Weekend Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save75geek

SC-500 Microsoft Certified: Cloud and AI Security Engineer Associate Questions and Answers

Questions 4

You have a Microsoft Sentinel workspace that has the following data connectors:

• Microsoft Entra ID Protection

• Azure Firewall

• Common Event Formal (CEF)

You need to ensure that data is being ingested from each connector.

From the Logs query window, which table should you query for each connector? To answer, select the appropriate options in the answer area.

Options:

Buy Now
Questions 5

You have an Azure Subscription that contains the Azure App Service web apps shown in the following table.

You purchase custom SSL certificates from a trusted third-party authority. To which apps can you assign the custom SSL certificates?

Options:

A.

App4 only

B.

App3 and App4 only

C.

App2, App1, and App4 only

D.

App1, App2, App3, and App4

Buy Now
Questions 6

You have an Azure subscription that contains an Azure Database for PostgreSQL instance named 081.

You plan to protect OBI by using Microsoft Defender for Cloud.

You need to configure Defender for Cloud to detect anomalous activities and database exploitations for 061. The solution must NOT affect any other databases.

What should you enable? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 7

You have Microsoft Security Copilot agents that authenticate by using Microsoft Entra service principals.

You receive a Microsoft Defender alert triggered by the anomalous OAuth authentication of an agent ' s Microsoft Entra service principal.

You need to assess the impact of the agent identity and identify which resources are affected if the identity is abused for lateral movement The solution must minimize administrative effort.

What should you do?

Options:

A.

From Advanced hunting, create a query against the IdentityLogonEvents table to list all the sign-ins performed by the identity.

B.

From Attack paths, select the identity and view the blast radius.

C.

From AI Observability in Microsoft Purview Data Security Posture Management (DSPM), review the agent activity.

D.

From Microsoft Purview Audit, query the audit logs for all the role assignments granted to the identity.

E.

From Incidents, review incidents related to OAuth events reported by Microsoft Defender for Cloud Apps.

Buy Now
Questions 8

You have an Azure subscription named Sub1 that contains a virtual network named VNet1.

VNet1 contains multiple virtual machines, including two virtual machines named VM1 and VM2.

Sub1 is linked to a Microsoft Entra tenant named contoso.com.

A partner company has an Azure subscription named Sub2 that contains a virtual network named VNet2. VNet2 contains a virtual machine named VM3.

Sub2 is linked to a Microsoft Entra tenant named fabrikam.com.

VM1 and VM2 contain data used by an application that runs on VM3.

You need to ensure that VM3 can access VM1 and VM2. The solution must deny VM3 access to any other resources in Sub1.

What should you configure on each virtual network? To answer, drag the components to the correct virtual networks. Each component may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 9

You are configuring a new Microsoft Sentinel workspace named Workspace1.

You have an external IT Service Management (ITSM) system that is NOT supported by any Microsoft Sentinel solutions in Azure Marketplace.

You need to ensure that Workspace1 creates service tickets in the ITSM system for all new security incidents.

What should you create?

Options:

A.

A playbook

B.

A workbook

C.

A watchlist

D.

An analytics rule

Buy Now
Questions 10

You have a Microsoft Sentinel workspace named Workspace1.

You hire a security consultant. You provide the consultant with a guest account named User1 in your Microsoft Entra tenant

You need to enable User1 to assign incidents in Workspace1.

Which roles should you assign to User1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 11

You plan to deploy Microsoft 365 Copilot.

You discover that Copilot can access sensitive information in your Microsoft SharePoint Online libraries.

You need to automatically identify which SharePoint Online content has been shared between all internal users.

What should you create?

Options:

A.

a Microsoft Purview data loss prevention (DLP) policy in audit mode for SharePoint Online

B.

a Microsoft Purview Data Security Posture Management (DSPM) remediation action

C.

a Conditional Access policy that requires multifactor authentication (MFA) for SharePoint Online

D.

a SharePoint Advanced Management (SAM) Data access governance report

Buy Now
Questions 12

You have an Azure subscription that contains three storage accounts, an Azure SQL managed instance named SQL1, and three Azure SQL databases.

The storage accounts are configured as shown in the following table.

Options:

Buy Now
Questions 13

You use Microsoft Security Copilot.

Users are assigned either the Security Copilot Contributor role or the Security Copilot Owner role.

A contributor enables a custom plugin that is NOT approved, and some Security Copilot features in embedded experiences no longer function.

You need to ensure that plugins affecting all users can only be added by owners.

What should you do in the Plugin settings?

Options:

A.

Select Contributors and Owners to configure which users can add custom plugins at the user scope.

B.

Select Contributors and Owners to configure which users can add custom plugins at the workspace scope.

C.

Select Owners only to configure which users can add custom plugins at the workspace scope.

D.

Select Owners only to configure which users can add custom plugins at the user scope.

Buy Now
Questions 14

An application run2 on VM1 and VM2. The application is being migrated from storage account key authentication to Microsoft Entra authentication.

You review the current configuration and identify the following:

• VM1 and VM2 each have a system-assigned managed identity.

• Each application instance requests tokens by using only the local system-assigned managed identity.

• Network access to storage 1 from VMI and VM2 is allowed.

• No Azure RBAC data roles are assigned to the managed identities on storage1.

You need to enable the application on VM1 and VM2 to read and write blob data in storage1 by using Microsoft Entra authentication without changing how the application requests tokens.

Solution: You create a private endpoint for the blob service of storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 15

You have an Azure subscription that contains a resource group named RG1. RG1 contains a storage account named storage1. You have two custom Azure roles named Role1 and Role2 that are scoped to RG1. The permissions for Role1 are shown in the following JSON code.

Options:

Buy Now
Questions 16

You are implementing security controls for an Azure Storage account by using infrastructure as code (IaC).

You deploy the following Bicep code.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 17

You have an Azure Container Registry named Registry1-

You add role assignments for Registry! as shown in the following table.

Options:

Buy Now
Questions 18

You have a Microsoft 365 subscription.

You use Microsoft Entra Agent ID to manage an agent identity.

You manage AI agents from the Microsoft 365 admin center.

An autonomous agent named Agent1 runs without a signed-in user. The agent must access Microsoft Graph and read secrets from a single Azure key vault.

You need to grant Agent 1 access to Microsoft Graph and Key Vault without requiring user interaction or consent at runtime.

What should you do for the agent identity? To answer, drag the appropriate actions to the correct services. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 19

You have an Azure subscription that contains an Azure Key vault. The role assignments for the vault are shown in the following.

Options:

Buy Now
Questions 20

You have an Azure subscription named Sub1. Sub1 contains 20 virtual machines that run Windows Server.

Sub1 has the Microsoft Defender for Cloud Defender Cloud Security Posture Management (CSPM) plan enabled.

You need to ensure that all the virtual machines are scanned automatically for known security flaws and misconfigurations.

What should you use?

Options:

A.

Attack path analysis

B.

Microsoft Cloud Security Benchmark (MCSB)

C.

Cloud security explorer

D.

Just-in-time (JIT) VM access

E.

Vulnerability assessment on the virtual machines

Buy Now
Questions 21

You have an Azure subscription named Sub1 that contains a resource group named RG1.

RG1 contains a virtual network named VNet1 and a storage account named storage1. Several engineers are assigned the Owner role for Sub1.

You need to prevent updates to and deletions from VNet1. The solution must ensure that engineers can continue updating other resources in RG1.

Which lock should you apply?

Options:

A.

a Read-only resource lock at the RG1 scope

B.

a Delete resource lock at the RG1 scope

C.

a Read-only resource lock at the VNet1 scope

D.

a Delete resource lock at the VNet1 scope

Buy Now
Questions 22

You have a Microsoft Entra tenant that contains a group named Group1.

You plan to target Group1 to use the Microsoft Authenticator authentication method.

You need to ensure that the members in Group1 can use the Authenticator app as their primary authentication method.

What should you do?

Options:

A.

Enable one-time passcodes in Authenticator for Group1.

B.

Revoke the sessions for the Group1 members.

C.

Enable Authenticator push authentication mode for Group1.

D.

Enable the Authenticator passwordless authentication method for Group1.

Buy Now
Questions 23

For each of the following statements, select Yes if the statement is true Otherwise, select No.

Options:

Buy Now
Questions 24

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You add each virtual machine to a role on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 25

You need to protect the applications hosted on AKS1. The solution must meet the technical requirements.

Which Defender for Cloud plan should you enable?

Options:

A.

Microsoft Defender for Servers

B.

Microsoft Defender for App Service

C.

Microsoft Defender for Containers

D.

Microsoft Defender for Resource Manager

E.

Microsoft Defender for Storage

Buy Now
Questions 26

You need to configure Server1 to meet the technical requirements.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 27

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You create a private endpoint on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 28

You need to implement the planned change for SQLdb1

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point

Options:

A.

Create a compliance policy.

B.

Configure Microsoft Entra authentication for SQLServer1.

C.

Create a Conditional Access policy.

D.

Configure federated client identity for SQLdb1.

E.

Configure a user-assigned managed identity for SQLdb1.

Buy Now
Questions 29

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution: You create a playbook

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 30

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You add each virtual machine to a security group, and then add the security group to a role on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 31

You need to implement the planned change for the AKS1 integration.

What should you configure for AKS1?

Options:

A.

application scaling

B.

a workload identity

C.

Secrets Store CSI Driver

D.

Kubernetes role-based access control (Kubernetes RBAC)

Buy Now
Questions 32

User1 has requested to use the AI Administrator role.

Which approvers can approve the request, and how long will User1 be an AI administrator after the role is approved? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 33

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution: You create an analytics rule.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 34

You need to configure Microsoft Sentinel to meet the technical requirements.

To what should you set Analytics retention for DnsEvents?

Options:

A.

2 years

B.

12 years

C.

180 days

D.

1 year

E.

6 years

Buy Now
Questions 35

For which storage accounts can you implement the planned changes for storage?

Options:

A.

storage1, storage2, storage3, and storage4

B.

storage1, storage2, and storage4 only

C.

storage2 and storage4 only

D.

storage1 and storage3 only

E.

storage2, storage3, and storage4 only

F.

storage1 only

Buy Now
Questions 36

You need to implement the planned change for storage2 The solution must meet the technical requirements for storage encryption.

What should you do?

Options:

A.

Enable purge protection for storage2.

B.

Create an encryption scope in storage2.

C.

Configure storage2 to use an account encryption key.

D.

Assign an Azure role-based access control (Azure RBAC) role to storage2.

Buy Now
Questions 37

You need to implement the function apps to meet the technical requirements.

Which apps should you include in the implementation?

Options:

A.

Fa1 and Fa2 only

B.

Fa2 and Fa3 only

C.

Fa1 and Fa3 only

D.

Fa1, Fa2, and Fa3

Buy Now
Questions 38

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You create a user-assigned managed identity, assign the identity to each virtual machine, and then add each managed identity to a role on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 39

You need to configure the AKS1 and ID 1 managed identities to meet the technical requirements. The solution must follow the principle of least privilege.

Which role should you assign to each identity? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 40

Note. This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem

After you answer a question in this section, you will NOT be able to return. As a result these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution You create a hunting query.

Does this meet the goal’

Options:

A.

Yes

B.

No

Buy Now
Exam Code: SC-500
Exam Name: Microsoft Certified: Cloud and AI Security Engineer Associate
Last Update: Sep 19, 2026
Questions: 135
SC-500 pdf

SC-500 PDF

$23.75  $94.99
SC-500 Engine

SC-500 Testing Engine

$27.5  $109.99
SC-500 PDF + Engine

SC-500 PDF + Testing Engine

$36.25  $144.99