Provide Microsoft SC-500 Practice Test Engine for Preparation
Detailed New SC-500 Exam Questions for Concept Clearance
NEW QUESTION # 69
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.
After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.
You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.
You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.
You need to ensure that VM1 and VM2 can access storage1.
Solution: You add each virtual machine to a role on storage1.
Does this meet the goal?
- A. No
- B. Yes
Answer: B
Explanation:
Each virtual machine already has its own system-assigned managed identity. Assigning an appropriate Azure Storage data-access role on storage1 to the managed identity of each VM authorizes both virtual machines to access the storage account by using Microsoft Entra authentication. Public network access is already enabled, so the required network connectivity is available.
Reference:
https://learn.microsoft.com/en-us/entra/identity/managed-identities-azure-resources/tutorial-windows-managed-identities-vm-access?pivots=identity-windows-mi-vm-access-data-lake
https://learn.microsoft.com/en-us/azure/storage/blobs/authorize-access-azure-active-directory
NEW QUESTION # 70
Drag and Drop Question
You have a Microsoft 365 subscription. All users have Microsoft Exchange Online mailboxes.
You use Microsoft Entra Agent ID to register and manage AI agents.
The developers at your company create the following two agents:
- Agent1: An interactive agent that helps users summarize their own
Exchange Online email
- Agent2: An autonomous agent that sends nightly updates to a Microsoft Teams channel You need to grant each agent access to Microsoft Graph. The solution must minimize the access scope, while meeting each agent's operating model.
Which type of permission should you assign to each agent? To answer, drag the appropriate permission types to the correct agents. Each permission type may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 71
Hotspot Question
You have an Azure subscription that contains an Azure Database for PostgreSQL instance named DB1.
You plan to protect DB1 by using Microsoft Defender for Cloud.
You need to configure Defender for Cloud to detect anomalous activities and database exploitations for DB1. The solution must NOT affect any other databases.
What should you enable? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
Box 1: At the individual database level
The database protection must be applied at the individual database level (specifically, at the individual database server level).
The requirement specifies that the configuration must not affect other databases.
Individual Database Level: Microsoft Defender for Cloud allows you to navigate directly to the specific Azure Database for PostgreSQL server, expand its Security menu, and enable Microsoft Defender for Cloud specifically for that single resource. This completely isolates the configuration to this instance.
Box 2: Microsoft Defender for Open-Source Relational Databases
The most appropriate plan is Microsoft Defender for Open-Source Relational Databases (which operates under the broader Microsoft Defender for Databases bundle).
Reference:
https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-sql-introduction
NEW QUESTION # 72
You create a new Microsoft Sentinel workspace named Workspace1.
Workspace1 ingests Azure Firewall logs that are used only occasionally during investigations.
You need to retain the logs for seven years at the lowest cost. The solution must ensure that investigators can search the retained data when needed.
What should you do?
- A. Configure the table in Workspace1 that stores the logs to use the data lake tier.
- B. Archive the logs to an Azure Storage account.
- C. Configure the table in Workspace1 that stores the logs to use the analytics tier.
- D. Increase the analytics retention period of Workspace1 to seven years.
Answer: A
Explanation:
To retain Azure Firewall logs for ten years at the lowest cost while keeping them searchable for investigations, you should configure the table in the workspace that stores the logs to use the data lake tier.
Configuring the specific log table to the Data Lake tier (also known as the Auxiliary or Archive tier) reduces costs significantly compared to keeping them in the Analytics tier. It allows you to set extended retention for up to 12 years and permits investigators to run search jobs or restore data when needed.
Reference: https://learn.microsoft.com/en-us/azure/sentinel/manage-data-overview
NEW QUESTION # 73
You use Azure Virtual Network Manager to manage multiple virtual networks in a network group named Group1.
You discover that the virtual machines in Group1 are accessible from the internet by using TCP port 3389.
You need to block inbound TCP 3389 from the internet across all the virtual networks in Group1.
The solution must minimize administrative effort.
What should you use?
- A. a security admin configuration
- B. a network security group (NSG)
- C. a user-defined route (UDR)
- D. a connectivity configuration
Answer: A
Explanation:
A security admin configuration in Azure Virtual Network Manager applies centralized security admin rules to all virtual networks in a targeted network group. A deny inbound rule for TCP port
3389 from the internet blocks RDP exposure across Group1 with minimal administrative effort and is evaluated before NSG rules.
Reference:
https://learn.microsoft.com/en-us/azure/virtual-network-manager/concept-security-admins
NEW QUESTION # 74
You have an Azure subscription.
You need to create and deploy an Azure policy that meets the following requirements:
*When a new virtual machine is deployed, automatically install a custom security extension.
*Trigger an autogenerated remediation task for non-compliant virtual machines to install the extension.
What should you include in the policy? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
Definition effect: DeployIfNotExists; For remediation: a managed identity that has the Contributor role DeployIfNotExists is the Azure Policy effect used when a noncompliant resource should trigger deployment of a related configuration, such as a VM extension. Remediation tasks require a managed identity that has the role permissions needed to deploy the extension. Audit or Deny would only report or block resources. The managed identity is essential because Azure Policy performs the deployment on behalf of the assignment.
This answer also follows operational scalability. Microsoft security architecture favors policy-driven deployment, agentless assessment, managed identities, and Defender workload plans where possible. Those mechanisms reduce manual configuration while keeping enforcement tied to the resource type, which is why the selected choice is stronger than manual or after-the-fact alternatives. The result is a direct exam-style implementation choice: it changes the required security behavior without relying on unrelated monitoring, manual cleanup, or excessive privilege. Official Microsoft source/topic: SC-500 Study Guide > Azure Policy built-in and custom definitions; Microsoft Learn > deployIfNotExists and remediation.
NEW QUESTION # 75
You have an Azure virtual network named VNet1 that contains a subnet named Subnet1.
You create a storage account named storage1.
You need to ensure that access to storage1 can be managed only by a network security group (NSG) linked to Subnet1.
What should you use?
- A. an Azure Private link service
- B. a private endpoint
- C. a service endpoint
- D. a user-defined route (UDR)
Answer: B
Explanation:
To manage access to an Azure Storage account exclusively using a Network Security Group (NSG) linked to a subnet, you must use an Azure Private Endpoint combined with enabling Network Policies for Private Endpoints on the subnet.
Incorrect:
[Not B]
While Virtual Network Service Endpoints can restrict a storage account to only accept traffic from a specific subnet, the NSG itself cannot easily manage specific, granular access to that individual storage account. In an NSG rule, using the default Storage service tag applies broadly to all Azure Storage accounts globally, failing the requirement to manage access exclusively to your specific storage account.
Reference:
https://learn.microsoft.com/en-us/azure/storage/common/storage-private-endpoints
NEW QUESTION # 76
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.
After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.
You have a Microsoft Sentinel workspace.
You have a multi-tier Security Operations Center (SOC) team.
You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.
Solution: You create an analytics rule.
Does this meet the goal?
- A. Yes
- B. No
Answer: B
Explanation:
An analytics rule detects threats and generates alerts or incidents from matching data. It does not automatically assign all newly created incidents to an analyst group or apply triage tags. An automation rule is required because it can trigger when an incident is created and immediately assign an owner and tag the incident for triage.
Reference:
https://learn.microsoft.com/en-us/azure/sentinel/create-manage-use-automation-rules?tabs=defender-portal%2Conboarded
https://learn.microsoft.com/en-us/azure/sentinel/create-analytics-rules?tabs=defender-portal
NEW QUESTION # 77
Drag and Drop Question
You have a Microsoft Defender External Attack Surface Management (Defender EASM) resource for a company named Contoso, Ltd.
You need to update the Defender EASM workflow to meet the following requirements:
- Assets from a business domain that Contoso no longer owns must be
removed from inventory.
- Findings that do NOT App1y to confirmed inventory must NOT affect
reported counts.
What should you do for each requirement? To answer, drag the appropriate actions to the correct requirements. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 78
Drag and Drop Question
You have an Azure virtual network named VNet1 that contains an AzureBastionSubnet. VNet1 contains a subnet named Subnet1. Subnet1 contains multiple virtual machines.
You plan to deploy Azure Bastion to provide secure RDP access to the virtual machines on Subnet1. You associate a network security group (NSG) named NSG1 to AzureBastionSubnet.
You need to configure rules for NSG1. The solution must meet the following requirements:
- Allow required inbound access to Azure Bastion from the internet.
- Allow user access to the virtual machines by using Azure Bastion.
Which TCP ports should you allow for the NSG1 rules? To answer, drag the appropriate ports to the correct rules. Each port may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 79
Hotspot Question
You have an Azure subscription that contains the following resources:
- An Azure SQL Database logical server named Server1 that contains a
database named DB1
- An Azure SQL Managed Instance named Instance1 that contains a
database named DB2
You need to configure database auditing. The solution must meet the following requirements:
- Ensure that audit data is centrally available in a location that
supports for KQL queries.
- Minimize ongoing administrative effort as additional databases are
added.
What should you configure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 80
A company stores confidential training data used by machine learning models. Administrators need to ensure that encryption keys remain under organizational control rather than being fully managed by Microsoft. Which option should be selected?
- A. Anonymous encryption
- B. Customer-managed keys (CMK)
- C. Shared Access Signatures
- D. Platform-managed keys only
Answer: B
Explanation:
Customer-managed keys allow organizations to control key lifecycle management, rotation, and revocation using Azure Key Vault or Managed HSM. This provides additional control over encryption compared to platform-managed keys. Shared Access Signatures govern access permissions and do not manage encryption ownership.
NEW QUESTION # 81
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals.
More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.
After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.
You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.
You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.
You need to ensure that VM1 and VM2 can access storage1.
Solution: You create a user-assigned managed identity, assign the identity to each virtual machine, and then add each managed identity to a role on storage1.
Does this meet the goal?
- A. No
- B. Yes
Answer: B
Explanation:
A user-assigned managed identity can be attached to multiple virtual machines and then granted an Azure Storage data role. The applications running on VM1 and VM2 can request tokens for that identity and access storage1 without account keys. Public network access is already enabled, so the missing control is authorization. Assigning the user-assigned managed identity to the correct storage role satisfies the access requirement. For SC-500, the decisive distinction is whether the control authenticates an identity, grants authorization, or merely changes configuration visibility. The incorrect choices generally either grant excessive privilege, change the application model, or operate at the wrong scope. Microsoft expects the least- privilege identity path that satisfies the scenario without introducing shared secrets or unnecessary tenant- wide rights. The result is a direct exam-style implementation choice: it changes the required security behavior without relying on unrelated monitoring, manual cleanup, or excessive privilege. Official Microsoft source
/topic: SC-500 Study Guide > managed identities; Microsoft Learn > user-assigned managed identities and role assignment to storage.
NEW QUESTION # 82
You use Microsoft Security Copilot.
Users are assigned either the Security Copilot Contributor role or the Security Copilot Owner role.
A contributor enables a custom plugin that is NOT approved, and some Security Copilot features in embedded experiences no longer function.
You need to ensure that plugins affecting all users can only be added by owners.
What should you do in the Plugin settings?
- A. Select Owners only to configure which users can add custom plugins at the user scope.
- B. Select Contributors and Owners to configure which users can add custom plugins at the user scope.
- C. Select Owners only to configure which users can add custom plugins at the workspace scope.
- D. Select Contributors and Owners to configure which users can add custom plugins at the workspace scope.
Answer: C
Explanation:
To restrict the addition and management of plugins that affect all users to Owners only, you should configure the setting at the workspace scope.
In Microsoft Security Copilot, selecting Owners only at the workspace scope prevents Contributors from adding, configuring, or managing custom plugins for the entire organization.
Contributors will only be allowed to manage plugins for themselves at the user scope, ensuring governance over platform-wide integrations.
Reference:
https://learn.microsoft.com/en-us/copilot/security/authentication
NEW QUESTION # 83
Drag and Drop Question
You have an Azure subscription named Sub1. Sub1 contains 60 virtual machines that run either Window Server or Linux.
All the Windows Server virtual machines host line-of-business (LOB) applications and all the Linux virtual machines host backend databases.
You need to enable malware protection for the virtual machines.
Which Microsoft Defender for Cloud plan should you enable for each type of virtual machine? To answer, drag the appropriate plans to the correct virtual machine types. Each plan may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
Box 1: Microsoft Defender for Servers
Windows Server VMs (LOB Applications): Microsoft Defender for Servers (Plan 1 or Plan 2). This plan provides advanced malware protection, endpoint detection and response (EDR) via Microsoft Defender for Endpoint, and security posture management.
Box 2: Microsoft Defender for Servers
Linux VMs (Backend Databases): Microsoft Defender for Servers (Plan 1 or Plan 2) paired with Microsoft Defender for Azure Cosmos DB or Microsoft Defender for SQL (depending on your specific database type). While Defender for Servers secures the underlying Linux operating system against malware, a database-specific Defender plan is required to protect the database layer from SQL injections, data exfiltration, and anomalous access.
Incorrect:
Defender for Databases:
Protects PaaS, Not VMs: The Microsoft Defender for Databases plan (such as Defender for Azure SQL or Defender for Open-source Relational Databases) is designed specifically for Azure PaaS (Platform as a Service) database solutions.
Reference:
https://learn.microsoft.com/it-it/azure/defender-for-cloud/tutorial-enable-servers-plan
NEW QUESTION # 84
An organization is evaluating the security of AI-generated content before it is presented to end users. The goal is to detect harmful, unsafe, or policy-violating responses automatically. Which capability should be prioritized?
- A. Deploying additional virtual networks
- B. Adding more GPUs
- C. Content filtering and safety evaluation
- D. Increasing context window size
Answer: C
Explanation:
Content filtering and safety evaluation mechanisms help identify harmful, toxic, biased, or policy- violating outputs before they reach users. These controls are a key component of responsible AI security. Infrastructure enhancements such as GPUs or virtual networks improve performance and connectivity but do not directly address content safety risks.
NEW QUESTION # 85
You have an Azure subscription that contains a resource group named RG1.
RG1 contains a Microsoft Security Copilot deployment that is integrated with a Microsoft Sentinel workspace named Workspace1.
Analysts use the Security Copilot standalone experience to retrieve incidents by using the Microsoft Sentinel plugin.
A user named User1 can sign in to Security Copilot but cannot retrieve incidents from Workspace1. You verify that User1 has only the Security Copilot Contributor role.
You need to ensure that User1 can retrieve the incidents. The solution must follow the principle of least privilege and NOT require any configuration changes to Security Copilot.
Which role should you assign to User1?
- A. the Security Reader role in Microsoft Entra
- B. the Microsoft Sentinel Reader role for Workspace1
- C. the Security Copilot Owner role
- D. the Security Administrator role in Microsoft Entra
- E. the Contributor role in Azure for RG1
Answer: B
Explanation:
The Security Copilot Contributor role permits User1 to use the Security Copilot platform, but it does not grant access to Microsoft Sentinel data. Assigning the Microsoft Sentinel Reader role at the Workspace1 scope grants read access to the workspace incidents through the Microsoft Sentinel plugin while avoiding broader security administration or resource modification privileges.
Reference:
https://learn.microsoft.com/en-us/copilot/security/authentication
NEW QUESTION # 86
You have an Azure key vault named KV1.
You have an Azure App Service web app named App1. App1 is integrated with a virtual network named VNet1 that is linked to an Azure Private DNS zone. App1 accesses secrets stored in KV1.
You need to configure KV1 to meet the following requirements:
- App1 must access the secrets by using a private IP address on VNet1.
- Requests from outside VNet1 must be denied.
Which two actions should you perform for KV1? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
- A. Add the IP addresses of App1.
- B. Create a private endpoint.
- C. Disable public access.
- D. Create an access policy.
Answer: B,C
Explanation:
To meet your requirements, you must create a Private Endpoint for the Azure Key Vault, configure its firewall to deny public access, and link the Key Vault's private DNS zone to your virtual network (VNet). Because your Azure App Service is already VNet-integrated, these steps ensure all traffic to the Key Vault routes securely over your private IP space.
Reference:
https://learn.microsoft.com/en-us/azure/key-vault/general/private-link-service
NEW QUESTION # 87
You have a Microsoft Entra tenant.
You need to implement password less authentication. The solution must meet the following requirements:
*Users can sign in without a password by using a mobile device.
*New users that sign in for the first time must use a helpdesk issued sign in method that expires.
Which authentication method should you enable for each requirement? To answer, drag the appropriate methods to the correct requirements. Each method may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
Passwordless sign-in: Microsoft Authenticator; First-time sign-in for new users: Temporary Access Pass
Microsoft Authenticator supports passwordless phone sign-in, allowing users to authenticate from a mobile device without typing a password. Temporary Access Pass is a time-limited, helpdesk-issued credential designed for onboarding or recovery, so it fits first-time sign-in for new users. SMS and voice call are authentication methods but are not passwordless sign-in methods in the same strong sense, and hardware OATH tokens are not the requested mobile-device experience. For SC-500, the decisive distinction is whether the control authenticates an identity, grants authorization, or merely changes configuration visibility. The incorrect choices generally either grant excessive privilege, change the application model, or operate at the wrong scope. Microsoft expects the least-privilege identity path that satisfies the scenario without introducing shared secrets or unnecessary tenant-wide rights. The result is a direct exam-style implementation choice: it changes the required security behavior without relying on unrelated monitoring, manual cleanup, or excessive privilege. Official Microsoft source/topic: SC-500 Study Guide > passwordless authentication methods; Microsoft Learn > Microsoft Authenticator and Temporary Access Pass.
NEW QUESTION # 88
You need to implement the function apps to meet the technical requirements.
Which apps should you include in the implementation?
- A. Fa1 and Fa2 only
- B. Fa1, Fa2, and Fa3
- C. Fa1 and Fa3 only
- D. Fa2 and Fa3 only
Answer: C
Explanation:
The correct implementation includes Fa1 and Fa3 only according to the visible answer area. In Azure Functions security scenarios, apps are included only when their hosting, authentication, identity, or network configuration matches the stated technical controls. Including Fa2 would apply the implementation to an app that does not meet those requirements. The selected set therefore narrows the change to the function apps that require the security implementation. For SC-500, compute controls are evaluated by workload type: VM, Arc server, AKS, container registry, container group, Functions, Logic Apps, App Service, and AI agent runtime.
The right answer uses the Microsoft control that is native to that workload. Broad Azure roles or unrelated monitoring services would either overgrant access or fail to enforce the required security state. The result is a direct exam-style implementation choice: it changes the required security behavior without relying on unrelated monitoring, manual cleanup, or excessive privilege. Official Microsoft source/topic: SC-500 Study Guide > Azure Functions security controls; Microsoft Learn > App Service/Functions authentication and network security.
NEW QUESTION # 89
You have an Azure Logic Apps Consumption workflow that uses a Request trigger. All supported authentication methods are enabled on the Request trigger.
You need to ensure that the endpoint accepts only OAuth-based requests. The solution must minimize costs.
What should you do?
- A. Enable Secure Inputs and enable Secure Outputs for the Request trigger.
- B. Use OAuth 2.0 authorization.
- C. Deploy Azure API Management.
- D. Disable shared access signature (SAS) authentication for the Request trigger.
Answer: D
NEW QUESTION # 90
Hotspot Question
You have an Azure key vault named KV1 that uses role-based access control (RBAC) for data plane authorization.
You have multiple Azure App Service web apps that retrieve a SQL connection string stored as a secret in KV1.
You need to ensure that the web apps can access KV1. The solution must minimize the number of required identities and follow the principle of least privilege.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
Box 1: User-Assigned Managed Identity
The best type of workload identity for this scenario is a User-Assigned Managed Identity.
Minimizes Required Identities: Unlike a system-assigned managed identity (which creates one distinct identity per App Service), a single user-assigned managed identity can be created once and shared across multiple Azure App Service web apps.
Enforces Least Privilege: You can assign this single identity the specific, built-in Azure RBAC role of Key Vault Secrets User. This scope restricts the apps to only reading the secret contents (the SQL connection string) without granting permissions to delete, list, or alter other data plane components like keys or certificates.
Eliminates Credential Management: Because it is an Azure-managed workload identity, there are no client secrets or certificates to rotate, secure, or accidentally expose in your application configurations.
Box 2: Key Vault Secrets User
Assign the Key Vault Secrets User built-in role to the web apps.
Principle of Least Privilege: The Key Vault Secrets User role grants authorization to read secret contents and properties. It completely restricts the web apps from modifying, deleting, or creating secrets. It also denies access to cryptographic keys and certificates stored in the same vault.
Reference:
https://learn.microsoft.com/en-us/azure/app-service/overview-managed-identity
https://learn.microsoft.com/en-us/azure/key-vault/general/rbac-guide
NEW QUESTION # 91
......
SC-500 2026 Training With 136 QA's: https://www.exams-boost.com/SC-500-valid-materials.html