Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Microsoft Implementing End-to-End Security Controls for Cloud and AI Workloads SC-500 Exam Questions

Page: 1 / 14 Total 201 questions

Want more questions? Get Premium Access.

Question 1

You have an Azure subscription named Sub1 that contains an Azure Database for PostgreSQL instance Sub1 has Microsoft Defender for Cloud enabled.

You need to configure Microsoft Defender for Databases to minimize costs.

Which Defender plan should you enable?

Correct Answer: B. Microsoft Defender for Open-Source Relational Databases
Explanation:

The protected resource is Azure Database for PostgreSQL, which is an open-source relational database service. Microsoft Defender for Open-Source Relational Databases is scoped to PostgreSQL and MySQL style services, so it satisfies the requirement without enabling broader plans. Defender for Azure SQL Databases applies to Azure SQL, Defender for SQL Servers on Machines applies to SQL Server on VMs or Arc-enabled machines, and Defender for Servers or Storage would charge for unrelated workloads. Microsoft platform security questions usually hinge on where enforcement occurs: at the resource, server, subnet, firewall policy, private endpoint, or subscription level. The selected answer uses the control plane that owns that enforcement point. Other options are rejected when they only log activity, broaden network access, or protect a different service category. The result is a direct exam-style implementation choice: it changes the required security behavior without relying on unrelated monitoring, manual cleanup, or excessive privilege. Official Microsoft source/topic: SC-500 Study Guide > Defender for Databases; Microsoft Learn > Defender for open-source relational databases.


Question 2

You have an Azure subscription named Sub1 that contains a resource group named RG1.

RG1 contains a virtual network named VNet1 and a storage account named storage1. Several engineers are assigned the Owner role for Sub1.

You need to prevent updates to and deletions from VNet1. The solution must ensure that engineers can continue updating other resources in RG1.

Which lock should you apply?

Correct Answer: C. a Read-only resource lock at the VNet1 scope
Explanation:

Apply a Read-only lock directly to VNet1. Azure management locks operate independently of Azure RBAC and override permissions such as Owner. A ReadOnly lock prevents authorized users from both updating and deleting the locked resource, which exactly satisfies the protection requirement for VNet1. Microsoft documents that a ReadOnly lock effectively restricts authorized users to read operations for the locked resource.

The lock must be scoped specifically to VNet1, not RG1. Locks applied at a parent scope are inherited by child resources. Therefore, applying ReadOnly to RG1 would also prevent modifications to storage1 and other resources in RG1, violating the requirement that engineers must remain able to update those resources.

A Delete lock is insufficient because CanNotDelete permits users to modify a resource while preventing only deletion. The question explicitly requires preventing updates and deletions, so ReadOnly is necessary.

This aligns with the SC-500 governance objective covering enforcement of security controls for Azure resources. The current study guide places governance and security-control enforcement under Manage identity, access, and governance.


Question 3

Note. This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem

After you answer a question in this section, you will NOT be able to return. As a result these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution You create a hunting query.

Does this meet the goal'

Correct Answer: B. No
Explanation:

A hunting query is an investigation tool. It can find suspicious activity or support manual threat hunting, but it does not automatically assign every new incident to a group or flag it for triage. The requirement is an operational automation requirement on incident creation. Therefore, a hunting query alone does not meet the goal even though it may help analysts review incidents later. In Microsoft Sentinel and Defender scenarios, collection, detection, investigation, and automation are separate functions. The selected answer maps to the function requested by the question rather than a neighboring capability. This is why analytics, hunting, workbooks, connectors, automation rules, and playbooks must not be treated as interchangeable. The result is a direct exam-style implementation choice: it changes the required security behavior without relying on unrelated monitoring, manual cleanup, or excessive privilege. Official Microsoft source/topic: SC-500 Study Guide > Sentinel hunting and automation; Microsoft Learn > hunting queries versus incident automation.


Question 4

You need to implement the planned change for storage2 The solution must meet the technical requirements for storage encryption.

What should you do?

Correct Answer: B. Create an encryption scope in storage2.
Explanation:

An encryption scope provides a named encryption boundary for blobs and can use Microsoft-managed or customer-managed keys depending on configuration. The planned change refers to storage encryption, and the visible answer set points to a storage2-specific encryption configuration rather than vault purge protection or Azure RBAC. Account-level encryption keys affect the entire account; encryption scopes are the correct more granular storage encryption control. The important exam skill is separating data-plane access, management-plane administration, and network reachability. A storage, database, or firewall setting must be selected because it enforces the exact path requested in the scenario. Distractors often look plausible because they improve security generally, but they do not satisfy the protocol, scope, or automation requirement stated in the question. The result is a direct exam-style implementation choice: it changes the required security behavior without relying on unrelated monitoring, manual cleanup, or excessive privilege. Official Microsoft source/topic: SC-500 Study Guide > storage encryption; Microsoft Learn > Azure Storage encryption scopes.


Question 5

You have an Azure Storage account named storage1 that contains Azure Files shares.

You have an application named App1 that uses a system-assigned managed identity to access the shares.

Administrators access the shares by using storage account keys.

You need to ensure that App1 access the shares without using the storage account keys.

What should you do on storage1?

Correct Answer: D. Assign the Storage File Data Privileged Reader role to the managed identity of App1.
Explanation:

The workload already has a managed identity, so the required control is an Azure Storage data-plane role assignment. Storage account keys are shared secrets and do not identify App1; putting them in Key Vault or rotating them only improves secret handling, not keyless authorization. Disabling shared key access or setting portal defaults is not enough unless the identity has the file-share data role required to read the share. Storage File Data Privileged Reader grants the managed identity Azure Files read access through Microsoft Entra authorization. Microsoft platform security questions usually hinge on where enforcement occurs: at the resource, server, subnet, firewall policy, private endpoint, or subscription level. The selected answer uses the control plane that owns that enforcement point. Other options are rejected when they only log activity, broaden network access, or protect a different service category. The result is a direct exam-style implementation choice: it changes the required security behavior without relying on unrelated monitoring, manual cleanup, or excessive privilege. Official Microsoft source/topic: SC-500 Study Guide > secure storage access; Microsoft Learn > Azure Files identity-based access and Azure Storage data-plane RBAC.


Question 6

You have a Microsoft Sentinel workspace

You need to collect Windows security events from 200 Azure virtual machines that run Windows Server. The solution must meet the following requirements:

*Use direct agent based data collection from each virtual machine.

*Use a supported agent for new virtual machine deployments

Which Microsoft Sentinel connector should you use?

Correct Answer: B. Windows Security Events via AMA
Explanation:

The Windows Security Events via AMA connector uses Azure Monitor Agent and data collection rules for direct collection from Windows machines. It is the supported path for new deployments and avoids the legacy Log Analytics agent. Windows Forwarded Events is for a Windows Event Collector model, not direct agent collection. Syslog via AMA is for Linux Syslog, and Azure Resource Graph is not an event-collection connector. In Microsoft Sentinel and Defender scenarios, collection, detection, investigation, and automation are separate functions. The selected answer maps to the function requested by the question rather than a neighboring capability. This is why analytics, hunting, workbooks, connectors, automation rules, and playbooks must not be treated as interchangeable. The result is a direct exam-style implementation choice: it changes the required security behavior without relying on unrelated monitoring, manual cleanup, or excessive privilege. Official Microsoft source/topic: SC-500 Study Guide > Windows Security events using DCRs; Microsoft Learn > Windows Security Events via AMA connector.


Question 7

You have an Azure virtual network that contains 100 virtual machines and an Azure Firewall instance named FW1.

All the traffic from the virtual machines is routed through FW1.

You need to ensure that FW1 allows access to only a URL of updates contoso.com and blocks all other outbound traffic.

What should you use?

Correct Answer: B. An application rule
Explanation:

Azure Firewall application rules inspect HTTP and HTTPS traffic by FQDN or URL-oriented application targets. The scenario says the virtual machines may reach only updates.contoso.com and all other outbound traffic must be blocked. A network rule works at IP address, port, and protocol level, but it is not the best fit for URL/FQDN-based allowlisting. NAT rules translate inbound traffic and do not solve outbound web filtering. The important exam skill is separating data-plane access, management-plane administration, and network reachability. A storage, database, or firewall setting must be selected because it enforces the exact path requested in the scenario. Distractors often look plausible because they improve security generally, but they do not satisfy the protocol, scope, or automation requirement stated in the question. The result is a direct exam-style implementation choice: it changes the required security behavior without relying on unrelated monitoring, manual cleanup, or excessive privilege. Official Microsoft source/topic: SC-500 Study Guide > Azure Firewall; Microsoft Learn > Azure Firewall application rules and FQDN filtering.


Question 8

You have a virtual network named VNet1 that contains a subnet named Subnet1 and a virtual machine named VM1. VM1 uses only dynamic IP addresses from Subnet1.

You have an Azure key vault named KV1.

You enable a firewall on KV1 and allow access to KV1 from only select virtual networks and IP addresses.

VM1 receives 403 errors when it attempts to access KV1.

You need to enable VM1 to access KV1, while maintaining the current restrictions on KV1.

What should you do?

Correct Answer: C. Add a Microsoft.KeyVault service endpoint for Subnet1.
Explanation:

Enable a Microsoft.KeyVault virtual network service endpoint on Subnet1 and authorize that subnet in the Key Vault network rules. Azure Key Vault service endpoints allow a vault firewall to permit traffic originating from specifically selected Azure virtual-network subnets while continuing to deny traffic from unauthorized networks. This provides stable network-level authorization based on the subnet rather than relying on a VM's changing IP address.

Because VM1 uses dynamic IP addressing, adding its current IPv4 address to KV1's firewall is not an appropriate design. That address can change, causing the allowlist entry to become invalid and potentially requiring repeated administrative updates. A service endpoint instead establishes the subnet identity for traffic reaching Key Vault.

The Allow trusted Microsoft services option does not make ordinary Azure VMs trusted services. That bypass is limited to specific Microsoft services and supported scenarios listed by Microsoft; a customer VM must still access the vault through an authorized IP rule, virtual-network rule, or private endpoint.

A routing rule does not cause Key Vault's firewall to recognize Subnet1 as authorized.

This directly maps to the SC-500 objective Secure secrets and keys by using Azure Key Vault, which specifically includes configuring Key Vault access and firewall settings.


Question 9

You use Azure Virtual Network Manager to manage multiple virtual networks in a network group named Group1

You discover that the virtual machines in Group1 are accessible from the internet by using TCP port 3389.

You need to block inbound TCP 3389 from the internet across all the virtual networks in Group1 The solution must minimize administrative effort.

What should you use?

Correct Answer: B. A security admin configuration
Explanation:

Azure Virtual Network Manager security admin configurations provide centrally managed security admin rules across virtual networks in a network group. Because all virtual networks are already managed through Group1 and the requirement is to block inbound RDP from the internet with minimum effort, a security admin configuration is the correct centralized control. A separate NSG could work locally, but it would require distributed management. Connectivity configurations and UDRs do not directly deny TCP 3389. Microsoft platform security questions usually hinge on where enforcement occurs: at the resource, server, subnet, firewall policy, private endpoint, or subscription level. The selected answer uses the control plane that owns that enforcement point. Other options are rejected when they only log activity, broaden network access, or protect a different service category. The result is a direct exam-style implementation choice: it changes the required security behavior without relying on unrelated monitoring, manual cleanup, or excessive privilege. Official Microsoft source/topic: SC-500 Study Guide > Azure Virtual Network Manager; Microsoft Learn > Security admin rules.


Question 10

You have 15 Azure virtual machines in a resource group named RG1.

All the virtual machines run identical applications.

You need to prevent unauthorized applications and malware from funning on the virtual machines. Authorized applications must be able to run on the virtual machines.

What should you do?

Correct Answer: B. From Microsoft Defender for Cloud, configure adaptive application controls.
Explanation:

To prevent unauthorized applications and malware while allowing authorized applications on the 15 virtual machines, you should implement Adaptive Application Controls (AAC) in Microsoft Defender for Cloud. This involves:

  • Enable Adaptive Application Controls in Defender for Cloud on RG1
  • Allow-list known good applications during the learning period by analyzing current behavior across the identical VMs
  • Enforce the policy to block any unauthorized executables or scripts

Adaptive Application Controls learn from your environment's baseline behavior and create a whitelist of authorized applications, preventing malware and unauthorized software while allowing legitimate business applications to run.

Question 11

You create a new Microsoft Sentinel workspace named Workspace1.

Workspace1 ingests Azure Firewall logs that are used only occasionally during investigations.

You need to retain the logs for seven years at the lowest cost. The solution must ensure that investigators ran search the retained data when needed.

What should you do?

Correct Answer: C. Configure the table in Workspace1 that stores the logs to use the data lake tier.
Explanation:

To retain Azure Firewall logs for seven years at the lowest cost while maintaining searchability, you should:

  • Export logs to Azure Blob Storage with lifecycle management policies to move data to cool or archive tiers after initial retention periods
  • Use Log Analytics with Azure Monitor for the short-term operational period, then export to Blob Storage for long-term retention
  • Archive tier storage is the lowest-cost option for 7-year retention
  • Ensure searchability: Use managed queries or export logs in a format that can be restored and searched when needed (e.g., exported as CSV/JSON)

The lowest-cost approach combines short-term Log Analytics retention with long-term Azure Blob Storage archive tier storage, ensuring cost-efficiency while maintaining investigator access to archived data.

Question 12

The subscription contains the virtual machines shown in the following table.

On Nl1I, you configure an application security group named ASG1.

On which other network interfaces can you configure ASG1?

Correct Answer: B. NIC2 and NlC3 only
Explanation:

Application Security Groups (ASGs) in Azure can be configured on network interfaces that meet specific criteria:

  • Must be: In the same virtual network (same VNet)
  • Can be: On different subnets within that VNet
  • Cannot be: Applied to network interfaces in different VNets or in peered VNets
  • Requirement: The network interface must exist and be in a non-deleted state

ASG1 configured on NI1 can be assigned to other network interfaces only if they are in the same virtual network as NI1, regardless of which subnet they are in.

Question 13

You need to protect the applications hosted on AKS1. The solution must meet the technical requirements.

Which Defender for Cloud plan should you enable?

Correct Answer: C. Microsoft Defender for Containers
Explanation:

AKS workload protection is provided by Microsoft Defender for Containers. That plan covers Kubernetes posture, runtime threat detection, image risk signals, and container workload protections. Defender for Servers protects VMs and Arc servers, Defender for App Service protects web apps, Resource Manager protects control-plane operations, and Defender for Storage protects storage accounts. Because the applications are hosted on AKS1, Defender for Containers is the correct plan. The compute domain tests whether protection is applied before deployment, during runtime, or through posture assessment. The selected answer matches the phase described in the requirement. Detection-only tools are not acceptable when the requirement says prevent, and local installation methods are inferior when Defender for Cloud, Azure Policy, or Azure Machine Configuration can enforce the control centrally. The result is a direct exam-style implementation choice: it changes the required security behavior without relying on unrelated monitoring, manual cleanup, or excessive privilege. Official Microsoft source/topic: SC-500 Study Guide > Defender for Containers; Microsoft Learn > AKS workload protection.


Question 14

You have multiple Microsoft Security Copilot workspaces.

A user named User1 accesses Security Copilot by using the default workspace.

You create a new workspace named Workspace 1 and assign a capacity to Workspace1.

You plan to route Security Copilot agent traffic to Workspace1.

You need to ensure that User1 can use embedded experiences without errors.

What should you do before switching to Workspace1?

Correct Answer: A. Add User1 to Workspace1.
Explanation:

Security Copilot workspaces have membership and capacity associations. Before routing embedded experience traffic to Workspace1, User1 must be granted access to that workspace. Assigning a generic Security Operator role in Microsoft Entra does not make the user a member of the Security Copilot workspace. Disassociating capacity from the default workspace or creating more capacity does not resolve the user-access error. This domain is tested through precise scope control: tenant, subscription, resource, application, and data-plane authorization are not interchangeable. The correct choice applies the smallest identity or governance control that enforces the stated requirement. Options that only add users, create registrations, or provide broad administrator access fail because they do not directly enforce the requested access behavior. The result is a direct exam-style implementation choice: it changes the required security behavior without relying on unrelated monitoring, manual cleanup, or excessive privilege. Official Microsoft source/topic: SC-500 Study Guide > Security Copilot workspaces; Microsoft Learn > workspace access and capacity.


Question 15

You have a Microsoft Sentinel workspace named Workspace1

You have 100 on-premises servers that run Linux and have the Azure Monitor Agent installed.

You need to collect Syslog events from the Linux servers. The solution must meet the following requirements:

*Ensure that filtering occurs before data is written to Workspace1

*Reduce ingestion costs by excluding low value Syslog messages.

What should you include in the solution?

Correct Answer: B. A data collection rule (DCR)
Explanation:

Filtering must happen before data is written to the Log Analytics workspace. With Azure Monitor Agent, Syslog collection is governed by data collection rules, and DCR transformations or filtering can reduce ingestion before records reach the workspace. An ASIM parser normalizes queried data after ingestion, an analytics rule detects conditions after data exists, and a table-level transformation is not the primary collection control for Linux Syslog from AMA in this scenario. The posture and monitoring objective focuses on turning security data into usable operational outcomes. The correct answer either collects the right signal, grants the right security-operations role, or automates incident handling at the correct layer. Distractors often provide dashboards, queries, or broad permissions, but those do not create the requested workflow or least-privilege security capability. The result is a direct exam-style implementation choice: it changes the required security behavior without relying on unrelated monitoring, manual cleanup, or excessive privilege. Official Microsoft source/topic: SC-500 Study Guide > Syslog event collection; Microsoft Learn > data collection rules for Azure Monitor Agent.