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is assessment of group type and role-assignable constraints. The scenario instead requires identify persistent privilege through PIM reports, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is diagnosis of activation blocked by role settings. The scenario instead requires identify persistent privilege through PIM reports, so this option would solve an adjacent identity problem rather than the documented gap.
Question 24
A change request for an auditor reviewing privileged assignment and activation history will be accepted only when the following is true: export of audit evidence for specific time window. The organization requires a supported Microsoft-managed control. Choose TWO actions that together implement and verify the requirement.
Correct Answers: E, F
Correct Answers
Answer E is correct because This verification step confirms that the selected control changes effective behavior for the intended pilot and exposes policy, assignment, propagation, or evidence problems before wider rollout.
Answer F is correct because This action directly provides export of audit evidence for specific time window at the correct Microsoft Entra control boundary.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is the appropriate eligible versus active Entra role assignment. It does not implement or verify export of audit evidence for specific time window in this scenario.
Answer B is incorrect because This action is appropriate when the requirement is a clear distinction between permanent assignment and eligible schedule. It does not implement or verify export of audit evidence for specific time window in this scenario.
Answer C is incorrect because This action is appropriate when the requirement is diagnosis of activation propagation versus resource permission. It does not implement or verify export of audit evidence for specific time window in this scenario.
Answer D is incorrect because This action is appropriate when the requirement is correct interpretation of inherited resource-role assignment scope. It does not implement or verify export of audit evidence for specific time window in this scenario.
Question 25
The implementation of two emergency access accounts that must work during a control-plane outage is complete except for this requirement: a design that addresses emergency access independent of normal dependencies. The current population and assignment scope must be preserved. Which action best satisfies the requirement?
Correct Answer: A
Correct Answer
Answer A is correct because This option directly tests design emergency access independent of normal dependencies at the control boundary named in the scenario. It addresses that specific stage or distinction rather than collapsing it into a neighboring workflow step.
Incorrect Answers
Answer B is incorrect because This action is appropriate when the requirement is removal of excessive active assignment after PIM validation. The scenario instead requires a design that addresses emergency access independent of normal dependencies, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is submit activation request with required evidence. The scenario instead requires a design that addresses emergency access independent of normal dependencies, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is onboard Azure resource scope for PIM management. The scenario instead requires a design that addresses emergency access independent of normal dependencies, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is the required setting for assignment duration for contractor administrator. The scenario instead requires a design that addresses emergency access independent of normal dependencies, so this option would solve an adjacent identity problem rather than the documented gap.
Question 26
The support team has ruled out unrelated causes in two emergency access accounts that must work during a control-plane outage. The remaining issue is: protection of emergency credentials using current guidance. Existing working access outside the stated scope must remain unchanged. Which action best satisfies the requirement?
Correct Answer: B
Correct Answer
Answer B is correct because This option directly tests protect emergency credentials using current guidance at the control boundary named in the scenario. It addresses that specific stage or distinction rather than collapsing it into a neighboring workflow step.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is route approval to authorized approver. The scenario instead requires protection of emergency credentials using current guidance, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is enforcement of MFA or authentication context at activation. The scenario instead requires protection of emergency credentials using current guidance, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is correct configuration of eligible group membership for privileged access. The scenario instead requires protection of emergency credentials using current guidance, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is the appropriate eligible role at least required Azure scope. The scenario instead requires protection of emergency credentials using current guidance, so this option would solve an adjacent identity problem rather than the documented gap.
Question 27
A readiness check of two emergency access accounts that must work during a control-plane outage leaves one unresolved condition: monitoring of and test emergency account usage. The change will be piloted before broader enforcement. Which action best satisfies the requirement?
Correct Answer: C
Correct Answer
Answer C is correct because This option directly tests monitor and test emergency account usage at the control boundary named in the scenario. It addresses that specific stage or distinction rather than collapsing it into a neighboring workflow step.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is the required setting for resource-role activation duration and approval. The scenario instead requires monitoring of and test emergency account usage, so this option would solve an adjacent identity problem rather than the documented gap.
Answer B is incorrect because This action is appropriate when the requirement is handling of request expiration without assuming activation. The scenario instead requires monitoring of and test emergency account usage, so this option would solve an adjacent identity problem rather than the documented gap.
Answer D is incorrect because This action is appropriate when the requirement is the required setting for justification and notification requirements. The scenario instead requires monitoring of and test emergency account usage, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is correct configuration of eligible ownership separately from membership. The scenario instead requires monitoring of and test emergency account usage, so this option would solve an adjacent identity problem rather than the documented gap.
Question 28
Testing of a privileged-access workflow is successful except for this condition: recover access during policy or federation outage. The tenant has the licensing required for the named capability. Which action best satisfies the requirement?
Correct Answer: D
Correct Answer
Answer D is correct because This action directly provides recover access during policy or federation outage. It changes the control that owns the stated requirement while preserving unrelated access and can be verified with Microsoft Entra evidence.
Incorrect Answers
Answer A is incorrect because This action is appropriate when the requirement is resolution of denied activation under separation-of-duties constraint. The scenario instead requires recover access during policy or federation outage, so this option would solve an adjacent identity problem rather than the documented gap.
Answer B is incorrect because This action is appropriate when the requirement is diagnosis of Azure RBAC authority versus Entra role authority. The scenario instead requires recover access during policy or federation outage, so this option would solve an adjacent identity problem rather than the documented gap.
Answer C is incorrect because This action is appropriate when the requirement is diagnosis of activation blocked by role settings. The scenario instead requires recover access during policy or federation outage, so this option would solve an adjacent identity problem rather than the documented gap.
Answer E is incorrect because This action is appropriate when the requirement is assessment of group type and role-assignable constraints. The scenario instead requires recover access during policy or federation outage, so this option would solve an adjacent identity problem rather than the documented gap.
Popular posts
Recent Posts
