Month End Sale Special 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: budy75

SC-500 Microsoft Certified: Cloud and AI Security Engineer Associate Questions and Answers

Questions 4

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You create a user-assigned managed identity, assign the identity to each virtual machine, and then add each managed identity to a role on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 5

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You add each virtual machine to a role on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 6

You need to delegate a user to implement the planned change for Defender for Cloud. The solution must follow the principle of least privilege.

Which user should you choose?

Options:

A.

Admin1

B.

Admin2

C.

Admin3

D.

Admin4

Buy Now
Questions 7

You need to implement the planned change for storage2 The solution must meet the technical requirements for storage encryption.

What should you do?

Options:

A.

Enable purge protection for storage2.

B.

Create an encryption scope in storage2.

C.

Configure storage2 to use an account encryption key.

D.

Assign an Azure role-based access control (Azure RBAC) role to storage2.

Buy Now
Questions 8

For which storage accounts can you implement the planned changes for storage?

Options:

A.

storage1, storage2, storage3, and storage4

B.

storage1, storage2, and storage4 only

C.

storage2 and storage4 only

D.

storage1 and storage3 only

E.

storage2, storage3, and storage4 only

F.

storage1 only

Buy Now
Questions 9

You need to configure Server1 to meet the technical requirements.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

SC-500 Question 9

Options:

Buy Now
Questions 10

User1 has requested to use the AI Administrator role.

Which approvers can approve the request, and how long will User1 be an AI administrator after the role is approved? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

SC-500 Question 10

Options:

Buy Now
Questions 11

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You create a private endpoint on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 12

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution: You create a playbook

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 13

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution: You create an analytics rule.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 14

You need to implement the function apps to meet the technical requirements.

Which apps should you include in the implementation?

Options:

A.

Fa1 and Fa2 only

B.

Fa2 and Fa3 only

C.

Fa1 and Fa3 only

D.

Fa1, Fa2, and Fa3

Buy Now
Questions 15

You plan to deploy Microsoft 365 Copilot.

You discover that Copilot can access sensitive information in your Microsoft SharePoint Online libraries.

You need to automatically identify which SharePoint Online content has been shared between all internal users.

What should you create?

Options:

A.

a Microsoft Purview data loss prevention (DLP) policy in audit mode for SharePoint Online

B.

a Microsoft Purview Data Security Posture Management (DSPM) remediation action

C.

a Conditional Access policy that requires multifactor authentication (MFA) for SharePoint Online

D.

a SharePoint Advanced Management (SAM) Data access governance report

Buy Now
Questions 16

You have an Azure Subscription that contains the storage accounts shown in the following table.

SC-500 Question 16

You enable Microsoft Defender for Storage.

Which storage services of storage5 are monitored by Microsoft for Storage which storage accounts are protected by.

SC-500 Question 16

Options:

Buy Now
Questions 17

You have an Azure API Management instance named APIM1 that publishes an API named OrdersAPI. Applications call OrdersAPI by using Microsoft Entra access tokens.

A security review finds that requests that do NOT contain a valid access token can still be forwarded to OrdersAPI.

You need to ensure that APIM1 rejects requests that do NOT contain a valid Microsoft Entra token before the requests reach OrdersAPI.

What should you configure?

Options:

A.

a subscription scope for OrdersAPI

B.

the rate-limit-by-key policy

C.

the validate-jwt policy

D.

the set-backend-service policy

Buy Now
Questions 18

You have a Microsoft Defender XDR environment.

You have a Microsoft Power Platform environment where makers publish custom Microsoft Copilot Studio agents.

You need to enable real-time protection so that suspicious tool invocations are blocked before an agent runs actions, and related alerts appear in the Microsoft Defender portal.

What should you do? To answer, drag the appropriate actions to the correct services. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

SC-500 Question 18

Options:

Buy Now
Questions 19

You have an Azure subscription that has Microsoft Defender for Cloud enabled.

You have an Amazon Web Services (AWS) account connected to Defender for Cloud that has the Defender Cloud Security Posture Management (CSPM) plan enabled.

You need to identify the potential impact of security incidents that exploit multiple risks reported by Defender CSPM.

What should you use?

Options:

A.

Regulatory compliance

B.

Cloud security explorer

C.

Security recommendations

D.

Attack path analysis

Buy Now
Questions 20

You use Azure Virtual Network Manager to manage multiple virtual networks in a network group named Group1

You discover that the virtual machines in Group1 are accessible from the internet by using TCP port 3389.

You need to block inbound TCP 3389 from the internet across all the virtual networks in Group1 The solution must minimize administrative effort.

What should you use?

Options:

A.

A connectivity configuration

B.

A security admin configuration

C.

A user-defined route (UDR)

D.

A network security group (NSG)

Buy Now
Questions 21

You have an Azure subscription.

You have the following custom role-based access control (RBAC) role definition

SC-500 Question 21

SC-500 Question 21

Options:

Buy Now
Questions 22

You have a Microsoft Security Copilot workspace named Workspace1 that is used by Security Operations Center (SOC) analysts and security administrators.

The SOC analysts use only the Security Copilot standalone experience, and the security administrators access Security Copilot from the Microsoft Defender portal.

A new Security Copilot workspace named Workspace2 is created for the security administrators. Workspace2 is assigned a capacity of five security compute units.

You need to ensure that Security Copilot usage for the SOC analysts is allocated to Workspace1 and Security Copilot usage for the security administrators is allocated to Workspace2.

What should you do?

Options:

A.

Configure Workspace2 for embedded agent traffic.

B.

Increase the capacity of Workspace2.

C.

Assign the Workspace1 capacity to Workspace2.

D.

Configure Workspace1 for embedded agent traffic.

Buy Now
Questions 23

Note. This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem

After you answer a question in this section, you will NOT be able to return. As a result these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution You create a hunting query.

Does this meet the goal’

Options:

A.

Yes

B.

No

Buy Now
Questions 24

For each of the following statements, select Yes if the statement is true Otherwise, select No.

SC-500 Question 24

Options:

Buy Now
Questions 25

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution: You create an automation rule.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 26

You need to implement the planned change for the AKS1 integration.

What should you configure for AKS1?

Options:

A.

application scaling

B.

a workload identity

C.

Secrets Store CSI Driver

D.

Kubernetes role-based access control (Kubernetes RBAC)

Buy Now
Questions 27

You need to configure Microsoft Sentinel to meet the technical requirements.

To what should you set Analytics retention for DnsEvents?

Options:

A.

2 years

B.

12 years

C.

180 days

D.

1 year

E.

6 years

Buy Now
Questions 28

You need to configure the AKS1 and ID 1 managed identities to meet the technical requirements. The solution must follow the principle of least privilege.

Which role should you assign to each identity? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

SC-500 Question 28

Options:

Buy Now
Questions 29

You need to implement the planned change for SQLdb1

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point

Options:

A.

Create a compliance policy.

B.

Configure Microsoft Entra authentication for SQLServer1.

C.

Create a Conditional Access policy.

D.

Configure federated client identity for SQLdb1.

E.

Configure a user-assigned managed identity for SQLdb1.

Buy Now
Questions 30

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You add each virtual machine to a security group, and then add the security group to a role on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 31

You have an Azure subscription named Sub1 that contains a storage account named storage1. Sub1 has Microsoft Defender for Storage enabled. Defender for Storage has malware scanning enabled.

You need to configure a solution that automates the remediation of malware detected in storage1.

What should you include in the solution?

Options:

A.

Application Insights

B.

Azure Event Hubs

C.

Azure Event Grid

D.

Azure Policy

Buy Now
Questions 32

You have an Azure subscription named Sub1 that contains an Azure Database for PostgreSQL instance Sub1 has Microsoft Defender for Cloud enabled.

You need to configure Microsoft Defender for Databases to minimize costs.

Which Defender plan should you enable?

Options:

A.

Microsoft Defender for Servers

B.

Microsoft Defender for Open-Source Relational Databases

C.

Microsoft Defender for SQL Servers on Machines

D.

Microsoft Defender for Azure SQL Databases

E.

Microsoft Defender for Storage

Buy Now
Questions 33

You have an Azure subscription that contains a resource group named RG1. RG1 contains a storage account named storage1. You have two custom Azure roles named Role1 and Role2 that are scoped to RG1. The permissions for Role1 are shown in the following JSON code.

SC-500 Question 33

SC-500 Question 33

Options:

Buy Now
Questions 34

You have a Microsoft Sentinel workspace named Workspace1.

You hire a security consultant. You provide the consultant with a guest account named User1 in your Microsoft Entra tenant

You need to enable User1 to assign incidents in Workspace1.

Which roles should you assign to User1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

SC-500 Question 34

Options:

Buy Now
Questions 35

You have an Azure subscription that contains an Azure Database for PostgreSQL instance named 081.

You plan to protect OBI by using Microsoft Defender for Cloud.

You need to configure Defender for Cloud to detect anomalous activities and database exploitations for 061. The solution must NOT affect any other databases.

What should you enable? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

SC-500 Question 35

Options:

Buy Now
Questions 36

You have an Azure management group named MG1 that contains two subscriptions named Sub1 and Sub? Both subscriptions are linked to a Microsoft Entra tenant that contains a security group named Group!

You need to ensure that the members of Group1 can assign roles to the resources in Sub1 and Sub2. The solution must follow the principle of least privilege.

Which role should you assign to Group1?

Options:

A.

Contributor at the MG1 scope

B.

Contributor at the Sub1 and Sub2 scopes

C.

User Access Administrator at the MG1 scope

D.

Owner at the MG1 scope

Buy Now
Questions 37

You have two management groups named MG1 and MG2 that contain multiple Azure subscriptions. The subscriptions are linked to a Microsoft Entra tenant.

You have a user named User1 and a global administrator named Admin 1

You are informed that User1 created an Azure subscription named Sub1 under the MG2 management group and is the only owner of the subscription.

You need to ensure that Admin1 can remove the Owner role from User1 for Sub1.

What should you do first?

Options:

A.

Move Sub1 to MG1.

B.

Assign Admin1 the User Access Administrator role for Sub1.

C.

Instruct Admin1 to use Privileged Identity Management (PIM) to request the Security Administrator role.

D.

Instruct Admin1 to enable Access management for Azure resources.

Buy Now
Questions 38

SC-500 Question 38

The subscription contains the virtual machines shown in the following table.

SC-500 Question 38

On Nl1I, you configure an application security group named ASG1.

On which other network interfaces can you configure ASG1?

Options:

A.

NIC2 only

B.

NIC2 and NlC3 only

C.

NIC2, NIC3, and NIC4 only

D.

NIC2, N1C3, NIC4, and NIC5

Buy Now
Questions 39

You have an Azure API Management instance named APIM1.

You have a partner company that accesses an API in APIM1 by using subscription keys.

A backend API key is stored in a named value in APIM1.

Microsoft Defender for Cloud generates the following recommendation: “API Management secret named values should be stored in Azure Key Vault.”

You need to address the recommendation.

What should you do first?

Options:

A.

Enable the Microsoft Defender for APIs plan.

B.

Enable a managed identity for APIM1.

C.

Mark the existing named value as a secret.

D.

Replace the backend API key with a subscription key.

Buy Now
Questions 40

You have a Microsoft 365 tenant that uses Microsoft Security Copilot and Microsoft Defender XDR.

Access to Microsoft Defender XDR is managed by using Microsoft entra global roles.

The Phishing triage Agent is available in Microsoft Defender. The required agent prerequisites and approvals are complete

Two users will perform the following tasks:

• User1 will enable and manage the Phishing Triage Agent settings.

• User2 will use Security Copilot in Microsoft Defender XDR to manage phishing incidents identified by the agent.

You need to assign the least-privileged built in Microsoft Entra role and Security Copilot role combination to each us Which roles should you assign to each user? To answer, select the appropriate options in the answer area.

SC-500 Question 40

Options:

Buy Now
Exam Code: SC-500
Exam Name: Microsoft Certified: Cloud and AI Security Engineer Associate
Last Update: Sep 30, 2026
Questions: 135

PDF + Testing Engine

$144.99

Testing Engine

$109.99

PDF (Q&A)

$94.99