Pre-Winter Sale - 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dm70dm

SC-500 Microsoft Certified: Cloud and AI Security Engineer Associate Questions and Answers

Questions 4

You plan to deploy Microsoft 365 Copilot

You discover that Copilot can access sensitive information in your Microsoft SharePoint Online libraries. You need to automatically identify which SharePoint Online content has be*»n shared between all internal users-What should you create?

Options:

A.

a Conditional Access policy that requires multifactor authentication (MFA) for SharePoint Online

B.

a Microsoft Purview Data Security Posture Management (DSPM) remediation action

C.

a Microsoft Purview data loss prevention IDLP) policy in audit mode for SharePoint Online

D.

a SharePoint Advanced Management (SAM) Data access governance report

Buy Now
Questions 5

You have an Azure subscription named Sub1 that contains a virtual network named VNet1.

VNet1 contains multiple virtual machines, including two virtual machines named VM1 and VM2.

Sub1 is linked to a Microsoft Entra tenant named contoso.com.

A partner company has an Azure subscription named Sub2 that contains a virtual network named VNet2. VNet2 contains a virtual machine named VM3.

Sub2 is linked to a Microsoft Entra tenant named fabrikam.com.

VM1 and VM2 contain data used by an application that runs on VM3.

You need to ensure that VM3 can access VM1 and VM2. The solution must deny VM3 access to any other resources in Sub1.

What should you configure on each virtual network? To answer, drag the components to the correct virtual networks. Each component may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

SC-500 Question 5

Options:

Buy Now
Questions 6

You have an Azure key vault named KV1 that uses rale based access control (RBAC) for data plane authorization.

You have multiple Azure App Service web apps that retrieve a SQL connection string stored as a secret in KV1.

You need to ensure that the web apps can access KV1. the solution must minimize the number of required identities and follow the principle of least privilege.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

SC-500 Question 6

Options:

Buy Now
Questions 7

You have an Azure Subscription that contains the Azure App Service web apps shown in the following table.

SC-500 Question 7

You purchase custom SSL certificates from a trusted third-party authority. To which apps can you assign the custom SSL certificates?

Options:

A.

App4 only

B.

App3 and App4 only

C.

App2, App1, and App4 only

D.

App1, App2, App3, and App4

Buy Now
Questions 8

You have an Azure subscription named Sub1 that contains multiple virtual machines. Sub1 has the Microsoft Defender Cloud Security Posture Management (CSPM) plan enabled.

You discover that Defender for Cloud falls to identify plaintext connection strings and SSH keys stored on the virtual machines.

You need to ensure that secrets can be identified on the virtual machines.

What should you do?

Options:

A.

Configure the Defender for Cloud data connector in Microsoft Sentinel.

B.

Enable agentless machine scanning.

C.

Deploy the Azure Monitor Agent to all the virtual machines.

D.

Enable Microsoft Defender for Key Vault.

Buy Now
Questions 9

You have an Azure Container Registry named Registry1-

You add role assignments for Registry! as shown in the following table.

SC-500 Question 9

SC-500 Question 9

Options:

Buy Now
Questions 10

You have a Microsoft Defender External Attack Surface Management (Defender EASM) resource for a company named Contoso. Ltd.

You need to update the Defender EASM workflow to meet the following requirements:

•Assets from a business domain that Contoso no longer owns must be removed from inventory.

•Findings that do NOT apply to confirmed inventory must NOT affect reported counts.

What should you do for each requirement? To answer, drag the appropriate actions to the correct requirements. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

SC-500 Question 10

Options:

Buy Now
Questions 11

You have a Microsoft Entra tenant named contoso.com that contains the users shown in the following table.

SC-500 Question 11

Microsoft Entra Privileged Identity Management (PIM) is used in contoso.com.

In PIM, the Password Administrator role has the following settings:

SC-500 Question 11

Options:

Buy Now
Questions 12

For each of the following statements, select Yes if the statement is true Otherwise, select No.

SC-500 Question 12

Options:

Buy Now
Questions 13

You need to configure Server1 to meet the technical requirements.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

SC-500 Question 13

Options:

Buy Now
Questions 14

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution: You create a playbook

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 15

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You add each virtual machine to a security group, and then add the security group to a role on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 16

Note. This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem

After you answer a question in this section, you will NOT be able to return. As a result these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution You create a hunting query.

Does this meet the goal’

Options:

A.

Yes

B.

No

Buy Now
Questions 17

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution: You create an analytics rule.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 18

You need to delegate a user to implement the planned change for Defender for Cloud. The solution must follow the principle of least privilege.

Which user should you choose?

Options:

A.

Admin1

B.

Admin2

C.

Admin3

D.

Admin4

Buy Now
Questions 19

You need to implement the function apps to meet the technical requirements.

Which apps should you include in the implementation?

Options:

A.

Fa1 and Fa2 only

B.

Fa2 and Fa3 only

C.

Fa1 and Fa3 only

D.

Fa1, Fa2, and Fa3

Buy Now
Questions 20

User1 has requested to use the AI Administrator role.

Which approvers can approve the request, and how long will User1 be an AI administrator after the role is approved? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

SC-500 Question 20

Options:

Buy Now
Questions 21

You need to implement the planned change for the AKS1 integration.

What should you configure for AKS1?

Options:

A.

application scaling

B.

a workload identity

C.

Secrets Store CSI Driver

D.

Kubernetes role-based access control (Kubernetes RBAC)

Buy Now
Questions 22

You need to configure Microsoft Sentinel to meet the technical requirements.

To what should you set Analytics retention for DnsEvents?

Options:

A.

2 years

B.

12 years

C.

180 days

D.

1 year

E.

6 years

Buy Now
Questions 23

You need to implement the planned change for SQLdb1

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point

Options:

A.

Create a compliance policy.

B.

Configure Microsoft Entra authentication for SQLServer1.

C.

Create a Conditional Access policy.

D.

Configure federated client identity for SQLdb1.

E.

Configure a user-assigned managed identity for SQLdb1.

Buy Now
Questions 24

For which storage accounts can you implement the planned changes for storage?

Options:

A.

storage1, storage2, storage3, and storage4

B.

storage1, storage2, and storage4 only

C.

storage2 and storage4 only

D.

storage1 and storage3 only

E.

storage2, storage3, and storage4 only

F.

storage1 only

Buy Now
Questions 25

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You create a private endpoint on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 26

You need to implement the planned change for storage2 The solution must meet the technical requirements for storage encryption.

What should you do?

Options:

A.

Enable purge protection for storage2.

B.

Create an encryption scope in storage2.

C.

Configure storage2 to use an account encryption key.

D.

Assign an Azure role-based access control (Azure RBAC) role to storage2.

Buy Now
Questions 27

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You create a user-assigned managed identity, assign the identity to each virtual machine, and then add each managed identity to a role on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 28

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution: You create an automation rule.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 29

You need to protect the applications hosted on AKS1. The solution must meet the technical requirements.

Which Defender for Cloud plan should you enable?

Options:

A.

Microsoft Defender for Servers

B.

Microsoft Defender for App Service

C.

Microsoft Defender for Containers

D.

Microsoft Defender for Resource Manager

E.

Microsoft Defender for Storage

Buy Now
Questions 30

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You add each virtual machine to a role on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 31

You need to configure the AKS1 and ID 1 managed identities to meet the technical requirements. The solution must follow the principle of least privilege.

Which role should you assign to each identity? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

SC-500 Question 31

Options:

Buy Now
Questions 32

Vou have a Microsoft Entra tenant that uses Microsoft Entra Agent ID. You have multiple Microsoft Foundry agents that have agent identities assigned. Vou dm OW that one of the identities is flagged as high risk duf in unusual sign-in activity. Vou need to ensure that agent access to resources is restricted automatically based on risk. What should you create?

Options:

A.

a Privileged Identity Management (PIM) activation policy

B.

a Microsoft Entra role assignment policy

C.

a Conditional Access policy for the identities

D.

an Access review for the identities

Buy Now
Questions 33

You have an Azure Storage account that contains a blob container named container 1 and a client application named App1. You need to enable App1 access to container1 by using Microsoft Entra authentication. What should you do ' To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

SC-500 Question 33

Options:

Buy Now
Questions 34

You have an Azure subscription that has the Microsoft Defender for Cloud Foundational Cloud Security Posture Management (CSPM) plan enabled.

You have an Amazon Web Services (AWS) account connected to Defender for Cloud for posture management.

In Defender for Cloud, security recommendations for the resources in Azure and AWS have a risk level of Not evaluated.

You need to ensure that Defender for Cloud assigns a risk level to the recommendations.

What should you do?

Options:

A.

Onboard all the virtual machines in the AWS account to Azure Arc.

B.

Enable Microsoft Defender for Servers Plan 2.

C.

Assign the CIS AWS Foundations v3.0.0 standard to the AWS account.

D.

Enable the Defender CSPM plan.

Buy Now
Questions 35

You have a Microsoft Foundry project that contains a model deployment named Deployment1.

Deployment1 contains an agent named Agent1 that uses an existing default guardrail configuration.

You discover that Agent1 generates tool calls that contain harmful language.

You need to ensure that Agent1 responses containing harmful content are prevented from running. The solution must prevent changes to the configuration of Deployment1.

What should you do?

Options:

A.

Create an automatic evaluation of the dataset of Agent1.

B.

Create a custom guardrail and assign it directly to Agent1.

C.

Fine-tune the model of Deployment1.

D.

Create a red teaming run for Agent1.

Buy Now
Questions 36

You have a virtual network named VNet1 that contains a subnet named Subnet1. Azure App Service is integrated with VNet1. You have an Azure SQL Database logical server named Server1 that contains a database named DB1. Server1 is accessible only by using a public IP address.

You need to ensure that Server1 does NOT use a public IP address and Azure App Service can still access Server1.

What should you create?

Options:

A.

a routing table

B.

an Azure Private Link service

C.

a private endpoint

D.

a service endpoint

Buy Now
Questions 37

You have an Azure subscription that contains an Azure Database for PostgreSQL instance named 081.

You plan to protect OBI by using Microsoft Defender for Cloud.

You need to configure Defender for Cloud to detect anomalous activities and database exploitations for 061. The solution must NOT affect any other databases.

What should you enable? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

SC-500 Question 37

Options:

Buy Now
Questions 38

You have an Azure subscription named Sub1 that contains a storage account named storage1. Sub1 has Microsoft Defender for Storage enabled. Defender for Storage has malware scanning enabled.

You need to configure a solution that automates the remediation of malware detected in storage1.

What should you include in the solution?

Options:

A.

Azure Logic Apps

B.

a Log Analytics workspace

C.

an alert rule

D.

Azure Policy

Buy Now
Questions 39

You have a Microsoft Defender External Attack Surface Management (Defender EASM) resource that discovers internet-facing assets for a company named Contoso, Ltd.

You need to classify the assets lo meet the following requirements.

• Third-party infrastructure assets must be tracked separately from assets owned by Contoso.

• Assets with unconfirmed ownership must remain outside the owned inventory until ownership is verified.

How should you classify the assets? To answer, drag the appropriate asset states to the correct assets. Each state may be used once, more than once or not at all. You may need to drag the split bar between panes or scroll to view content.

SC-500 Question 39

Options:

Buy Now
Questions 40

You have a Microsoft Sentinel workspace named Workspace1.

You hire a security consultant. You provide the consultant with a guest account named User1 in your Microsoft Entra tenant

You need to enable User1 to assign incidents in Workspace1.

Which roles should you assign to User1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

SC-500 Question 40

Options:

Buy Now
Exam Code: SC-500
Exam Name: Microsoft Certified: Cloud and AI Security Engineer Associate
Last Update: Sep 19, 2026
Questions: 135

PDF + Testing Engine

$52.5  $174.99

Testing Engine

$40.5  $134.99
buy now SC-500 testing engine

PDF (Q&A)

$34.5  $114.99
buy now SC-500 pdf
dumpsmate guaranteed to pass

24/7 Customer Support

DumpsMate's team of experts is always available to respond your queries on exam preparation. Get professional answers on any topic of the certification syllabus. Our experts will thoroughly satisfy you.

Site Secure

mcafee secure

TESTED 19 Sep 2026