Microsoft SC-300 Hybrid Synchronization and Authentication Practice Test

 

Topic 04 covers hybrid synchronization and authentication for the Microsoft Certified: Identity and Access Administrator Associate certification. These original practice questions apply the verified SC-300 objectives to practical decisions and troubleshooting. Select one answer unless a fixed number is requested. For broader preparation, visit the SC-300 Exam Dumps page. Each option includes an explanation of the relevant behavior and scenario constraints.

Question 1

Testing of a Microsoft Entra Connect Sync deployment is successful except for this condition: the server-based hybrid synchronization path for required topology and features. The organization requires a supported Microsoft-managed control. Which action best satisfies the requirement?

  1. Configure the Cloud Sync scoping and attribute mappings for the intended source population.
  2. Configure and validate a Microsoft Entra Connect Sync staging server for controlled failover.
  3. Use Microsoft Entra Connect Sync for the hybrid synchronization topology.
  4. Configure the synchronization scope and attribute filtering for only the intended objects.
  5. Verify password hash synchronization timing and the latest sync result before treating the password as invalid.

Correct Answer: C

 

Correct Answer

Answer C is correct because This action directly implements the server-based hybrid synchronization path for required topology and features. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is scope and attribute mapping for source population. In this scenario, however, the decisive requirement is the server-based hybrid synchronization path for required topology and features, so it would solve a neighboring identity problem rather than the one described.

Answer B is incorrect because This action is appropriate when the requirement is staging server and controlled failover. In this scenario, however, the decisive requirement is the server-based hybrid synchronization path for required topology and features, so it would solve a neighboring identity problem rather than the one described.

Answer D is incorrect because This action is appropriate when the requirement is synchronization to intended users and attributes. In this scenario, however, the decisive requirement is the server-based hybrid synchronization path for required topology and features, so it would solve a neighboring identity problem rather than the one described.

Answer E is incorrect because This action is appropriate when the requirement is password-change propagation delay. In this scenario, however, the decisive requirement is the server-based hybrid synchronization path for required topology and features, so it would solve a neighboring identity problem rather than the one described.

 

Question 2

A production issue involving the hybrid identity design has been narrowed to this requirement: synchronization to intended users and attributes. The current population scope must be preserved. Which action best satisfies the requirement?

  1. Configure the synchronization scope and attribute filtering for only the intended objects.
  2. Use provisioning-agent health and provisioning logs to isolate the connectivity or mapping failure.
  3. Treat account synchronization and password validation as separate functions and troubleshoot each independently.
  4. Resolve the source anchor or duplicate attribute conflict before forcing another synchronization cycle.
  5. Separate synchronization health from authentication health and troubleshoot the failing layer.

Correct Answer: A

 

Correct Answer

Answer A is correct because This action directly implements synchronization to intended users and attributes. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Incorrect Answers

Answer B is incorrect because This action is appropriate when the requirement is agent connectivity or provisioning failure. In this scenario, however, the decisive requirement is synchronization to intended users and attributes, so it would solve a neighboring identity problem rather than the one described.

Answer C is incorrect because This action is appropriate when the requirement is synchronized account state from password validation. In this scenario, however, the decisive requirement is synchronization to intended users and attributes, so it would solve a neighboring identity problem rather than the one described.

Answer D is incorrect because This action is appropriate when the requirement is source-anchor or duplicate-attribute synchronization conflict. In this scenario, however, the decisive requirement is synchronization to intended users and attributes, so it would solve a neighboring identity problem rather than the one described.

Answer E is incorrect because This action is appropriate when the requirement is synchronization engine versus sign-in failure. In this scenario, however, the decisive requirement is synchronization to intended users and attributes, so it would solve a neighboring identity problem rather than the one described.

 

Question 3

A staged rollout of a synchronization conflict involving duplicate attributes cannot proceed until the team can demonstrate: source-anchor or duplicate-attribute synchronization conflict. No new standing administrator privilege may be introduced. Which action best satisfies the requirement?

  1. Enable password hash synchronization when the required protection depends on synchronized password-hash analysis.
  2. Resolve the source anchor or duplicate attribute conflict before forcing another synchronization cycle.
  3. Configure and validate a Microsoft Entra Connect Sync staging server for controlled failover.
  4. Use Microsoft Entra Cloud Sync when its cloud-managed agent model meets the stated feature requirements.
  5. Define one authoritative synchronization owner for each object during coexistence or migration.

Correct Answer: B

 

Correct Answer

Answer B is correct because This action directly implements source-anchor or duplicate-attribute synchronization conflict. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is hash sync for required detection capability. In this scenario, however, the decisive requirement is source-anchor or duplicate-attribute synchronization conflict, so it would solve a neighboring identity problem rather than the one described.

Answer C is incorrect because This action is appropriate when the requirement is staging server and controlled failover. In this scenario, however, the decisive requirement is source-anchor or duplicate-attribute synchronization conflict, so it would solve a neighboring identity problem rather than the one described.

Answer D is incorrect because This action is appropriate when the requirement is the cloud-managed provisioning-agent synchronization path against stated feature requirements. In this scenario, however, the decisive requirement is source-anchor or duplicate-attribute synchronization conflict, so it would solve a neighboring identity problem rather than the one described.

Answer E is incorrect because This action is appropriate when the requirement is coexistence or migration without duplicate ownership. In this scenario, however, the decisive requirement is source-anchor or duplicate-attribute synchronization conflict, so it would solve a neighboring identity problem rather than the one described.

 

Question 4

The support team has ruled out unrelated causes in a Connect Sync staging-server design. The remaining issue is: staging server and controlled failover. General network connectivity outside the identity path is already verified. Which action best satisfies the requirement?

  1. Deploy redundant Cloud Sync provisioning agents with outbound connectivity to the required directories and Microsoft Entra.
  2. Separate synchronization health from authentication health and troubleshoot the failing layer.
  3. Plan password hash synchronization as a tested fallback and document the explicit cutover procedure.
  4. Enable password hash synchronization so Microsoft Entra can validate cloud sign-ins independently of on-premises agents.
  5. Configure and validate a Microsoft Entra Connect Sync staging server for controlled failover.

Correct Answer: E

 

Correct Answer

Answer E is correct because This action directly implements staging server and controlled failover. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is place provisioning agents for network and availability needs. In this scenario, however, the decisive requirement is staging server and controlled failover, so it would solve a neighboring identity problem rather than the one described.

Answer B is incorrect because This action is appropriate when the requirement is synchronization engine versus sign-in failure. In this scenario, however, the decisive requirement is staging server and controlled failover, so it would solve a neighboring identity problem rather than the one described.

Answer C is incorrect because This action is appropriate when the requirement is hash-sync fallback with explicit activation process. In this scenario, however, the decisive requirement is staging server and controlled failover, so it would solve a neighboring identity problem rather than the one described.

Answer D is incorrect because This action is appropriate when the requirement is cloud-side password validation from synchronized hashes for cloud validation resilience. In this scenario, however, the decisive requirement is staging server and controlled failover, so it would solve a neighboring identity problem rather than the one described.

 

Question 5

Before expanding the hybrid identity design, the administrator must satisfy this condition: synchronization engine versus sign-in failure. Existing working access outside the stated scope must remain unchanged. Which action best satisfies the requirement?

  1. Separate synchronization health from authentication health and troubleshoot the failing layer.
  2. Verify password hash synchronization timing and the latest sync result before treating the password as invalid.
  3. Use pass-through authentication when password validation must occur against on-premises Active Directory.
  4. Configure the Cloud Sync scoping and attribute mappings for the intended source population.
  5. Use Microsoft Entra Cloud Sync when its cloud-managed agent model meets the stated feature requirements.

Correct Answer: A

 

Correct Answer

Answer A is correct because This action directly implements synchronization engine versus sign-in failure. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Incorrect Answers

Answer B is incorrect because This action is appropriate when the requirement is password-change propagation delay. In this scenario, however, the decisive requirement is synchronization engine versus sign-in failure, so it would solve a neighboring identity problem rather than the one described.

Answer C is incorrect because This action is appropriate when the requirement is real-time on-premises password validation validation for on-premises policy requirement. In this scenario, however, the decisive requirement is synchronization engine versus sign-in failure, so it would solve a neighboring identity problem rather than the one described.

Answer D is incorrect because This action is appropriate when the requirement is scope and attribute mapping for source population. In this scenario, however, the decisive requirement is synchronization engine versus sign-in failure, so it would solve a neighboring identity problem rather than the one described.

Answer E is incorrect because This action is appropriate when the requirement is the cloud-managed provisioning-agent synchronization path against stated feature requirements. In this scenario, however, the decisive requirement is synchronization engine versus sign-in failure, so it would solve a neighboring identity problem rather than the one described.

 

Question 6

The current configuration of a Microsoft Entra Cloud Sync deployment is otherwise acceptable. The unresolved requirement is: the cloud-managed provisioning-agent synchronization path against stated feature requirements. The change will be piloted before broader enforcement. Choose TWO actions that together implement and verify the requirement.

  1. Confirm synchronization and authentication health with the relevant Entra Connect/Cloud Sync health data before broad rollout.
  2. Treat account synchronization and password validation as separate functions and troubleshoot each independently.
  3. Use Microsoft Entra Cloud Sync when its cloud-managed agent model meets the stated feature requirements.
  4. Deploy multiple pass-through authentication agents in separate failure domains.
  5. Use provisioning-agent health and provisioning logs to isolate the connectivity or mapping failure.
  6. Deploy redundant Cloud Sync provisioning agents with outbound connectivity to the required directories and Microsoft Entra.

Correct Answers: A, C

 

Correct Answers

Answer A is correct because This verification step confirms that the selected control actually changes effective behavior for the targeted pilot and exposes policy, assignment, or propagation problems before wider rollout.

Answer C is correct because This action directly implements the cloud-managed provisioning-agent synchronization path against stated feature requirements. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Incorrect Answers

Answer B is incorrect because This action is appropriate when the requirement is synchronized account state from password validation. In this scenario, however, the decisive requirement is the cloud-managed provisioning-agent synchronization path against stated feature requirements, so it would solve a neighboring identity problem rather than the one described.

Answer D is incorrect because This action is appropriate when the requirement is redundant agents across failure domains. In this scenario, however, the decisive requirement is the cloud-managed provisioning-agent synchronization path against stated feature requirements, so it would solve a neighboring identity problem rather than the one described.

Answer E is incorrect because This action is appropriate when the requirement is agent connectivity or provisioning failure. In this scenario, however, the decisive requirement is the cloud-managed provisioning-agent synchronization path against stated feature requirements, so it would solve a neighboring identity problem rather than the one described.

Answer F is incorrect because This action is appropriate when the requirement is place provisioning agents for network and availability needs. In this scenario, however, the decisive requirement is the cloud-managed provisioning-agent synchronization path against stated feature requirements, so it would solve a neighboring identity problem rather than the one described.

 

Question 7

A change request for a Cloud Sync provisioning-agent deployment will be accepted only when the following is true: provisioning-agent placement that meets the network and availability requirements. The tenant has the licensing required for the named capability. Which action best satisfies the requirement?

  1. Enable password hash synchronization when the required protection depends on synchronized password-hash analysis.
  2. Deploy redundant Cloud Sync provisioning agents with outbound connectivity to the required directories and Microsoft Entra.
  3. Configure the Cloud Sync scoping and attribute mappings for the intended source population.
  4. Define one authoritative synchronization owner for each object during coexistence or migration.
  5. Use agent diagnostics to distinguish on-premises directory reachability from outbound Microsoft Entra connectivity.

Correct Answer: B

 

Correct Answer

Answer B is correct because This action directly implements place provisioning agents for network and availability needs. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is hash sync for required detection capability. In this scenario, however, the decisive requirement is place provisioning agents for network and availability needs, so it would solve a neighboring identity problem rather than the one described.

Answer C is incorrect because This action is appropriate when the requirement is scope and attribute mapping for source population. In this scenario, however, the decisive requirement is place provisioning agents for network and availability needs, so it would solve a neighboring identity problem rather than the one described.

Answer D is incorrect because This action is appropriate when the requirement is coexistence or migration without duplicate ownership. In this scenario, however, the decisive requirement is place provisioning agents for network and availability needs, so it would solve a neighboring identity problem rather than the one described.

Answer E is incorrect because This action is appropriate when the requirement is directory connectivity versus cloud connectivity failure. In this scenario, however, the decisive requirement is place provisioning agents for network and availability needs, so it would solve a neighboring identity problem rather than the one described.

 

Question 8

A design review of the hybrid identity design identifies one remaining requirement: synchronization scope and attribute mappings for the intended source population. The administrator must verify the effective result from Microsoft Entra evidence. Which action best satisfies the requirement?

  1. Plan password hash synchronization as a tested fallback and document the explicit cutover procedure.
  2. Enable password hash synchronization so Microsoft Entra can validate cloud sign-ins independently of on-premises agents.
  3. Configure the Cloud Sync scoping and attribute mappings for the intended source population.
  4. Use an authentication method that checks the on-premises account during sign-in when real-time account state is required.
  5. Use provisioning-agent health and provisioning logs to isolate the connectivity or mapping failure.

Correct Answer: C

 

Correct Answer

Answer C is correct because This action directly implements scope and attribute mapping for source population. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is hash-sync fallback with explicit activation process. In this scenario, however, the decisive requirement is scope and attribute mapping for source population, so it would solve a neighboring identity problem rather than the one described.

Answer B is incorrect because This action is appropriate when the requirement is cloud-side password validation from synchronized hashes for cloud validation resilience. In this scenario, however, the decisive requirement is scope and attribute mapping for source population, so it would solve a neighboring identity problem rather than the one described.

Answer D is incorrect because This action is appropriate when the requirement is account-state enforcement at authentication time. In this scenario, however, the decisive requirement is scope and attribute mapping for source population, so it would solve a neighboring identity problem rather than the one described.

Answer E is incorrect because This action is appropriate when the requirement is agent connectivity or provisioning failure. In this scenario, however, the decisive requirement is scope and attribute mapping for source population, so it would solve a neighboring identity problem rather than the one described.

 

Question 9

The team is validating the hybrid identity design. The decisive requirement is: agent connectivity or provisioning failure. The organization requires a supported Microsoft-managed control. Which action best satisfies the requirement?

  1. Verify password hash synchronization timing and the latest sync result before treating the password as invalid.
  2. Treat additional PTA agents as automatic redundancy, while a switch to another authentication method is a separate planned fallback.
  3. Use provisioning-agent health and provisioning logs to isolate the connectivity or mapping failure.
  4. Define one authoritative synchronization owner for each object during coexistence or migration.
  5. Use pass-through authentication when password validation must occur against on-premises Active Directory.

Correct Answer: C

 

Correct Answer

Answer C is correct because This action directly implements agent connectivity or provisioning failure. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is password-change propagation delay. In this scenario, however, the decisive requirement is agent connectivity or provisioning failure, so it would solve a neighboring identity problem rather than the one described.

Answer B is incorrect because This action is appropriate when the requirement is manual fallback from automatic agent redundancy. In this scenario, however, the decisive requirement is agent connectivity or provisioning failure, so it would solve a neighboring identity problem rather than the one described.

Answer D is incorrect because This action is appropriate when the requirement is coexistence or migration without duplicate ownership. In this scenario, however, the decisive requirement is agent connectivity or provisioning failure, so it would solve a neighboring identity problem rather than the one described.

Answer E is incorrect because This action is appropriate when the requirement is real-time on-premises password validation validation for on-premises policy requirement. In this scenario, however, the decisive requirement is agent connectivity or provisioning failure, so it would solve a neighboring identity problem rather than the one described.

 

Question 10

The identity architect is reviewing the hybrid identity design. The required outcome is: coexistence or migration without duplicate ownership. The current population scope must be preserved. Which action best satisfies the requirement?

  1. Enable password hash synchronization so Microsoft Entra can validate cloud sign-ins independently of on-premises agents.
  2. Deploy multiple pass-through authentication agents in separate failure domains.
  3. Treat account synchronization and password validation as separate functions and troubleshoot each independently.
  4. Enable Microsoft Entra Seamless SSO for supported domain-joined intranet clients.
  5. Define one authoritative synchronization owner for each object during coexistence or migration.

Correct Answer: E

 

Correct Answer

Answer E is correct because This action directly implements coexistence or migration without duplicate ownership. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is cloud-side password validation from synchronized hashes for cloud validation resilience. In this scenario, however, the decisive requirement is coexistence or migration without duplicate ownership, so it would solve a neighboring identity problem rather than the one described.

Answer B is incorrect because This action is appropriate when the requirement is redundant agents across failure domains. In this scenario, however, the decisive requirement is coexistence or migration without duplicate ownership, so it would solve a neighboring identity problem rather than the one described.

Answer C is incorrect because This action is appropriate when the requirement is synchronized account state from password validation. In this scenario, however, the decisive requirement is coexistence or migration without duplicate ownership, so it would solve a neighboring identity problem rather than the one described.

Answer D is incorrect because This action is appropriate when the requirement is automatic intranet single sign-on for domain-joined clients for supported domain-joined clients. In this scenario, however, the decisive requirement is coexistence or migration without duplicate ownership, so it would solve a neighboring identity problem rather than the one described.

 

Question 11

Testing of a password hash synchronization design is successful except for this condition: cloud-side password validation from synchronized hashes for cloud validation resilience. No new standing administrator privilege may be introduced. Which action best satisfies the requirement?

  1. Enable password hash synchronization so Microsoft Entra can validate cloud sign-ins independently of on-premises agents.
  2. Validate intranet-zone configuration, Kerberos reachability, and the Seamless SSO computer account prerequisites.
  3. Use agent diagnostics to distinguish on-premises directory reachability from outbound Microsoft Entra connectivity.
  4. Verify password hash synchronization timing and the latest sync result before treating the password as invalid.
  5. Enable password hash synchronization when the required protection depends on synchronized password-hash analysis.

Correct Answer: A

 

Correct Answer

Answer A is correct because This action directly implements cloud-side password validation from synchronized hashes for cloud validation resilience. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Incorrect Answers

Answer B is incorrect because This action is appropriate when the requirement is intranet configuration and Kerberos prerequisites. In this scenario, however, the decisive requirement is cloud-side password validation from synchronized hashes for cloud validation resilience, so it would solve a neighboring identity problem rather than the one described.

Answer C is incorrect because This action is appropriate when the requirement is directory connectivity versus cloud connectivity failure. In this scenario, however, the decisive requirement is cloud-side password validation from synchronized hashes for cloud validation resilience, so it would solve a neighboring identity problem rather than the one described.

Answer D is incorrect because This action is appropriate when the requirement is password-change propagation delay. In this scenario, however, the decisive requirement is cloud-side password validation from synchronized hashes for cloud validation resilience, so it would solve a neighboring identity problem rather than the one described.

Answer E is incorrect because This action is appropriate when the requirement is hash sync for required detection capability. In this scenario, however, the decisive requirement is cloud-side password validation from synchronized hashes for cloud validation resilience, so it would solve a neighboring identity problem rather than the one described.

 

Question 12

A production issue involving a recently changed on-premises password has been narrowed to this requirement: password-change propagation delay. General network connectivity outside the identity path is already verified. Choose TWO actions that together implement and verify the requirement.

  1. Confirm synchronization and authentication health with the relevant Entra Connect/Cloud Sync health data before broad rollout.
  2. Verify password hash synchronization timing and the latest sync result before treating the password as invalid.
  3. Use an authentication method that checks the on-premises account during sign-in when real-time account state is required.
  4. Troubleshoot Seamless SSO/Kerberos configuration rather than the user password.
  5. Treat account synchronization and password validation as separate functions and troubleshoot each independently.
  6. Plan password hash synchronization as a tested fallback and document the explicit cutover procedure.

Correct Answers: A, B

 

Correct Answers

Answer A is correct because This verification step confirms that the selected control actually changes effective behavior for the targeted pilot and exposes policy, assignment, or propagation problems before wider rollout.

Answer B is correct because This action directly implements password-change propagation delay. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Incorrect Answers

Answer C is incorrect because This action is appropriate when the requirement is account-state enforcement at authentication time. In this scenario, however, the decisive requirement is password-change propagation delay, so it would solve a neighboring identity problem rather than the one described.

Answer D is incorrect because This action is appropriate when the requirement is sSO failure with otherwise successful password sign-in. In this scenario, however, the decisive requirement is password-change propagation delay, so it would solve a neighboring identity problem rather than the one described.

Answer E is incorrect because This action is appropriate when the requirement is synchronized account state from password validation. In this scenario, however, the decisive requirement is password-change propagation delay, so it would solve a neighboring identity problem rather than the one described.

Answer F is incorrect because This action is appropriate when the requirement is hash-sync fallback with explicit activation process. In this scenario, however, the decisive requirement is password-change propagation delay, so it would solve a neighboring identity problem rather than the one described.

 

Question 13

A staged rollout of the hybrid identity design cannot proceed until the team can demonstrate: synchronized account state from password validation. Existing working access outside the stated scope must remain unchanged. Which action best satisfies the requirement?

  1. Treat additional PTA agents as automatic redundancy, while a switch to another authentication method is a separate planned fallback.
  2. Use pass-through authentication when password validation must occur against on-premises Active Directory.
  3. Enable password hash synchronization when the required protection depends on synchronized password-hash analysis.
  4. Treat account synchronization and password validation as separate functions and troubleshoot each independently.
  5. Rotate the Seamless SSO Kerberos key on the required schedule and verify the resulting configuration.

Correct Answer: D

 

Correct Answer

Answer D is correct because This action directly implements synchronized account state from password validation. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is manual fallback from automatic agent redundancy. In this scenario, however, the decisive requirement is synchronized account state from password validation, so it would solve a neighboring identity problem rather than the one described.

Answer B is incorrect because This action is appropriate when the requirement is real-time on-premises password validation validation for on-premises policy requirement. In this scenario, however, the decisive requirement is synchronized account state from password validation, so it would solve a neighboring identity problem rather than the one described.

Answer C is incorrect because This action is appropriate when the requirement is hash sync for required detection capability. In this scenario, however, the decisive requirement is synchronized account state from password validation, so it would solve a neighboring identity problem rather than the one described.

Answer E is incorrect because This action is appropriate when the requirement is kerberos key rollover and operational verification. In this scenario, however, the decisive requirement is synchronized account state from password validation, so it would solve a neighboring identity problem rather than the one described.

 

Question 14

The support team has ruled out unrelated causes in a password hash synchronization design. The remaining issue is: hash sync for required detection capability. The change will be piloted before broader enforcement. Which action best satisfies the requirement?

  1. Enable password hash synchronization when the required protection depends on synchronized password-hash analysis.
  2. Deploy multiple pass-through authentication agents in separate failure domains.
  3. Plan password hash synchronization as a tested fallback and document the explicit cutover procedure.
  4. Enable Microsoft Entra Seamless SSO for supported domain-joined intranet clients.
  5. Migrate the pilot population from federation to the selected cloud authentication method before removing the federation dependency.

Correct Answer: A

 

Correct Answer

Answer A is correct because This action directly implements hash sync for required detection capability. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Incorrect Answers

Answer B is incorrect because This action is appropriate when the requirement is redundant agents across failure domains. In this scenario, however, the decisive requirement is hash sync for required detection capability, so it would solve a neighboring identity problem rather than the one described.

Answer C is incorrect because This action is appropriate when the requirement is hash-sync fallback with explicit activation process. In this scenario, however, the decisive requirement is hash sync for required detection capability, so it would solve a neighboring identity problem rather than the one described.

Answer D is incorrect because This action is appropriate when the requirement is automatic intranet single sign-on for domain-joined clients for supported domain-joined clients. In this scenario, however, the decisive requirement is hash sync for required detection capability, so it would solve a neighboring identity problem rather than the one described.

Answer E is incorrect because This action is appropriate when the requirement is target cloud authentication after federation assessment. In this scenario, however, the decisive requirement is hash sync for required detection capability, so it would solve a neighboring identity problem rather than the one described.

 

Question 15

Before expanding the hybrid identity design, the administrator must satisfy this condition: hash-sync fallback with explicit activation process. The tenant has the licensing required for the named capability. Which action best satisfies the requirement?

  1. Use staged rollout with a deliberately scoped pilot population and documented exceptions.
  2. Use pass-through authentication when password validation must occur against on-premises Active Directory.
  3. Plan password hash synchronization as a tested fallback and document the explicit cutover procedure.
  4. Validate intranet-zone configuration, Kerberos reachability, and the Seamless SSO computer account prerequisites.
  5. Use agent diagnostics to distinguish on-premises directory reachability from outbound Microsoft Entra connectivity.

Correct Answer: C

 

Correct Answer

Answer C is correct because This action directly implements hash-sync fallback with explicit activation process. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is staged rollout and pilot exceptions. In this scenario, however, the decisive requirement is hash-sync fallback with explicit activation process, so it would solve a neighboring identity problem rather than the one described.

Answer B is incorrect because This action is appropriate when the requirement is real-time on-premises password validation validation for on-premises policy requirement. In this scenario, however, the decisive requirement is hash-sync fallback with explicit activation process, so it would solve a neighboring identity problem rather than the one described.

Answer D is incorrect because This action is appropriate when the requirement is intranet configuration and Kerberos prerequisites. In this scenario, however, the decisive requirement is hash-sync fallback with explicit activation process, so it would solve a neighboring identity problem rather than the one described.

Answer E is incorrect because This action is appropriate when the requirement is directory connectivity versus cloud connectivity failure. In this scenario, however, the decisive requirement is hash-sync fallback with explicit activation process, so it would solve a neighboring identity problem rather than the one described.

 

Question 16

The current configuration of a pass-through authentication deployment is otherwise acceptable. The unresolved requirement is: real-time on-premises password validation that satisfies the stated policy requirement. The administrator must verify the effective result from Microsoft Entra evidence. Which action best satisfies the requirement?

  1. Use pass-through authentication when password validation must occur against on-premises Active Directory.
  2. Inventory and deliberately migrate claims-dependent applications before changing the federation authority.
  3. Troubleshoot Seamless SSO/Kerberos configuration rather than the user password.
  4. Deploy multiple pass-through authentication agents in separate failure domains.
  5. Use an authentication method that checks the on-premises account during sign-in when real-time account state is required.

Correct Answer: A

 

Correct Answer

Answer A is correct because This action directly implements real-time on-premises password validation validation for on-premises policy requirement. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Incorrect Answers

Answer B is incorrect because This action is appropriate when the requirement is claims-dependent application authentication deliberately. In this scenario, however, the decisive requirement is real-time on-premises password validation validation for on-premises policy requirement, so it would solve a neighboring identity problem rather than the one described.

Answer C is incorrect because This action is appropriate when the requirement is sSO failure with otherwise successful password sign-in. In this scenario, however, the decisive requirement is real-time on-premises password validation validation for on-premises policy requirement, so it would solve a neighboring identity problem rather than the one described.

Answer D is incorrect because This action is appropriate when the requirement is redundant agents across failure domains. In this scenario, however, the decisive requirement is real-time on-premises password validation validation for on-premises policy requirement, so it would solve a neighboring identity problem rather than the one described.

Answer E is incorrect because This action is appropriate when the requirement is account-state enforcement at authentication time. In this scenario, however, the decisive requirement is real-time on-premises password validation validation for on-premises policy requirement, so it would solve a neighboring identity problem rather than the one described.

 

Question 17

A change request for pass-through authentication agents in separate failure domains will be accepted only when the following is true: redundant agents across failure domains. The organization requires a supported Microsoft-managed control. Which action best satisfies the requirement?

  1. Rotate the Seamless SSO Kerberos key on the required schedule and verify the resulting configuration.
  2. Use agent diagnostics to distinguish on-premises directory reachability from outbound Microsoft Entra connectivity.
  3. Document rollback, DNS/federation changes, and dependency removal before the production cutover.
  4. Treat additional PTA agents as automatic redundancy, while a switch to another authentication method is a separate planned fallback.
  5. Deploy multiple pass-through authentication agents in separate failure domains.

Correct Answer: E

 

Correct Answer

Answer E is correct because This action directly implements redundant agents across failure domains. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is kerberos key rollover and operational verification. In this scenario, however, the decisive requirement is redundant agents across failure domains, so it would solve a neighboring identity problem rather than the one described.

Answer B is incorrect because This action is appropriate when the requirement is directory connectivity versus cloud connectivity failure. In this scenario, however, the decisive requirement is redundant agents across failure domains, so it would solve a neighboring identity problem rather than the one described.

Answer C is incorrect because This action is appropriate when the requirement is cutover rollback and federation dependency removal. In this scenario, however, the decisive requirement is redundant agents across failure domains, so it would solve a neighboring identity problem rather than the one described.

Answer D is incorrect because This action is appropriate when the requirement is manual fallback from automatic agent redundancy. In this scenario, however, the decisive requirement is redundant agents across failure domains, so it would solve a neighboring identity problem rather than the one described.

 

Question 18

A design review of a pass-through authentication sign-in path identifies one remaining requirement: directory connectivity versus cloud connectivity failure. The current population scope must be preserved. Choose TWO actions that together implement and verify the requirement.

  1. Use an authentication method that checks the on-premises account during sign-in when real-time account state is required.
  2. Use agent diagnostics to distinguish on-premises directory reachability from outbound Microsoft Entra connectivity.
  3. Use the Microsoft Entra Connect Health view that corresponds to the failing synchronization or authentication component.
  4. Migrate the pilot population from federation to the selected cloud authentication method before removing the federation dependency.
  5. Confirm synchronization and authentication health with the relevant Entra Connect/Cloud Sync health data before broad rollout.
  6. Enable Microsoft Entra Seamless SSO for supported domain-joined intranet clients.

Correct Answers: B, E

 

Correct Answers

Answer B is correct because This action directly implements directory connectivity versus cloud connectivity failure. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Answer E is correct because This verification step confirms that the selected control actually changes effective behavior for the targeted pilot and exposes policy, assignment, or propagation problems before wider rollout.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is account-state enforcement at authentication time. In this scenario, however, the decisive requirement is directory connectivity versus cloud connectivity failure, so it would solve a neighboring identity problem rather than the one described.

Answer C is incorrect because This action is appropriate when the requirement is connect Health component for observed failure. In this scenario, however, the decisive requirement is directory connectivity versus cloud connectivity failure, so it would solve a neighboring identity problem rather than the one described.

Answer D is incorrect because This action is appropriate when the requirement is target cloud authentication after federation assessment. In this scenario, however, the decisive requirement is directory connectivity versus cloud connectivity failure, so it would solve a neighboring identity problem rather than the one described.

Answer F is incorrect because This action is appropriate when the requirement is automatic intranet single sign-on for domain-joined clients for supported domain-joined clients. In this scenario, however, the decisive requirement is directory connectivity versus cloud connectivity failure, so it would solve a neighboring identity problem rather than the one described.

 

Question 19

The team is validating a synchronized account whose on-premises state changed. The decisive requirement is: account-state enforcement at authentication time. No new standing administrator privilege may be introduced. Which action best satisfies the requirement?

  1. Validate intranet-zone configuration, Kerberos reachability, and the Seamless SSO computer account prerequisites.
  2. Use an authentication method that checks the on-premises account during sign-in when real-time account state is required.
  3. Treat additional PTA agents as automatic redundancy, while a switch to another authentication method is a separate planned fallback.
  4. Verify Connect Health agent registration, service connectivity, and required permissions before relying on its telemetry.
  5. Use staged rollout with a deliberately scoped pilot population and documented exceptions.

Correct Answer: B

 

Correct Answer

Answer B is correct because This action directly implements account-state enforcement at authentication time. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is intranet configuration and Kerberos prerequisites. In this scenario, however, the decisive requirement is account-state enforcement at authentication time, so it would solve a neighboring identity problem rather than the one described.

Answer C is incorrect because This action is appropriate when the requirement is manual fallback from automatic agent redundancy. In this scenario, however, the decisive requirement is account-state enforcement at authentication time, so it would solve a neighboring identity problem rather than the one described.

Answer D is incorrect because This action is appropriate when the requirement is missing telemetry or agent registration. In this scenario, however, the decisive requirement is account-state enforcement at authentication time, so it would solve a neighboring identity problem rather than the one described.

Answer E is incorrect because This action is appropriate when the requirement is staged rollout and pilot exceptions. In this scenario, however, the decisive requirement is account-state enforcement at authentication time, so it would solve a neighboring identity problem rather than the one described.

 

Question 20

The identity architect is reviewing the hybrid identity design. The required outcome is: manual fallback from automatic agent redundancy. General network connectivity outside the identity path is already verified. Which action best satisfies the requirement?

  1. Enable Microsoft Entra Seamless SSO for supported domain-joined intranet clients.
  2. Inventory and deliberately migrate claims-dependent applications before changing the federation authority.
  3. Use the alert category and affected component to separate synchronization faults from authentication faults.
  4. Treat additional PTA agents as automatic redundancy, while a switch to another authentication method is a separate planned fallback.
  5. Troubleshoot Seamless SSO/Kerberos configuration rather than the user password.

Correct Answer: D

 

Correct Answer

Answer D is correct because This action directly implements manual fallback from automatic agent redundancy. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is automatic intranet single sign-on for domain-joined clients for supported domain-joined clients. In this scenario, however, the decisive requirement is manual fallback from automatic agent redundancy, so it would solve a neighboring identity problem rather than the one described.

Answer B is incorrect because This action is appropriate when the requirement is claims-dependent application authentication deliberately. In this scenario, however, the decisive requirement is manual fallback from automatic agent redundancy, so it would solve a neighboring identity problem rather than the one described.

Answer C is incorrect because This action is appropriate when the requirement is synchronization alerts versus authentication alerts. In this scenario, however, the decisive requirement is manual fallback from automatic agent redundancy, so it would solve a neighboring identity problem rather than the one described.

Answer E is incorrect because This action is appropriate when the requirement is sSO failure with otherwise successful password sign-in. In this scenario, however, the decisive requirement is manual fallback from automatic agent redundancy, so it would solve a neighboring identity problem rather than the one described.

 

Question 21

Testing of domain-joined Windows clients using seamless SSO is successful except for this condition: automatic intranet single sign-on for supported domain-joined clients. Existing working access outside the stated scope must remain unchanged. Which action best satisfies the requirement?

  1. Enable Microsoft Entra Seamless SSO for supported domain-joined intranet clients.
  2. Validate intranet-zone configuration, Kerberos reachability, and the Seamless SSO computer account prerequisites.
  3. Document rollback, DNS/federation changes, and dependency removal before the production cutover.
  4. Rotate the Seamless SSO Kerberos key on the required schedule and verify the resulting configuration.
  5. Prioritize the failing component and user impact indicated by Connect Health evidence instead of restarting every hybrid service.

Correct Answer: A

 

Correct Answer

Answer A is correct because This action directly implements automatic intranet single sign-on for domain-joined clients for supported domain-joined clients. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Incorrect Answers

Answer B is incorrect because This action is appropriate when the requirement is intranet configuration and Kerberos prerequisites. In this scenario, however, the decisive requirement is automatic intranet single sign-on for domain-joined clients for supported domain-joined clients, so it would solve a neighboring identity problem rather than the one described.

Answer C is incorrect because This action is appropriate when the requirement is cutover rollback and federation dependency removal. In this scenario, however, the decisive requirement is automatic intranet single sign-on for domain-joined clients for supported domain-joined clients, so it would solve a neighboring identity problem rather than the one described.

Answer D is incorrect because This action is appropriate when the requirement is kerberos key rollover and operational verification. In this scenario, however, the decisive requirement is automatic intranet single sign-on for domain-joined clients for supported domain-joined clients, so it would solve a neighboring identity problem rather than the one described.

Answer E is incorrect because This action is appropriate when the requirement is remediation using health evidence. In this scenario, however, the decisive requirement is automatic intranet single sign-on for domain-joined clients for supported domain-joined clients, so it would solve a neighboring identity problem rather than the one described.

 

Question 22

A production issue involving a seamless SSO deployment has been narrowed to this requirement: intranet configuration and Kerberos prerequisites. The change will be piloted before broader enforcement. Which action best satisfies the requirement?

  1. Troubleshoot Seamless SSO/Kerberos configuration rather than the user password.
  2. Use Microsoft Entra Connect Sync for the hybrid synchronization topology.
  3. Validate intranet-zone configuration, Kerberos reachability, and the Seamless SSO computer account prerequisites.
  4. Use the Microsoft Entra Connect Health view that corresponds to the failing synchronization or authentication component.
  5. Migrate the pilot population from federation to the selected cloud authentication method before removing the federation dependency.

Correct Answer: C

 

Correct Answer

Answer C is correct because This action directly implements intranet configuration and Kerberos prerequisites. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is sSO failure with otherwise successful password sign-in. In this scenario, however, the decisive requirement is intranet configuration and Kerberos prerequisites, so it would solve a neighboring identity problem rather than the one described.

Answer B is incorrect because This action is appropriate when the requirement is the server-based hybrid synchronization path for required topology and features. In this scenario, however, the decisive requirement is intranet configuration and Kerberos prerequisites, so it would solve a neighboring identity problem rather than the one described.

Answer D is incorrect because This action is appropriate when the requirement is connect Health component for observed failure. In this scenario, however, the decisive requirement is intranet configuration and Kerberos prerequisites, so it would solve a neighboring identity problem rather than the one described.

Answer E is incorrect because This action is appropriate when the requirement is target cloud authentication after federation assessment. In this scenario, however, the decisive requirement is intranet configuration and Kerberos prerequisites, so it would solve a neighboring identity problem rather than the one described.

 

Question 23

A staged rollout of a domain-joined client whose password sign-in works but seamless SSO does not cannot proceed until the team can demonstrate: an SSO failure despite successful password sign-in. The tenant has the licensing required for the named capability. Which action best satisfies the requirement?

  1. Rotate the Seamless SSO Kerberos key on the required schedule and verify the resulting configuration.
  2. Use staged rollout with a deliberately scoped pilot population and documented exceptions.
  3. Configure the synchronization scope and attribute filtering for only the intended objects.
  4. Troubleshoot Seamless SSO/Kerberos configuration rather than the user password.
  5. Verify Connect Health agent registration, service connectivity, and required permissions before relying on its telemetry.

Correct Answer: D

 

Correct Answer

Answer D is correct because This action directly implements sSO failure with otherwise successful password sign-in. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is kerberos key rollover and operational verification. In this scenario, however, the decisive requirement is sSO failure with otherwise successful password sign-in, so it would solve a neighboring identity problem rather than the one described.

Answer B is incorrect because This action is appropriate when the requirement is staged rollout and pilot exceptions. In this scenario, however, the decisive requirement is sSO failure with otherwise successful password sign-in, so it would solve a neighboring identity problem rather than the one described.

Answer C is incorrect because This action is appropriate when the requirement is synchronization to intended users and attributes. In this scenario, however, the decisive requirement is sSO failure with otherwise successful password sign-in, so it would solve a neighboring identity problem rather than the one described.

Answer E is incorrect because This action is appropriate when the requirement is missing telemetry or agent registration. In this scenario, however, the decisive requirement is sSO failure with otherwise successful password sign-in, so it would solve a neighboring identity problem rather than the one described.

 

Question 24

The support team has ruled out unrelated causes in the seamless SSO Kerberos computer account. The remaining issue is: Kerberos key rollover and operational verification. The administrator must verify the effective result from Microsoft Entra evidence. Choose TWO actions that together implement and verify the requirement.

  1. Resolve the source anchor or duplicate attribute conflict before forcing another synchronization cycle.
  2. Inventory and deliberately migrate claims-dependent applications before changing the federation authority.
  3. Rotate the Seamless SSO Kerberos key on the required schedule and verify the resulting configuration.
  4. Confirm synchronization and authentication health with the relevant Entra Connect/Cloud Sync health data before broad rollout.
  5. Migrate the pilot population from federation to the selected cloud authentication method before removing the federation dependency.
  6. Use the alert category and affected component to separate synchronization faults from authentication faults.

Correct Answers: C, D

 

Correct Answers

Answer C is correct because This action directly implements kerberos key rollover and operational verification. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Answer D is correct because This verification step confirms that the selected control actually changes effective behavior for the targeted pilot and exposes policy, assignment, or propagation problems before wider rollout.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is source-anchor or duplicate-attribute synchronization conflict. In this scenario, however, the decisive requirement is kerberos key rollover and operational verification, so it would solve a neighboring identity problem rather than the one described.

Answer B is incorrect because This action is appropriate when the requirement is claims-dependent application authentication deliberately. In this scenario, however, the decisive requirement is kerberos key rollover and operational verification, so it would solve a neighboring identity problem rather than the one described.

Answer E is incorrect because This action is appropriate when the requirement is target cloud authentication after federation assessment. In this scenario, however, the decisive requirement is kerberos key rollover and operational verification, so it would solve a neighboring identity problem rather than the one described.

Answer F is incorrect because This action is appropriate when the requirement is synchronization alerts versus authentication alerts. In this scenario, however, the decisive requirement is kerberos key rollover and operational verification, so it would solve a neighboring identity problem rather than the one described.

 

Question 25

Before expanding an AD FS-to-cloud-authentication migration, the administrator must satisfy this condition: target cloud authentication after federation assessment. The organization requires a supported Microsoft-managed control. Which action best satisfies the requirement?

  1. Prioritize the failing component and user impact indicated by Connect Health evidence instead of restarting every hybrid service.
  2. Use staged rollout with a deliberately scoped pilot population and documented exceptions.
  3. Document rollback, DNS/federation changes, and dependency removal before the production cutover.
  4. Migrate the pilot population from federation to the selected cloud authentication method before removing the federation dependency.
  5. Configure and validate a Microsoft Entra Connect Sync staging server for controlled failover.

Correct Answer: D

 

Correct Answer

Answer D is correct because This action directly implements target cloud authentication after federation assessment. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is remediation using health evidence. In this scenario, however, the decisive requirement is target cloud authentication after federation assessment, so it would solve a neighboring identity problem rather than the one described.

Answer B is incorrect because This action is appropriate when the requirement is staged rollout and pilot exceptions. In this scenario, however, the decisive requirement is target cloud authentication after federation assessment, so it would solve a neighboring identity problem rather than the one described.

Answer C is incorrect because This action is appropriate when the requirement is cutover rollback and federation dependency removal. In this scenario, however, the decisive requirement is target cloud authentication after federation assessment, so it would solve a neighboring identity problem rather than the one described.

Answer E is incorrect because This action is appropriate when the requirement is staging server and controlled failover. In this scenario, however, the decisive requirement is target cloud authentication after federation assessment, so it would solve a neighboring identity problem rather than the one described.

 

Question 26

The current configuration of the hybrid identity design is otherwise acceptable. The unresolved requirement is: staged rollout and pilot exceptions. The current population scope must be preserved. Which action best satisfies the requirement?

  1. Use staged rollout with a deliberately scoped pilot population and documented exceptions.
  2. Inventory and deliberately migrate claims-dependent applications before changing the federation authority.
  3. Use Microsoft Entra Connect Sync for the hybrid synchronization topology.
  4. Separate synchronization health from authentication health and troubleshoot the failing layer.
  5. Use the Microsoft Entra Connect Health view that corresponds to the failing synchronization or authentication component.

Correct Answer: A

 

Correct Answer

Answer A is correct because This action directly implements staged rollout and pilot exceptions. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Incorrect Answers

Answer B is incorrect because This action is appropriate when the requirement is claims-dependent application authentication deliberately. In this scenario, however, the decisive requirement is staged rollout and pilot exceptions, so it would solve a neighboring identity problem rather than the one described.

Answer C is incorrect because This action is appropriate when the requirement is the server-based hybrid synchronization path for required topology and features. In this scenario, however, the decisive requirement is staged rollout and pilot exceptions, so it would solve a neighboring identity problem rather than the one described.

Answer D is incorrect because This action is appropriate when the requirement is synchronization engine versus sign-in failure. In this scenario, however, the decisive requirement is staged rollout and pilot exceptions, so it would solve a neighboring identity problem rather than the one described.

Answer E is incorrect because This action is appropriate when the requirement is connect Health component for observed failure. In this scenario, however, the decisive requirement is staged rollout and pilot exceptions, so it would solve a neighboring identity problem rather than the one described.

 

Question 27

A change request for a claims-dependent application during federation migration will be accepted only when the following is true: a deliberate migration path for claims-dependent application authentication. No new standing administrator privilege may be introduced. Which action best satisfies the requirement?

  1. Document rollback, DNS/federation changes, and dependency removal before the production cutover.
  2. Inventory and deliberately migrate claims-dependent applications before changing the federation authority.
  3. Verify Connect Health agent registration, service connectivity, and required permissions before relying on its telemetry.
  4. Configure the synchronization scope and attribute filtering for only the intended objects.
  5. Use Microsoft Entra Cloud Sync when its cloud-managed agent model meets the stated feature requirements.

Correct Answer: B

 

Correct Answer

Answer B is correct because This action directly implements claims-dependent application authentication deliberately. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is cutover rollback and federation dependency removal. In this scenario, however, the decisive requirement is claims-dependent application authentication deliberately, so it would solve a neighboring identity problem rather than the one described.

Answer C is incorrect because This action is appropriate when the requirement is missing telemetry or agent registration. In this scenario, however, the decisive requirement is claims-dependent application authentication deliberately, so it would solve a neighboring identity problem rather than the one described.

Answer D is incorrect because This action is appropriate when the requirement is synchronization to intended users and attributes. In this scenario, however, the decisive requirement is claims-dependent application authentication deliberately, so it would solve a neighboring identity problem rather than the one described.

Answer E is incorrect because This action is appropriate when the requirement is the cloud-managed provisioning-agent synchronization path against stated feature requirements. In this scenario, however, the decisive requirement is claims-dependent application authentication deliberately, so it would solve a neighboring identity problem rather than the one described.

 

Question 28

A design review of an AD FS-to-cloud-authentication migration identifies one remaining requirement: cutover rollback and federation dependency removal. General network connectivity outside the identity path is already verified. Which action best satisfies the requirement?

  1. Use the Microsoft Entra Connect Health view that corresponds to the failing synchronization or authentication component.
  2. Document rollback, DNS/federation changes, and dependency removal before the production cutover.
  3. Resolve the source anchor or duplicate attribute conflict before forcing another synchronization cycle.
  4. Deploy redundant Cloud Sync provisioning agents with outbound connectivity to the required directories and Microsoft Entra.
  5. Use the alert category and affected component to separate synchronization faults from authentication faults.

Correct Answer: B

 

Correct Answer

Answer B is correct because This action directly implements cutover rollback and federation dependency removal. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is connect Health component for observed failure. In this scenario, however, the decisive requirement is cutover rollback and federation dependency removal, so it would solve a neighboring identity problem rather than the one described.

Answer C is incorrect because This action is appropriate when the requirement is source-anchor or duplicate-attribute synchronization conflict. In this scenario, however, the decisive requirement is cutover rollback and federation dependency removal, so it would solve a neighboring identity problem rather than the one described.

Answer D is incorrect because This action is appropriate when the requirement is place provisioning agents for network and availability needs. In this scenario, however, the decisive requirement is cutover rollback and federation dependency removal, so it would solve a neighboring identity problem rather than the one described.

Answer E is incorrect because This action is appropriate when the requirement is synchronization alerts versus authentication alerts. In this scenario, however, the decisive requirement is cutover rollback and federation dependency removal, so it would solve a neighboring identity problem rather than the one described.

 

Question 29

The team is validating Microsoft Entra Connect Health telemetry. The decisive requirement is: the Connect Health component that matches the observed failure. Existing working access outside the stated scope must remain unchanged. Which action best satisfies the requirement?

  1. Configure and validate a Microsoft Entra Connect Sync staging server for controlled failover.
  2. Configure the Cloud Sync scoping and attribute mappings for the intended source population.
  3. Use the Microsoft Entra Connect Health view that corresponds to the failing synchronization or authentication component.
  4. Verify Connect Health agent registration, service connectivity, and required permissions before relying on its telemetry.
  5. Prioritize the failing component and user impact indicated by Connect Health evidence instead of restarting every hybrid service.

Correct Answer: C

 

Correct Answer

Answer C is correct because This action directly implements connect Health component for observed failure. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is staging server and controlled failover. In this scenario, however, the decisive requirement is connect Health component for observed failure, so it would solve a neighboring identity problem rather than the one described.

Answer B is incorrect because This action is appropriate when the requirement is scope and attribute mapping for source population. In this scenario, however, the decisive requirement is connect Health component for observed failure, so it would solve a neighboring identity problem rather than the one described.

Answer D is incorrect because This action is appropriate when the requirement is missing telemetry or agent registration. In this scenario, however, the decisive requirement is connect Health component for observed failure, so it would solve a neighboring identity problem rather than the one described.

Answer E is incorrect because This action is appropriate when the requirement is remediation using health evidence. In this scenario, however, the decisive requirement is connect Health component for observed failure, so it would solve a neighboring identity problem rather than the one described.

 

Question 30

The identity architect is reviewing a server expected to report to Connect Health. The required outcome is: missing telemetry or agent registration. The change will be piloted before broader enforcement. Choose TWO actions that together implement and verify the requirement.

  1. Use the alert category and affected component to separate synchronization faults from authentication faults.
  2. Use provisioning-agent health and provisioning logs to isolate the connectivity or mapping failure.
  3. Use Microsoft Entra Connect Sync for the hybrid synchronization topology.
  4. Separate synchronization health from authentication health and troubleshoot the failing layer.
  5. Verify Connect Health agent registration, service connectivity, and required permissions before relying on its telemetry.
  6. Confirm synchronization and authentication health with the relevant Entra Connect/Cloud Sync health data before broad rollout.

Correct Answers: E, F

 

Correct Answers

Answer E is correct because This action directly implements missing telemetry or agent registration. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Answer F is correct because This verification step confirms that the selected control actually changes effective behavior for the targeted pilot and exposes policy, assignment, or propagation problems before wider rollout.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is synchronization alerts versus authentication alerts. In this scenario, however, the decisive requirement is missing telemetry or agent registration, so it would solve a neighboring identity problem rather than the one described.

Answer B is incorrect because This action is appropriate when the requirement is agent connectivity or provisioning failure. In this scenario, however, the decisive requirement is missing telemetry or agent registration, so it would solve a neighboring identity problem rather than the one described.

Answer C is incorrect because This action is appropriate when the requirement is the server-based hybrid synchronization path for required topology and features. In this scenario, however, the decisive requirement is missing telemetry or agent registration, so it would solve a neighboring identity problem rather than the one described.

Answer D is incorrect because This action is appropriate when the requirement is synchronization engine versus sign-in failure. In this scenario, however, the decisive requirement is missing telemetry or agent registration, so it would solve a neighboring identity problem rather than the one described.

 

Question 31

Testing of Connect Health synchronization and authentication alerts is successful except for this condition: synchronization alerts versus authentication alerts. The tenant has the licensing required for the named capability. Which action best satisfies the requirement?

  1. Configure the synchronization scope and attribute filtering for only the intended objects.
  2. Use Microsoft Entra Cloud Sync when its cloud-managed agent model meets the stated feature requirements.
  3. Prioritize the failing component and user impact indicated by Connect Health evidence instead of restarting every hybrid service.
  4. Define one authoritative synchronization owner for each object during coexistence or migration.
  5. Use the alert category and affected component to separate synchronization faults from authentication faults.

Correct Answer: E

 

Correct Answer

Answer E is correct because This action directly implements synchronization alerts versus authentication alerts. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is synchronization to intended users and attributes. In this scenario, however, the decisive requirement is synchronization alerts versus authentication alerts, so it would solve a neighboring identity problem rather than the one described.

Answer B is incorrect because This action is appropriate when the requirement is the cloud-managed provisioning-agent synchronization path against stated feature requirements. In this scenario, however, the decisive requirement is synchronization alerts versus authentication alerts, so it would solve a neighboring identity problem rather than the one described.

Answer C is incorrect because This action is appropriate when the requirement is remediation using health evidence. In this scenario, however, the decisive requirement is synchronization alerts versus authentication alerts, so it would solve a neighboring identity problem rather than the one described.

Answer D is incorrect because This action is appropriate when the requirement is coexistence or migration without duplicate ownership. In this scenario, however, the decisive requirement is synchronization alerts versus authentication alerts, so it would solve a neighboring identity problem rather than the one described.

 

Question 32

A production issue involving a hybrid-identity health investigation has been narrowed to this requirement: remediation using health evidence. The administrator must verify the effective result from Microsoft Entra evidence. Which action best satisfies the requirement?

  1. Use Microsoft Entra Connect Sync for the hybrid synchronization topology.
  2. Enable password hash synchronization so Microsoft Entra can validate cloud sign-ins independently of on-premises agents.
  3. Resolve the source anchor or duplicate attribute conflict before forcing another synchronization cycle.
  4. Deploy redundant Cloud Sync provisioning agents with outbound connectivity to the required directories and Microsoft Entra.
  5. Prioritize the failing component and user impact indicated by Connect Health evidence instead of restarting every hybrid service.

Correct Answer: E

 

Correct Answer

Answer E is correct because This action directly implements remediation using health evidence. It addresses the requirement at the correct Microsoft Entra control layer without broadening unrelated privilege or changing an adjacent identity function.

Incorrect Answers

Answer A is incorrect because This action is appropriate when the requirement is the server-based hybrid synchronization path for required topology and features. In this scenario, however, the decisive requirement is remediation using health evidence, so it would solve a neighboring identity problem rather than the one described.

Answer B is incorrect because This action is appropriate when the requirement is cloud-side password validation from synchronized hashes for cloud validation resilience. In this scenario, however, the decisive requirement is remediation using health evidence, so it would solve a neighboring identity problem rather than the one described.

Answer C is incorrect because This action is appropriate when the requirement is source-anchor or duplicate-attribute synchronization conflict. In this scenario, however, the decisive requirement is remediation using health evidence, so it would solve a neighboring identity problem rather than the one described.

Answer D is incorrect because This action is appropriate when the requirement is place provisioning agents for network and availability needs. In this scenario, however, the decisive requirement is remediation using health evidence, so it would solve a neighboring identity problem rather than the one described.

img