
Explanation:
< Statement 1 # No
Statement 2 # No
Statement 3 # Yes
According to the Microsoft SC-300: Microsoft Identity and Access Administrator study guide and Azure AD Privileged Identity Management (PIM) documentation, roles in PIM can be configured for eligible or active assignments.
* User1 is assigned automatically - NoThe "Add assignments" screen shows User1's assignment type as Eligible, not Active. Eligible assignments mean the user is not automatically granted the role; they must activate it manually when needed. Therefore, User1 is not assigned automatically to the Application Administrator role.
* When User2 requests role assignment, only User3 can approve - NoThe Role setting details show that approval is required to activate and that the approver is listed as Group1. Because both User2 and User3 are members of Group1, any member of the group can approve the request, not only User3. Hence, the statement that only User3 can approve is incorrect.
* User1's approval on January 31, 2021, at 23:00 - YesThe configuration shows an activation maximum duration of 5 hours. Therefore, if User1's request is approved at 23:00 on January 31, the role remains active for 5 hours - until 04:00 on February 1, 2021. This aligns precisely with the parameters displayed in the exhibit.
As confirmed in Microsoft documentation ("Configure role settings in Azure AD PIM"), activation settings define how long a user can remain active after approval, and group approvers allow any member of that group to approve activations.