SC-500 Practice Exam #2

This practice exam is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.

Implementing End-to-End Security Controls for Cloud and AI Workloads


Section 1: Manage Identity, Access, and Governance


Question 1 — Privileged Identity Management

A company uses Microsoft Entra Privileged Identity Management (PIM) to control access to privileged roles. A security administrator must ensure that administrators cannot retain permanent active assignments to a highly privileged role. Administrators must request access when needed, provide justification, and activate the role for a limited period.

Which configuration best meets these requirements?

A. Assign the role permanently as active and require multifactor authentication at every sign-in.

B. Create eligible assignments, configure activation requirements, and set a maximum activation duration.

C. Assign the role through an Azure Policy initiative and configure a resource lock.

D. Create a Conditional Access policy that blocks all users outside the corporate network.

Answer: B

Explanation: Eligible assignments allow users to activate a role when required rather than having permanent active privileges. PIM can require justification, multifactor authentication, approval, and a limited activation duration, depending on the role and configuration.

Conditional Access can add authentication and access restrictions, but it does not replace PIM’s eligible-assignment and activation workflow. Azure Policy and resource locks govern Azure resources, not Microsoft Entra privileged-role activation.


Question 2 — Authentication Methods

A company wants employees to sign in using phishing-resistant authentication. The security team wants to prioritize a method that does not rely on a password and is designed to resist credential phishing.

Which option is the best fit?

A. SMS one-time passcodes

B. Email one-time passcodes

C. Security questions

D. Passkeys using FIDO2 security keys

Answer: D

Explanation: FIDO2 security keys and supported passkey implementations provide phishing-resistant authentication. Authentication is cryptographically bound to the legitimate relying party, helping prevent credentials from being reused on a fraudulent website.

SMS and email codes can be vulnerable to phishing or interception, and security questions are not a strong authentication method.

Exam tip: Distinguish between merely adding another authentication step and using a phishing-resistant authentication method.


Question 3 — Azure RBAC and Least Privilege

A developer must restart virtual machines in a specific resource group. The developer must not be able to create virtual machines, modify network security groups, or assign roles to other users.

Which approach best follows least privilege?

A. Assign Owner at the subscription scope.

B. Assign Contributor at the subscription scope.

C. Assign a suitable narrowly scoped role that permits the required VM restart operation at the resource group or resource scope.

D. Assign User Access Administrator at the resource group scope.

Answer: C

Explanation: Azure RBAC assignments should grant only the required actions at the narrowest practical scope. A suitable built-in role or custom role can permit VM restart operations without granting broad resource-management or role-assignment permissions.

Owner and Contributor are too broad for this requirement. User Access Administrator focuses on managing access assignments rather than restarting VMs.


Question 4 — Scenario: Azure Policy and Resource Locks

A production resource group contains a critical Azure resource. The organization wants to accomplish two things:

  1. Prevent accidental deletion of the resource.
  2. Require newly deployed storage accounts to use secure transfer.

Which combination of controls should be used?

A. A CanNotDelete resource lock and an Azure Policy definition enforcing secure transfer.

B. A ReadOnly resource lock and a Microsoft Sentinel automation rule.

C. A PIM eligible assignment and a Key Vault certificate.

D. A Defender for Cloud recommendation and a network security group.

Answer: A

Explanation: A CanNotDelete lock prevents deletion while allowing permitted modifications. Azure Policy can audit or deny storage-account configurations that do not meet the secure-transfer requirement.

A ReadOnly lock is more restrictive and can prevent many write operations. Sentinel automation rules and PIM do not directly enforce these two resource requirements.

Important distinction: Resource locks protect resources from certain management operations. Azure Policy evaluates and enforces resource configuration requirements.


Question 5 — Fill in the Blank: Azure Resource Access

An application hosted on an Azure resource must access Azure Key Vault without embedding a client secret in its code. The application should authenticate using an identity managed by Azure.

The capability to configure is a __________ identity.

A. guest

B. managed

C. consumer

D. shared

Answer: B. managed

Explanation: Managed identities provide Azure resources with identities that can authenticate to supported services. Azure manages the credentials, reducing the need to store and rotate application secrets.

Authentication alone does not grant access to Key Vault. The managed identity must also receive the appropriate authorization, such as a suitable Key Vault data-plane role when using Azure RBAC authorization.


Question 6 — Multiple Answer: Azure Backup Security

An organization wants to strengthen the security of its Azure Backup recovery points against accidental or malicious deletion.

Which two controls should the security team consider?

A. Configure Azure Bastion for all backup vaults.

B. Enable Microsoft Sentinel syslog collection.

C. Use Azure Backup security features such as soft delete and, where supported, immutability.

D. Configure Multi-User Authorization (MUA) for supported critical backup operations.

Answer: C and D

Explanation: Azure Backup provides several layers of protection for recovery points and critical operations.

  • Soft delete helps protect backup data from accidental or malicious deletion by retaining deleted backup data for a configured or service-defined period.
  • Immutability, where supported and appropriately configured, helps prevent protected backup data from being modified or deleted.
  • Multi-User Authorization (MUA) adds an approval layer for supported critical operations, reducing the risk of a single compromised administrator destroying backups.

Bastion is for secure VM administration. Syslog collection supports monitoring but does not itself protect recovery points.


Question 7 — Scenario: Securing an API Plugin


A developer is building an API plugin for a declarative agent. The API accesses confidential business data and must verify the identity of the caller. The team wants delegated access so that the API can act within the signed-in user’s permitted access.

Which authentication approach most directly supports this requirement?

A. Publish the API without authentication and rely on network restrictions.

B. Embed a shared administrator password in the plugin definition.

C. Use a managed identity for the API and assume it automatically represents every user’s delegated permissions.

D. Configure an appropriate Microsoft identity platform OAuth authentication flow with delegated permissions and consent.

Answer: D

Explanation: OAuth-based authentication with delegated permissions allows an application to access an API on behalf of a signed-in user, within the granted permissions and consent framework.

A managed identity can authenticate an Azure-hosted workload as itself, but it does not automatically represent the user’s delegated permissions. Network restrictions are useful defense in depth, not a replacement for API authentication and authorization.


Section 2: Secure Storage, Databases, and Networking


Question 8 — Scenario: Azure Storage Network Restrictions

A company stores confidential files in an Azure Storage account. Only clients on approved corporate networks should be able to connect to the storage service. The security team also wants to retain identity-based authorization for users accessing blobs.

Which configuration best meets these requirements?

A. Enable anonymous blob access and use Azure Policy to audit downloads.

B. Assign Storage Blob Data Contributor to all employees and rely on storage-account keys for network restrictions.

C. Configure the storage firewall to allow approved network paths and use Microsoft Entra ID-based authorization with appropriate data-plane permissions.

D. Enable Microsoft Defender for Storage and leave the storage account’s network access unrestricted.

Answer: C

Explanation: The storage firewall or network access settings restrict which network paths can reach the storage account. Microsoft Entra ID-based authorization and appropriate data-plane roles control what an authenticated identity can do with blob data.

Defender for Storage provides additional threat protection, but it does not replace network restrictions or authorization.


Question 9 — Multiple Answer: Azure SQL Security

A financial application uses Azure SQL Database. Auditors require a record of database activity, and the security team wants to detect suspicious database behavior and potential threats.

Which two capabilities should be configured?

A. Azure SQL auditing

B. Azure Bastion

C. Microsoft Defender for Databases

D. Azure Firewall Manager only

Answer: A and C

Explanation:

  • Azure SQL auditing records database events to support investigation, accountability, and compliance.
  • Microsoft Defender for Databases adds database threat-protection capabilities and can surface suspicious activities and security recommendations.

Bastion provides secure administrative access to VMs. Azure Firewall Manager manages firewall deployments and policies, not SQL auditing.


Question 10 — Scenario: Network Security Groups

An application has a web tier and a database tier in separate subnets. The database must accept connections from the web tier on TCP port 1433 but must not accept direct connections from the internet.

Which design is most appropriate?

A. Assign a public IP address to the database and use a broad outbound NSG rule.

B. Use an NSG rule to allow the required database traffic from the web tier, with other inbound traffic denied by the applicable rules.

C. Configure Azure Bastion to forward all application traffic to the database.

D. Enable Microsoft Defender for SQL and remove the database subnet’s network controls.

Answer: B

Explanation: Network security groups filter inbound and outbound traffic using rules that specify source, destination, port, protocol, and priority. An appropriately scoped rule can allow the web tier to connect to the database while blocking other unwanted connections.

NSGs are stateful, and their rules are evaluated by priority. Ensure that the effective rules and network architecture actually prevent direct internet access; simply adding an allow rule is not enough.


Question 11 — Matching: Private Connectivity

Match each Azure networking capability to its primary purpose.

CapabilityPurpose
1. Azure Private EndpointA. Encrypted connectivity between networks over a VPN
2. Azure VPN GatewayB. Filter traffic using network security rules at a subnet or network interface
3. Network Security GroupC. Provide a private IP-based connection to a supported service
4. Azure FirewallD. Centralized network traffic inspection and filtering

Answer

  • 1 → C
  • 2 → A
  • 3 → B
  • 4 → D

Explanation: A private endpoint maps a supported service to a private IP address in a virtual network. VPN Gateway provides VPN connectivity. NSGs filter network traffic at subnet or network-interface scope. Azure Firewall provides centralized network traffic filtering and inspection.

Exam trap: Private Link, VPN Gateway, NSGs, and Azure Firewall are complementary controls, not interchangeable services.


Question 12 — Scenario: Azure Key Vault Authorization

An application can successfully authenticate to Azure Key Vault using its managed identity, but it receives an authorization error when attempting to retrieve a secret. The vault uses Azure role-based access control for its data plane.

What should the administrator do?

A. Assign the managed identity an appropriate Key Vault data-plane role, such as Key Vault Secrets User, at the appropriate scope.

B. Assign the managed identity Reader at the subscription scope.

C. Enable Azure Bastion on the Key Vault.

D. Create a Sentinel playbook that retries the secret request.

Answer: A

Explanation: Authentication establishes the identity; authorization determines what that identity can access. With the Azure RBAC permission model, retrieving secrets requires an appropriate data-plane role, such as Key Vault Secrets User, at a suitable scope.

The Reader role generally provides control-plane read access to Azure resources; it does not grant permission to read secret values. A playbook cannot correct a missing authorization assignment.


Question 13 — Multiple Answer: Azure SQL Data Protection

A company wants to protect sensitive information in Azure SQL Database. Its requirements include encrypting stored database data and maintaining an audit trail of database activity.

Which two features best address these requirements?

A. Azure Bastion and JIT VM access

B. Azure Private Link and NSGs only

C. Microsoft Sentinel automation rules and Azure Policy only

D. Transparent Data Encryption (TDE) and Azure SQL auditing

Answer: D

Explanation: TDE encrypts database files and associated data at rest. Azure SQL auditing records selected database events for security investigation and compliance.

These controls address different objectives: encryption protects data at rest, while auditing supports accountability and investigation. Neither feature alone replaces identity controls, network security, or other data-protection measures.


Question 14 — Fill in the Blank: Azure Network Diagnostics

An administrator wants to determine which network security rules apply to a network interface and investigate why traffic is being allowed or denied.

The administrator should use Azure Network Watcher __________ security rules.

A. export

B. effective

C. privileged

D. delegated

Answer: B. effective

Explanation: Azure Network Watcher provides tools for examining effective security rules on a network interface. These help administrators understand the combined effect of applicable NSG rules and troubleshoot connectivity.

This is particularly useful when subnet-level and network-interface-level rules interact.


Question 15 — Scenario: Azure Private Link

An organization hosts a database service that supports Azure Private Link. The company wants clients in a virtual network to connect using a private IP address and wants to disable public network access where the service supports that configuration.

Which approach is most appropriate?

A. Create a public IP address and restrict access using a password.

B. Configure an NSG without creating a private connection to the service.

C. Create a private endpoint, configure the required name resolution, and disable public network access if supported and required.

D. Enable Microsoft Defender for Databases and assume the service no longer has a public endpoint.

Answer: C

Explanation: A private endpoint provides private IP-based connectivity to a supported service. Correct DNS configuration is important so that clients resolve the service name to the intended private endpoint. Where supported, disabling public network access provides an additional control.

A private endpoint does not automatically mean the public endpoint is disabled; that must be configured separately when the service supports it.


Section 3: Secure Compute


Question 16 — Scenario: Trusted Launch and Disk Encryption

A company is deploying a new Azure VM for a sensitive workload. The security team requires protection against boot-level attacks and encryption of data stored on the VM’s disks.

Which combination most directly addresses both requirements?

A. Azure Bastion and Microsoft Sentinel

B. Trusted Launch and an appropriate VM disk-encryption configuration

C. Azure Policy and Microsoft Entra PIM only

D. A network security group and a public IP address

Answer: B

Explanation: Trusted Launch provides VM security features such as Secure Boot and virtual TPM. Disk encryption protects data stored on supported VM disks.

These controls protect different layers. Trusted Launch does not, by itself, mean that all disk-encryption requirements have been met.


Question 17 — Multiple Answer: Azure Kubernetes Service

A security team is reviewing an Azure Kubernetes Service (AKS) deployment. It wants to reduce workload exposure and improve container security.

Which two actions are appropriate?

A. Review and apply AKS network and workload-isolation controls.

B. Enable Microsoft Defender for Containers for relevant protection and security insights.

C. Give every workload cluster Owner permissions on the subscription.

D. Make all container images publicly accessible to simplify deployment.

Answer: A and B

Explanation: AKS security is layered. Network policies and appropriate isolation controls help restrict workload communication, while Defender for Containers provides security capabilities for containerized environments.

Broad subscription permissions and publicly exposing container images increase risk rather than reducing it.


Question 18 — Scenario: Just-in-Time VM Access

Administrators need occasional RDP access to a group of Azure VMs. Security policy requires that management ports not remain unnecessarily exposed and that access requests be time-limited.

Which capability best meets this requirement?

A. Azure Storage firewall rules

B. Microsoft Purview DSPM

C. Azure SQL auditing

D. Just-in-time (JIT) VM access

Answer: D

Explanation: JIT VM access reduces persistent exposure of management ports by allowing access to be requested for a limited time under configured conditions. It is commonly used to reduce exposure of ports such as RDP and SSH.

JIT is not a replacement for identity authorization, network controls, or monitoring, but it directly addresses the requirement for time-limited management-port access.


Question 19 — Scenario: Azure App Service and Web Traffic

A company hosts a public web application on Azure App Service. The security team wants to protect the application from common web attacks, including malicious HTTP requests that match known attack patterns.

Which option is the best fit when the design calls for a Web Application Firewall (WAF)?

A. Azure Machine Configuration

B. Azure Backup soft delete

C. A supported WAF deployment, such as Azure Application Gateway WAF or Azure Front Door WAF, positioned to inspect the application’s web traffic

D. Microsoft Entra PIM

Answer: C

Explanation: A WAF can inspect HTTP(S) traffic and help protect web applications against common web exploits. The appropriate WAF product and deployment pattern depend on the application’s ingress architecture and requirements.

PIM controls privileged identity access, Azure Machine Configuration assesses or enforces machine configuration, and Backup soft delete protects backup data.


Question 20 — Matching: Application and Container Security

Match each technology or capability with its primary purpose.

TechnologyPurpose
1. Microsoft Defender for ContainersA. Secure API access, traffic policies, and backend integration
2. Azure API ManagementB. Assess or enforce supported machine configuration settings
3. Azure Machine ConfigurationC. Detect container-related risks and provide container security capabilities
4. Azure BastionD. Secure administrative access to Azure VMs

Answer

  • 1 → C
  • 2 → A
  • 3 → B
  • 4 → D

Explanation: Defender for Containers supports container security. API Management helps secure and govern APIs and their backend access. Azure Machine Configuration helps assess and enforce supported configuration settings on machines. Bastion provides secure RDP/SSH access to VMs.


Question 21 — Scenario: AI Guardrails

A company deploys an AI application using Microsoft Foundry. Testing reveals that the model sometimes returns harmful content and can be manipulated by adversarial prompts. The company wants to apply configurable controls to evaluate prompts and responses.

Which approach is most appropriate?

A. Enable Azure Bastion and restrict RDP access.

B. Configure and test appropriate Foundry guardrails, including relevant content filters and Prompt Shields.

C. Enable Azure SQL auditing.

D. Assign the AI application the Contributor role at the subscription scope.

Answer: B

Explanation: Microsoft Foundry guardrails can evaluate model interactions and apply controls such as content filters, blocklists, and Prompt Shields. The appropriate controls should be configured and validated against the application’s risk profile.

Guardrails help mitigate unsafe interactions and prompt-injection risks, but they do not eliminate all AI risks. Identity, data access, monitoring, and application-layer controls remain necessary.


Question 22 — Multiple Answer: AI Identity and Data Security

An organization has deployed AI agents that can access Microsoft 365 data and Azure resources. Security wants to assess risks caused by excessive agent permissions and overexposed organizational data.

Which two actions are appropriate?

A. Use Microsoft Defender XDR to investigate AI agent identities and assess potential blast radius.

B. Enable anonymous access to SharePoint so that agents do not need authorization.

C. Use Microsoft Purview Data Security Posture Management to identify relevant AI data risks and overexposure.

D. Replace all agent identities with a single shared administrator account.

Answer: A and C

Explanation: Microsoft Defender XDR can help discover AI agents and analyze identity-related risks and attack paths. Microsoft Purview DSPM helps identify data security risks associated with AI usage and data exposure.

Shared administrator accounts and anonymous access undermine least privilege and make it harder to establish accountability. Microsoft’s current AI security learning path covers both Entra Agent ID risk analysis and Purview DSPM for AI data risks.


Question 23 — Fill in the Blank: AI Traffic Security

An organization wants to apply centralized security and governance controls to model traffic for AI applications built with Microsoft Foundry. The relevant capability in the SC-500 learning path is AI Gateway in Azure __________ Management.

A. Identity

B. Storage

C. Firewall

D. API

Answer: D. API

Explanation: The SC-500 AI security learning path covers configuring AI Gateway in Azure API Management for Microsoft Foundry. The gateway can provide a centralized point for applying access restrictions, governance, and monitoring to AI model traffic.

AI Gateway complements other controls, including agent identity security, Foundry guardrails, and Defender for Cloud workload protection.


Section 4: Manage and Monitor Security Posture


Question 24 — Scenario: Prioritizing Cloud Security Risks

A security team uses Microsoft Defender for Cloud to assess hundreds of security recommendations. The team wants to identify issues that could contribute to a realistic attack path to a critical database, rather than simply fixing recommendations in alphabetical order.

Which capability is most appropriate?

A. Azure Backup soft delete

B. Microsoft Entra password protection

C. Defender CSPM attack path analysis

D. Microsoft Sentinel workspace retention

Answer: C

Explanation: Defender CSPM attack path analysis helps identify chains of security issues that could expose important resources to attack. It provides context for prioritizing risks based on potential attack paths rather than treating every recommendation as equally urgent.

For example, an internet-exposed workload with excessive permissions and access to a sensitive database may deserve higher priority than an isolated configuration issue. Attack path analysis and Cloud Security Explorer are covered in Microsoft’s Defender for Cloud learning path.


Question 25 — Multiple Answer: Microsoft Sentinel Data Collection

A company is onboarding network security appliances and Windows servers to Microsoft Sentinel. The appliances can send Common Event Format (CEF) messages, while Windows servers use Windows Event Forwarding (WEF).

Which two statements are correct?

A. CEF collection and Windows Security event collection using DCRs are distinct ingestion configurations.

B. Enabling a Sentinel automation rule automatically configures every appliance to send logs.

C. WEF eliminates the need to configure the appropriate data collection path into Azure Monitor and Sentinel.

D. A Sentinel playbook must be used to parse every CEF message before it can be ingested.

Answer: A

Explanation: CEF and Windows Security events use different collection configurations. For Windows Security events, DCRs can define which events are collected, including scenarios involving WEF. CEF collection requires the appropriate forwarding and ingestion setup for the source appliance.

Automation rules and playbooks help automate security operations; they do not automatically configure log sources or replace ingestion pipelines.

Important: This is a multiple-answer-style question, but only A is correct as written. In a live exam, always follow the number of answers requested and evaluate each option independently.


Question 26 — Scenario: Defender for Cloud Multicloud Coverage

An organization has workloads in Azure and AWS. The security team can see Azure recommendations in Defender for Cloud but does not have the expected security posture visibility for its AWS environment.

What should the team do first?

A. Deploy Azure Bastion in the AWS account.

B. Configure the appropriate AWS connector and required integration settings in Defender for Cloud, then verify the connected resources and enabled capabilities.

C. Create an Azure Policy assignment directly on the AWS resources.

D. Enable Microsoft Sentinel’s Windows Security Events connector.

Answer: B

Explanation: Defender for Cloud can integrate with AWS to provide security posture visibility and, depending on the configured plans and integration, workload protection. The security team should configure the appropriate connector, authentication, scope, and required plans, then verify that the intended resources are covered.

Azure Policy does not directly govern AWS resources in the same way it governs Azure resources. A Sentinel Windows event connector does not establish Defender for Cloud’s AWS integration.


Question 27 — Matching: Security Posture Tools

Match each capability with the task it most directly supports.

CapabilityTask
1. Defender CSPMA. Assess compliance against regulatory frameworks and identify control gaps.
2. Defender for Cloud regulatory complianceB. Discover and investigate external attack-surface exposure
3. Microsoft Defender EASMC. Assess cloud posture and prioritize security risks
4. Microsoft Defender for Servers vulnerability assessmentD. Identify vulnerabilities on covered servers and VMs

Answer

  • 1 → C
  • 2 → A
  • 3 → B
  • 4 → D

Explanation: These tools support related but different security outcomes:

  • Defender CSPM identifies posture issues and helps prioritize risk.
  • Regulatory compliance evaluates the environment against selected security standards and frameworks.
  • Defender EASM discovers and assesses externally visible assets.
  • Defender for Servers vulnerability assessment identifies vulnerabilities on covered servers and VMs.

Question 28 — Scenario: Security Copilot Agent Permissions

A company wants to deploy a partner-built agent from Microsoft Security Store. During setup, the agent requests permissions to access Microsoft security product data. The agent cannot be fully configured until the required permissions are approved.

Which action should the organization expect to take?

A. Grant the agent unrestricted subscription Owner access without reviewing its requested permissions.

B. Disable all Microsoft Entra authentication requirements for the agent.

C. Remove all plugins and assume the agent will retain its original capabilities.

D. Have an appropriately authorized Global Administrator review and approve the required Microsoft product permissions, then complete the remaining setup using an authorized Security Copilot role.

Answer: D

Explanation: Partner-built Security Copilot agents that require access to Microsoft product data can require Global Administrator approval of their requested permissions. The administrator should review the requested permissions and approve only as appropriate. An authorized Security Copilot Owner or Contributor can then complete the remaining setup steps.

The key principle is to review and approve permissions deliberately rather than granting broad access by default. Acquiring a partner agent and configuring its operational permissions are related but distinct steps.


Question 29 — Fill in the Blank: Defender for Cloud AI Protection

A company wants to secure AI workloads through Microsoft Defender for Cloud. The team wants to review AI-related security posture insights, detect runtime threats, and investigate security alerts.

The Microsoft Defender for Cloud dashboard specifically associated with these AI-related posture insights is the Data & __________ security dashboard.

A. Identity

B. Network

C. AI

D. Backup

Answer: C

Explanation: The dashboard is called the Data & AI security dashboard. It helps teams review insights related to AI security posture.

Defender for Cloud AI workload protection also involves enabling the appropriate AI protection plan, assessing posture through CSPM, detecting runtime threats through workload protection, and investigating incidents in Microsoft Defender XDR.


Question 30 — Scenario: Investigating a Suspicious AI Agent

An organization detects an AI agent that appears to have access to more resources than it needs. The security team wants to understand which resources could be affected if the agent’s identity were compromised and whether the agent has risky paths to sensitive data.

Which approach is most appropriate?

A. Use Microsoft Defender XDR to discover the agent and investigate its identity-related risks and potential blast radius.

B. Use Azure Storage lifecycle management to delete old files.

C. Use Azure Bastion to rotate the agent’s permissions.

D. Use Azure SQL auditing as the sole tool for analyzing all agent identity relationships.

Answer: A

Explanation: Microsoft Defender XDR can help security teams discover AI agents and investigate identity-related risks, including potential blast radius and attack paths. This helps determine which resources or data might be exposed if an agent identity is compromised.

The investigation should be followed by remediation, such as reducing excessive permissions, correcting access assignments, and reviewing the agent’s identity lifecycle. Microsoft’s current AI security learning path specifically covers discovering AI agents and assessing their blast radius.


What to review after this exam

Focus especially on the distinctions that commonly drive scenario questions:

  • Authentication vs. authorization: successful sign-in does not automatically grant access to Key Vault or other resources.
  • Azure Policy vs. resource locks: configuration governance is different from protection against resource deletion or modification.
  • Private endpoints vs. public access: creating a private endpoint does not necessarily disable a service’s public endpoint.
  • Trusted Launch vs. disk encryption: boot integrity and encryption at rest solve different problems.
  • Defender CSPM vs. workload protection: posture management identifies and prioritizes weaknesses; workload protection detects threats to supported workloads.
  • Sentinel ingestion vs. automation: connectors and collection configurations bring logs into the workspace; automation rules and playbooks support response workflows.
  • AI guardrails vs. AI identity controls: guardrails evaluate model interactions, while identity and access controls govern which resources an agent can reach.

Go to the SC-500 Exam Prep Hub main page

Leave a Reply