This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Manage identity, access, and governance (20–25%)
--> Secure secrets and keys by using Azure Key Vault
--> Scan for secrets by using Defender Cloud Security Posture Management (Defender CSPM)
Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.
Overview
Secrets such as passwords, API keys, access tokens, private keys, connection strings, and other credentials can provide attackers with direct access to cloud resources. Accidentally exposing a secret in source code, deployment artifacts, virtual machines, or other cloud resources can therefore create a significant security risk.
For the SC-500 exam, you should understand how Microsoft Defender for Cloud uses Defender Cloud Security Posture Management (Defender CSPM) to discover exposed secrets, assess their potential impact, prioritize findings, and help security teams remediate them.
The key concept is:
Secret scanning is about discovering credentials that have been exposed where they shouldn’t be, understanding what those credentials can access, and prioritizing the exposure based on risk.
Defender for Cloud provides several forms of secret scanning. Under Defender CSPM, these capabilities can include scanning cloud deployment resources, code repositories, and machines, depending on the scenario and supported resource type.
What Is a Secret?
A secret is sensitive information that can be used to authenticate to or gain access to a resource.
Examples include:
- Passwords
- API keys
- Access tokens
- Personal access tokens (PATs)
- Client secrets
- Private keys
- Connection strings
- Shared access signatures
- Service credentials
- Deployment credentials
- Cloud provider credentials
Examples of potentially exposed secrets include:
- Microsoft Entra application client secrets
- Azure DevOps personal access tokens
- GitHub personal access tokens
- Azure Storage access keys
- Azure Container Registry access keys
- Azure App Configuration access keys
- Azure service keys
- Private SSH keys
- Database credentials
The danger isn’t simply that a secret exists. The danger is that someone who obtains the secret may be able to authenticate as the secret’s owner and access resources with the associated permissions.
Why Secret Scanning Matters
Consider a developer who accidentally commits an Azure credential to a source-code repository.
Even if the developer immediately deletes the credential from the file, the credential may still exist in:
- Previous Git commits
- Repository history
- Build artifacts
- Deployment files
- VM disks
- Configuration files
Deleting the visible copy doesn’t necessarily invalidate the credential.
An attacker who discovers the credential could potentially use it to:
- Authenticate to Azure or another service.
- Access the resources permitted by the credential.
- Move laterally through the environment.
- Access sensitive databases or storage.
- Modify or delete resources.
- Obtain additional credentials.
This is why secret discovery needs to be combined with credential rotation/revocation and least-privilege access.
Defender CSPM and Secret Scanning
Defender CSPM is the enhanced cloud security posture management capability in Microsoft Defender for Cloud.
It provides capabilities beyond basic security posture assessment, including risk-based analysis and advanced security insights.
For secret scanning, Defender CSPM can help identify exposed secrets and, importantly, help security teams understand the potential attack paths associated with those secrets.
Microsoft currently distinguishes several secret-scanning scenarios:
| Scanning type | What is scanned | Defender CSPM |
|---|---|---|
| Machine scanning | Secrets on supported VMs/instances | Yes |
| Cloud deployment resource scanning | Infrastructure/deployment resources | Yes |
| Code repository scanning | Exposed secrets in supported repositories | Yes |
| Runtime/resource context | Helps understand potential impact | Yes |
For the SC-500 exam, don’t think of secret scanning as simply a pattern-matching exercise. The security value comes from discovering the secret and determining what the secret could allow an attacker to do.
Secret Scanning in Code Repositories
One important Defender for Cloud scenario involves identifying secrets exposed in source-code repositories.
Defender for Cloud can surface exposed secrets from supported GitHub and Azure DevOps repositories.
The repository scanning capabilities rely on the relevant GitHub Advanced Security functionality. Defender for Cloud can then provide security teams with information about the exposed secret and its potential impact.
Examples of secrets that may be detected include:
- Tokens
- Passwords
- API keys
- Private keys
- Service credentials
Why repository history matters
A common exam trap is assuming that deleting a secret from the latest version of a file eliminates the exposure.
It doesn’t.
A secret committed in an earlier Git commit may remain in repository history.
Repository secret scanning can therefore identify secrets that exist in historical commits. For Azure DevOps, repository scanning detects existing secrets, including those in historical commits.
Important security principle
If a credential has been exposed:
Remove the secret from the repository AND revoke/rotate the credential.
Removing it from Git does not automatically make the credential unusable.
Secret Push Protection
Secret scanning should ideally detect a secret before it reaches the repository.
This is where secret push protection is important.
Push protection examines code being pushed to a repository and can prevent a detected secret from being committed.
There are therefore two related concepts:
Repository secret scanning
Looks for secrets that have already been committed.
Secret push protection
Attempts to prevent secrets from being committed in the first place.
Azure DevOps GitHub Advanced Security supports both repository secret scanning and secret push protection.
A useful way to remember the distinction is:
Scanning = detect existing exposure
Push protection = prevent new exposure
Cloud Deployment Secret Scanning
Secrets aren’t limited to source code.
Cloud deployment resources can also contain plaintext secrets.
For example, deployment artifacts or infrastructure-as-code-related resources might contain credentials that were accidentally exposed during deployment.
Defender for Cloud provides agentless cloud deployment secret scanning that uses cloud control-plane APIs to inspect supported deployment resources. Defender CSPM is required for this capability.
This is particularly important because a secret may appear during deployment even though it was not intentionally stored in source control.
Examples of potentially sensitive information include:
- Credentials
- Access keys
- Private keys
- Connection strings
- Tokens
The goal is to identify these exposures before they become an avenue for compromise.
Machine Secret Scanning
Defender for Cloud can also perform agentless secret scanning on supported machines.
With Defender CSPM or Defender for Servers Plan 2, supported Azure VMs and connected AWS/GCP instances can be scanned for secrets.
The scanning process is designed to minimize impact on the running machine.
At a high level:
- Defender for Cloud obtains a disk snapshot.
- The secret-scanning engine analyzes the snapshot.
- Metadata about discovered secrets is sent to Defender for Cloud.
- Security teams can investigate the findings.
This is useful for finding credentials that developers or administrators may have inadvertently left on a machine.
Agentless Secret Scanning
The term agentless is important for the SC-500 exam.
Agentless scanning means the security capability doesn’t require installing a security agent on every resource being scanned.
For machine secret scanning, Defender for Cloud can use disk snapshots and analyze them without directly installing an agent solely for this purpose.
For cloud deployment scanning, Defender for Cloud uses cloud control-plane APIs to inspect supported deployment resources.
Exam takeaway
If a question emphasizes:
- No agent installation
- Disk snapshots
- Cloud API/control-plane inspection
think agentless scanning.
What Information Does Defender for Cloud Provide?
Finding a secret is only the first step.
Security teams need enough context to determine:
How dangerous is this secret?
Defender for Cloud can provide rich metadata associated with secret findings.
For code repository findings, this can include information such as:
- File path
- Line number
- Column
- Commit hash
- File URL
- Security alert URL
- Information about whether the target resource exists
This context allows security teams to investigate the finding efficiently.
Secret Exposure and Lateral Movement
One of the most important concepts for SC-500 is lateral movement.
Suppose a repository contains a credential.
The credential might provide access to:
Code Repository | | exposed credential vAzure Resource | vSensitive Database
The repository itself may not be a critical resource.
However, the exposed credential could give an attacker access to something that is.
Defender CSPM can help identify these relationships and prioritize findings based on potential attack paths.
For example, Defender for Cloud can identify scenarios such as:
- An Azure DevOps repository containing a secret that can provide lateral movement to a SQL database.
- A publicly accessible Azure DevOps repository containing a secret that can provide lateral movement to a storage account.
This is a major distinction between simply finding secrets and performing risk-based security analysis.
Attack Path Analysis
Attack path analysis uses a graph-based approach to identify potentially exploitable paths through an environment.
Instead of asking only:
“Does this repository contain a secret?”
security teams can ask:
“Does this secret provide an attacker with a path to a high-impact resource?”
This is much more valuable from a security-prioritization perspective.
For example:
Public Repository | | exposed secret vAzure Credential | | permissions vStorage Account | vSensitive Data
The second scenario is generally more urgent than an exposed credential that has already expired and provides no access to resources.
Defender for Cloud uses attack-path analysis to help identify these potentially exploitable relationships.
Cloud Security Explorer
Cloud Security Explorer can be used to investigate relationships and risks within the cloud security graph.
For exposed secrets, relevant queries can include scenarios such as:
- Code repositories containing secrets
- Azure DevOps repositories containing secrets that can authenticate to object storage
- Azure DevOps repositories containing secrets that can authenticate to managed databases
Why is this useful?
Security teams can move beyond individual alerts and investigate relationships across the environment.
For example:
Which repositories contain secrets that could provide access to sensitive databases?
That’s much more useful than simply asking:
Which repositories have secret findings?
Recommendations for Exposed Secrets
Defender for Cloud can surface security recommendations when exposed secrets are discovered.
Examples include recommendations for:
- Azure DevOps repositories that have secret-scanning findings
- GitHub repositories that have secret-scanning findings
These recommendations help organizations identify resources that require remediation.
How Should an Exposed Secret Be Remediated?
Finding the secret is not enough.
A strong remediation process generally looks like this:
1. Identify the exposed credential
Determine:
- What type of credential is it?
- Where was it discovered?
- When was it exposed?
- What resource does it access?
2. Determine the potential impact
Ask:
- Is the credential still valid?
- What permissions does it have?
- What resources can it access?
- Can it enable lateral movement?
- Is the target resource internet-accessible?
3. Revoke or rotate the credential
This is one of the most important steps.
If an attacker could have obtained the credential, assume that simply deleting the visible copy isn’t sufficient.
Invalidate the compromised credential and issue a replacement.
4. Remove the secret from the exposed location
Remove the secret from:
- Source code
- Configuration files
- Deployment artifacts
- VM files
- Other inappropriate locations
For repository exposures, historical commits may also need to be addressed.
5. Store the replacement securely
Use an appropriate secret-management solution, such as Azure Key Vault, rather than placing credentials directly in source code.
6. Reduce permissions
Apply the principle of least privilege.
If a credential only needs read access to one resource, don’t give it broad administrative permissions.
7. Prefer short-lived credentials where appropriate
Short-lived credentials reduce the period during which a compromised credential can be exploited.
Microsoft specifically recommends considering short-lived secrets, such as replacing long-lived storage connection strings with appropriately scoped SAS tokens where suitable.
Secret Scanning vs. Secret Management
These concepts are related but serve different purposes.
| Capability | Purpose |
|---|---|
| Secret scanning | Finds exposed secrets |
| Secret push protection | Prevents secrets from being committed |
| Azure Key Vault | Securely stores and manages secrets |
| Credential rotation | Replaces compromised or aging credentials |
| RBAC | Controls who can access resources/secrets |
| Defender CSPM | Identifies posture risks and helps prioritize them |
| Attack paths | Identifies potentially exploitable relationships |
A common exam scenario might describe an organization that repeatedly discovers passwords in source code.
The correct security strategy isn’t simply:
“Run secret scanning more frequently.”
A more complete approach is:
Detect → revoke/rotate → remove → securely store → prevent recurrence → minimize permissions.
Important SC-500 Exam Distinctions
Defender CSPM vs. Defender for Servers
Don’t confuse the plans.
Defender CSPM provides advanced cloud security posture capabilities and supports several secret-scanning scenarios.
Defender for Servers Plan 2 can also provide machine secret scanning.
For machine scanning, Microsoft currently lists Defender CSPM or Defender for Servers Plan 2 as supported plans.
Secret Scanning vs. Vulnerability Scanning
These are different security capabilities.
Secret scanning looks for exposed credentials and other sensitive authentication material.
Vulnerability scanning looks for software vulnerabilities and weaknesses.
For example:
- Exposed API key → secret scanning
- Outdated OpenSSL version → vulnerability scanning
- Exposed private SSH key → secret scanning
- SQL injection vulnerability → vulnerability/code scanning
Secret Scanning vs. Azure Key Vault
Azure Key Vault is not primarily a secret-discovery tool.
Key Vault is used to securely store and manage secrets, keys, and certificates.
Defender CSPM secret scanning helps discover secrets that have been exposed elsewhere.
A good architecture is therefore:
Application | | securely retrieves secret vAzure Key Vault | vProtected credentialDefender CSPM | +----> Detects accidentally exposed secrets
Key Exam Takeaways
For the SC-500 exam, remember these points:
- Secrets can provide attackers with authentication and access to resources.
- Defender for Cloud can identify exposed secrets across several supported environments.
- Defender CSPM provides advanced posture and risk-analysis capabilities associated with secret exposure.
- Code repository scanning can identify secrets in repository history.
- Push protection helps prevent new secrets from being committed.
- Cloud deployment secret scanning is agentless and uses cloud control-plane APIs.
- Machine secret scanning can use disk snapshots without requiring an agent solely for the scanning operation.
- Secret findings can include rich contextual metadata.
- Defender CSPM can help identify potential lateral movement involving exposed secrets.
- Attack path analysis helps prioritize secrets based on their potential impact.
- Cloud Security Explorer can be used to investigate relationships involving exposed secrets.
- Simply deleting an exposed secret from source code is insufficient if the credential remains valid.
- Compromised credentials should generally be revoked or rotated.
- Replacement secrets should be stored in an appropriate secret-management solution such as Azure Key Vault.
- Least privilege limits the damage if a secret is compromised.
Practice Exam Questions
Question 1
A security team discovers an Azure DevOps repository containing a credential that can authenticate to an Azure SQL database. The team wants to determine whether the exposed credential creates a potential path to a high-impact resource.
Which Defender for Cloud capability is most appropriate?
A. Azure Resource Locks
B. Azure Policy
C. Microsoft Defender Vulnerability Management
D. Attack path analysis
Answer: D
Explanation
Attack path analysis can identify potentially exploitable relationships between exposed secrets and high-impact resources. In this scenario, the important question isn’t simply whether a secret exists, but whether the secret can provide a path from the repository to the SQL database.
Azure Policy enforces governance, vulnerability management identifies software vulnerabilities, and resource locks protect Azure resources from deletion or modification. They don’t provide this attack-path analysis.
Question 2
A company wants to detect secrets that developers have accidentally committed to an Azure DevOps repository, including secrets that were committed several months ago.
Which capability should the security team use?
A. Azure Monitor
B. Repository secret scanning
C. Azure Firewall
D. Microsoft Entra Conditional Access
Answer: B
Explanation
Repository secret scanning is designed to identify exposed credentials in source repositories, including existing secrets in repository history.
Azure Monitor provides monitoring and telemetry, Azure Firewall controls network traffic, and Conditional Access controls authentication conditions. None of these capabilities specifically scan Git repositories for exposed secrets.
Question 3
An organization wants to prevent developers from accidentally pushing credentials into an Azure DevOps repository in the first place.
Which capability should be implemented?
A. Cloud Security Explorer
B. Attack path analysis
C. Secret push protection
D. Azure Resource Manager locks
Answer: C
Explanation
Secret push protection is designed to detect secrets during pushes and prevent them from being committed.
Repository secret scanning is primarily concerned with detecting secrets that already exist. Attack path analysis evaluates potential attack paths, while resource locks protect Azure resources from certain management operations.
Question 4
A security engineer wants Defender for Cloud to scan supported Azure virtual machines for exposed credentials without installing an agent specifically for secret scanning.
Which capability should the engineer use?
A. Microsoft Sentinel analytics rules
B. Azure Policy remediation
C. Microsoft Defender for Cloud agent-based vulnerability assessment
D. Agentless machine secret scanning
Answer: D
Explanation
Defender for Cloud supports agentless machine secret scanning. It can analyze disk snapshots to identify supported secrets without requiring a dedicated secret-scanning agent on the VM.
The other options address different security or monitoring requirements.
Question 5
A developer discovers an API key committed to a public repository. The developer immediately deletes the API key from the source file.
What should the security team do next?
A. Assume the key is no longer usable
B. Delete the repository
C. Revoke or rotate the exposed credential
D. Disable Azure Monitor
Answer: C
Explanation
Deleting the key from the current source file does not necessarily invalidate it. The credential may remain in repository history and may already have been copied by an attacker.
The exposed credential should therefore be revoked or rotated, followed by removal of the exposed secret and secure storage of its replacement.
Question 6
A security team wants to investigate code repositories that contain secrets and determine what cloud resources those secrets may be able to authenticate to.
Which Defender for Cloud capability can help with this investigation?
A. Cloud Security Explorer
B. Azure Bastion
C. Azure DDoS Protection
D. Azure Resource Locks
Answer: A
Explanation
Cloud Security Explorer allows security teams to query relationships in the cloud security graph. It can be used to investigate exposed secrets and relationships between repositories, credentials, and resources.
The other services serve network access, DDoS protection, or resource protection purposes.
Question 7
An organization has enabled Defender CSPM and wants to identify plaintext secrets exposed in supported cloud deployment resources.
Which statement is correct?
A. The deployment resources must first be converted to Git repositories
B. Defender CSPM provides agentless cloud deployment secret scanning
C. Secret scanning requires installing an agent on every deployment resource
D. Only passwords stored in Azure Key Vault can be detected
Answer: B
Explanation
Defender CSPM supports agentless scanning of supported cloud deployment resources. The scanning uses cloud control-plane APIs to detect plaintext secrets.
The capability does not require deployment resources to be Git repositories or require an agent specifically for the scanning process.
Question 8
A secret-scanning finding identifies a credential that has access to a highly sensitive database. Another finding identifies an expired credential that no longer provides access to any resource.
Which finding should generally receive higher priority?
A. The expired credential
B. Both findings must always receive identical priority
C. The finding with the older discovery date
D. The valid credential that can access the sensitive database
Answer: D
Explanation
Risk prioritization should consider the potential impact of the secret.
A valid credential that can access a highly sensitive database represents a potentially exploitable path to a critical resource and should generally receive greater urgency than an expired credential that cannot authenticate to anything.
This illustrates the value of Defender CSPM’s contextual and risk-based analysis.
Question 9
An organization discovers that a secret has been exposed in source code. The company wants to prevent similar credentials from being exposed in future development activities.
Which approach provides the strongest overall protection?
A. Combine secret scanning, push protection, secure secret storage, credential rotation, and least privilege
B. Rely exclusively on repository deletion
C. Store credentials in source-code comments
D. Increase the lifetime of credentials
Answer: A
Explanation
A defense-in-depth approach combines multiple controls:
- Secret scanning detects existing exposures.
- Push protection helps prevent new exposures.
- Secure secret storage, such as Azure Key Vault, keeps credentials out of source code.
- Credential rotation limits the lifetime of compromised credentials.
- Least privilege limits what a compromised credential can access.
The other approaches either fail to address the underlying risk or make the risk worse.
Question 10
A security engineer is reviewing an exposed secret discovered by Defender for Cloud. The engineer wants detailed information that can help locate the secret in the repository and investigate the original exposure.
Which information may be available with a repository secret finding?
A. Only the Azure subscription name
B. Only the repository owner
C. File path, line number, commit hash, and file URL
D. Only the IP address of the developer
Answer: C
Explanation
Defender for Cloud can provide rich metadata associated with repository secret findings, including information such as the file path, line number, column, commit hash, file URL, and security-alert URL.
This information helps security teams quickly locate and investigate the exposure and determine the appropriate remediation.
Final Exam Tip
When you see “secrets” in an SC-500 scenario, don’t automatically think only about Azure Key Vault. Think about the entire lifecycle:
Prevent → Discover → Assess → Prioritize → Revoke/Rotate → Remove → Secure → Monitor
And when the question introduces a secret plus a database, storage account, or other high-value resource, pay particular attention to lateral movement and attack paths. That is often the clue that the question is testing the risk-analysis capabilities of Defender CSPM rather than simple secret detection.
Go to the SC-500 Exam Prep Hub main page
