Free Microsoft AZ-305 Exam Questions (page: 7)

Your company has the divisions shown in the following table.
Sub1 contains an Azure App Service web app named App1. App1 uses Azure AD for single-tenant user authentication. Users from contoso.com can authenticate to App1.
You need to recommend a solution to enable users in the fabrikam.com tenant to authenticate to App1.
What should you recommend?

  1. Configure Azure AD join.
  2. Configure Azure AD Identity Protection.
  3. Configure a Conditional Access policy.
  4. Configure Supported account types in the application registration and update the sign-in endpoint.

Answer(s): D



You have an Azure AD tenant named contoso.com that has a security group named Group1. Group1 is configured for assigned memberships. Group1 has 50 members, including 20 guest users.
You need to recommend a solution for evaluating the membership of Group1. The solution must meet the following requirements:
• The evaluation must be repeated automatically every three months.
• Every member must be able to report whether they need to be in Group1.
• Users who report that they do not need to be in Group1 must be removed from Group1 automatically.
• Users who do not report whether they need to be in Group1 must be removed from Group1 automatically.
What should you include in the recommendation?

  1. Implement Azure AD Identity Protection.
  2. Change the Membership type of Group1 to Dynamic User.
  3. Create an access review.
  4. Implement Azure AD Privileged Identity Management (PIM).

Answer(s): C



HOTSPOT (Drag and Drop is not supported)
You have an Azure subscription named Sub1 that is linked to an Azure AD tenant named contoso.com.
You plan to implement two ASP.NET Core apps named App1 and App2 that will be deployed to 100 virtual machines in Sub1. Users will sign in to App1 and App2 by using their contoso.com credentials.
App1 requires read permissions to access the calendar of the signed-in user. App2 requires write permissions to access the calendar of the signed-in user.
You need to recommend an authentication and authorization solution for the apps. The solution must meet the following requirements:
• Use the principle of least privilege.
• Minimize administrative effort.
What should you include in the recommendation? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

  1. See Explanation section for answer.

Answer(s): A

Explanation:



Your company has the divisions shown in the following table.
Sub1 contains an Azure App Service web app named App1. App1 uses Azure AD for single-tenant user authentication. Users from contoso.com can authenticate to App1.
You need to recommend a solution to enable users in the fabrikam.com tenant to authenticate to App1.
What should you recommend?

  1. Enable Azure AD pass-through authentication and update the sign-in endpoint.
  2. Use Azure AD entitlement management to govern external users.
  3. Configure assignments for the fabrikam.com users by using Azure AD Privileged Identity Management (PIM).
  4. Configure Azure AD Identity Protection.

Answer(s): B



Your company has the divisions shown in the following table.
Sub1 contains an Azure App Service web app named App1. App1 uses Azure AD for single-tenant user authentication. Users from contoso.com can authenticate to App1.
You need to recommend a solution to enable users in the fabrikam.com tenant to authenticate to App1.
What should you recommend?

  1. Configure the Azure AD provisioning service.
  2. Enable Azure AD pass-through authentication and update the sign-in endpoint.
  3. Configure Supported account types in the application registration and update the sign-in endpoint.
  4. Configure Azure AD join.

Answer(s): C



HOTSPOT (Drag and Drop is not supported)
You have an Azure AD tenant that contains a management group named MG1.
You have the Azure subscriptions shown in the following table.
The subscriptions contain the resource groups shown in the following table.
The subscription contains the Azure AD security groups shown in the following table.
The subscription contains the user accounts shown in the following table.
You perform the following actions:
Assign User3 the Contributor role for Sub1.
Assign Group1 the Virtual Machine Contributor role for MG1.
Assign Group3 the Contributor role for the Tenant Root Group.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.




  1. See Explanation section for answer.

Answer(s): A

Explanation:



Your company has the divisions shown in the following table.
Sub1 contains an Azure App Service web app named App1. App1 uses Azure AD for single-tenant user authentication. Users from contoso.com can authenticate to App1.
You need to recommend a solution to enable users in the fabrikam.com tenant to authenticate to App1.
What should you recommend?

  1. Configure Azure AD Identity Protection.
  2. Configure assignments for the fabrikam.com users by using Azure AD Privileged Identity Management (PIM).
  3. Configure Supported account types in the application registration and update the sign-in endpoint.
  4. Configure a Conditional Access policy.

Answer(s): C



Your company has the divisions shown in the following table.
Sub1 contains an Azure App Service web app named App1. App1 uses Azure AD for single-tenant user authentication. Users from contoso.com can authenticate to App1.
You need to recommend a solution to enable users in the fabrikam.com tenant to authenticate to App1.
What should you recommend?

  1. Use Azure AD entitlement management to govern external users.
  2. Enable Azure AD pass-through authentication and update the sign-in endpoint.
  3. Configure a Conditional Access policy.
  4. Configure assignments for the fabrikam.com users by using Azure AD Privileged Identity Management (PIM).

Answer(s): A



Viewing page 7 of 37



Post your Comments and Discuss Microsoft AZ-305 exam prep with other Community members:

AZ-305 Exam Discussions & Posts