This practice exam is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
Implementing End-to-End Security Controls for Cloud and AI Workloads
Question 1 — Single Answer
Skill area: Manage identity, access, and governance
A company wants administrators to have access to privileged Azure roles only when they actually need them. Administrators should activate their privileges for a limited period and provide an appropriate justification.
Which Microsoft Entra capability should you implement?
A. Privileged Identity Management (PIM)
B. Microsoft Entra Password Protection
C. Microsoft Entra Domain Services
D. Application Proxy
Answer: A. Privileged Identity Management (PIM)
Explanation:
Microsoft Entra Privileged Identity Management (PIM) is designed to manage, control, and monitor access to important resources. It supports just-in-time access, activation requirements, time-limited privileged access, and auditing of privileged role usage.
The other options address different identity scenarios. Password Protection helps prevent weak passwords, Domain Services provides managed domain services, and Application Proxy provides access to on-premises applications.
PIM is specifically identified in the SC-500 study guide as a required capability.
Question 2 — Multiple Answer
Skill area: Manage identity, access, and governance
You are securing access to an Azure Key Vault.
Which two actions can help restrict access to the Key Vault?
A. Configure Key Vault networking/firewall settings
B. Assign appropriate permissions to users, groups, or managed identities
C. Enable Azure Bastion
D. Create a Microsoft Sentinel playbook
Answer: A and B
Explanation:
Key Vault security uses multiple layers.
- A is correct: Key Vault firewall and networking controls can restrict which networks can reach the vault.
- B is correct: Access to keys, secrets, and certificates must be controlled through appropriate authorization.
- C is incorrect: Azure Bastion provides secure administrative access to VMs; it does not control Key Vault authorization.
- D is incorrect: A Sentinel playbook can automate security operations but isn’t a Key Vault access-control mechanism.
The SC-500 study guide specifically includes deploying Key Vault, configuring access, firewall settings, and managing keys, secrets, and certificates.
Question 3 — Scenario — Single Answer
Skill area: Manage identity, access, and governance
A development team deploys Azure resources through infrastructure-as-code pipelines. Security requires that all storage accounts must use secure transfer and that resources must comply with organizational security requirements.
You want Azure to evaluate resources against these requirements and prevent noncompliant deployments where appropriate.
Which service should you use?
A. Microsoft Sentinel
B. Azure Policy
C. Azure Bastion
D. Microsoft Defender External Attack Surface Management
Answer: B. Azure Policy
Explanation:
Azure Policy allows organizations to define and enforce organizational standards for Azure resources. Policies can audit resources, deny noncompliant configurations, and support remediation.
This makes Azure Policy appropriate for enforcing governance requirements during infrastructure deployment.
Microsoft specifically includes Azure Policy and resource locks in the SC-500 governance objectives.
Question 4 — Fill in the Blank
Skill area: Manage identity, access, and governance
A developer needs an Azure application to access an Azure resource without storing a password, client secret, or certificate in application code.
The recommended identity capability is an Azure __________ identity.
A. guest
B. managed
C. external
D. federated
Answer: B. managed
Explanation:
Azure managed identities allow Azure resources to authenticate to supported services without developers having to manage credentials such as passwords or client secrets.
The SC-500 study guide specifically identifies implementation and configuration of managed identities for Azure resources as an exam objective.
Question 5 — Matching
Skill area: Manage identity, access, and governance
Match each security capability with its primary purpose.
| Capability | Purpose |
|---|---|
| 1. PIM | A. Authenticate applications without storing credentials |
| 2. Managed identity | B. Manage temporary privileged access |
| 3. Conditional Access | C. Apply access decisions based on conditions |
| 4. Azure Policy | D. Enforce organizational resource configuration standards |
Answer
- 1 → B
- 2 → A
- 3 → C
- 4 → D
Explanation:
- PIM controls privileged access and supports just-in-time activation.
- Managed identities provide Azure resources with identities that can authenticate without application-managed secrets.
- Conditional Access evaluates conditions such as user, device, location, risk, and application before granting access.
- Azure Policy governs resource configurations and compliance.
These capabilities belong to different security layers, so understanding their boundaries is important for SC-500 scenario questions.
Question 6 — Scenario — Single Answer
Skill area: Manage identity, access, and governance
A company has a production Key Vault containing encryption keys and application secrets. Security wants applications to access the vault, but the vault should not be broadly reachable from the public internet.
Which control most directly addresses the network exposure requirement?
A. Azure Policy
B. Microsoft Entra PIM
C. Key Vault firewall/networking configuration
D. Microsoft Sentinel automation rules
Answer: C. Key Vault firewall/networking configuration
Explanation:
Authorization controls determine who can access Key Vault. Network controls determine where requests can originate from.
The requirement in this scenario specifically concerns network exposure, so Key Vault’s networking and firewall configuration is the appropriate control.
Secure Storage, Databases, and Networking
Question 7 — Single Answer
Skill area: Secure storage, databases, and networking
An organization wants to prevent anonymous access to data stored in Azure Blob Storage.
Which control should be reviewed first?
A. Azure Bastion
B. Storage account access configuration
C. Microsoft Sentinel automation rules
D. Azure Firewall Premium
Answer: B. Storage account access configuration
Explanation:
Azure Storage security includes configuring storage-account access settings and authorization mechanisms.
The SC-500 storage objectives include implementing security and managing access for Azure Storage.
Azure Firewall and Bastion solve different networking and administrative-access problems.
Question 8 — Multiple Answer
Skill area: Secure storage, databases, and networking
A security engineer wants to reduce public network exposure for an Azure PaaS service.
Which two technologies can be used to provide private connectivity?
A. Azure Bastion
B. Azure Private Link
C. Private endpoints
D. Microsoft Entra PIM
Answer: B and C
Explanation:
Azure Private Link provides private connectivity to Azure PaaS services through private endpoints.
A private endpoint provides a private IP address in a virtual network that maps to the supported service.
Bastion is intended for secure RDP/SSH access to VMs, while PIM manages privileged identity access.
The SC-500 networking objectives explicitly include eliminating public network exposure of Azure PaaS services using Private Link.
Question 9 — Scenario — Single Answer
Skill area: Secure storage, databases, and networking
An organization has several Azure VNets containing application, database, and management workloads. The security team wants to isolate traffic between workload tiers and control which network flows are allowed.
Which capability should form part of the network segmentation design?
A. Microsoft Purview Audit
B. Azure Key Vault certificates
C. Network security groups (NSGs)
D. Microsoft Defender Vulnerability Management
Answer: C. Network security groups (NSGs)
Explanation:
NSGs provide network traffic filtering for Azure resources and subnets. They can be used as part of a segmentation strategy to control allowed inbound and outbound traffic.
The SC-500 networking objectives include segmenting and isolating Azure workloads using network security controls.
Question 10 — Multiple Answer
Skill area: Secure storage, databases, and networking
Which two capabilities are directly associated with securing Azure SQL databases?
A. Auditing
B. Microsoft Defender External Attack Surface Management
C. Azure Bastion
D. Microsoft Defender for Databases
Answer: A and D
Explanation:
Azure SQL security includes auditing capabilities and Microsoft Defender for Databases.
Auditing provides records of database activity for security and compliance analysis. Defender for Databases provides additional security monitoring and threat protection capabilities.
The SC-500 study guide explicitly includes platform-level Azure SQL security, auditing for Azure SQL Database and SQL Managed Instance, and Defender for Databases.
Question 11 — Scenario — Single Answer
A company needs centralized inspection and enforcement of network traffic across several Azure networks.
Which Azure service is specifically designed to provide centralized network traffic inspection and filtering?
A. Azure Storage
B. Azure Key Vault
C. Azure Firewall
D. Microsoft Entra ID
Answer: C. Azure Firewall
Explanation:
Azure Firewall is a managed, centralized network security service that can inspect and control network traffic.
This is different from an NSG, which provides network traffic filtering at the subnet or network-interface level.
The SC-500 networking learning path specifically covers centralizing and enforcing traffic inspection using Azure Firewall.
Question 12 — Matching
Skill area: Secure storage, databases, and networking
Match each technology with the scenario it most directly addresses.
| Technology | Scenario |
|---|---|
| 1. Azure Firewall | A. Private connectivity to a PaaS resource |
| 2. Private Link | B. Centralized network traffic inspection |
| 3. VPN Gateway | C. Encrypted connectivity between networks |
| 4. Azure Bastion | D. Browser-based secure administration of Azure VMs |
Answer
- 1 → B
- 2 → A
- 3 → C
- 4 → D
Explanation:
These services are frequently confused because they all participate in Azure security architectures.
- Azure Firewall → centralized network traffic inspection
- Private Link → private access to supported Azure services
- VPN Gateway → encrypted VPN connectivity
- Azure Bastion → secure RDP/SSH connectivity to VMs without exposing those VMs directly to the public internet
Question 13 — Scenario — Multiple Answer
A company stores sensitive business files in Azure Storage. Security wants to strengthen protection against malware and suspicious activity involving the storage environment.
Which two actions are appropriate?
A. Enable Microsoft Defender for Storage
B. Configure appropriate storage access controls
C. Deploy Azure Bastion into the storage account
D. Replace the storage account with Azure SQL Database
Answer: A and B
Explanation:
Security should be layered.
- Microsoft Defender for Storage provides additional security monitoring and threat protection for Azure Storage.
- Storage access controls limit who and what can access the data.
Bastion isn’t a storage-security mechanism, and moving the workload to SQL Database is not inherently a security control.
Question 14 — Fill in the Blank
Skill area: Secure storage, databases, and networking
To eliminate public network exposure for a supported Azure PaaS resource while allowing access from a virtual network, configure an Azure __________ endpoint.
A. service
B. public
C. private
D. management
Answer: C. private
Explanation:
A private endpoint provides a private IP address in an Azure virtual network for supported Azure services. This enables private connectivity rather than requiring clients to access the service through its public endpoint.
Private Link and private endpoints are specifically included in the SC-500 networking objectives.
Secure Compute
Question 15 — Scenario — Single Answer
Skill area: Secure compute
A company runs Azure VMs containing sensitive workloads. Security wants protection against boot-level attacks and wants the VM to use a virtual Trusted Platform Module.
Which capability should you configure?
A. Microsoft Sentinel
B. Azure Policy only
C. Azure Bastion
D. Trusted Launch
Answer: D. Trusted Launch
Explanation:
Azure Trusted Launch provides enhanced VM security features including Secure Boot and vTPM, along with integrity monitoring capabilities.
The SC-500 study guide specifically identifies secure boot, vTPM, integrity monitoring, and VM security type as VM security objectives.
Question 16 — Multiple Answer
Skill area: Secure compute
Which two capabilities are associated with securing Azure virtual machines?
A. Just-in-time VM access
B. Disk encryption
C. Microsoft Purview DSPM
D. Azure Storage lifecycle management
Answer: A and B
Explanation:
Both capabilities directly protect Azure VMs:
- JIT VM access restricts management-port exposure and provides access only when required.
- Disk encryption protects data stored on VM disks.
The SC-500 VM objectives specifically include disk encryption and JIT VM access.
Question 17 — Scenario — Single Answer
A security administrator wants to allow administrators to connect to Azure VMs through RDP and SSH without assigning public IP addresses directly to the VMs.
Which service should be implemented?
A. Azure Firewall
B. Azure Bastion
C. Azure Private Link
D. Microsoft Sentinel
Answer: B. Azure Bastion
Explanation:
Azure Bastion provides secure RDP and SSH connectivity to Azure VMs over the Azure portal without requiring public IP addresses on the VMs.
Bastion is specifically included in the SC-500 secure-compute objectives.
Question 18 — Scenario — Multiple Answer
A company operates AI workloads and wants to identify security risks associated with AI identities and AI data.
Which two capabilities are relevant?
A. Azure Bastion
B. Azure Storage lifecycle policies
C. Microsoft Purview Data Security Posture Management (DSPM)
D. Microsoft Defender XDR analysis of Entra Agent ID risks
Answer: C and D
Explanation:
The SC-500 AI-security objectives include:
- identifying AI data risks using Microsoft Purview DSPM
- analyzing security risks and blast radius associated with Microsoft Entra Agent ID using Microsoft Defender XDR
These address different layers of AI security: data risk and identity-related risk.
Question 19 — Scenario — Single Answer
A company deploys generative AI applications using Microsoft Foundry. Security wants a centralized gateway through which AI model traffic can be inspected and controlled.
Which capability should be configured?
A. Azure Bastion
B. Microsoft Defender for Storage
C. AI Gateway in Azure API Management
D. Azure VPN Gateway
Answer: C. AI Gateway in Azure API Management
Explanation:
The SC-500 AI security objectives include configuring and deploying AI Gateway in Azure API Management for Microsoft Foundry.
The AI Gateway is intended to provide governance and security controls around AI traffic and interactions.
Question 20 — Matching
Skill area: Secure compute
Match the security control to its primary purpose.
| Control | Purpose |
|---|---|
| 1. Trusted Launch | A. Secure administrative access to VMs |
| 2. Azure Bastion | B. Protect VM disks |
| 3. JIT VM access | C. Protect VM boot process and establish hardware-backed trust |
| 4. Disk encryption | D. Limit management-port exposure |
Answer
- 1 → C
- 2 → A
- 3 → D
- 4 → B
Explanation:
Understanding these distinctions is important because SC-500 scenario questions may provide several controls that appear applicable.
Trusted Launch protects the VM boot chain and provides security capabilities such as Secure Boot and vTPM. Bastion provides administrative connectivity. JIT controls management-port exposure. Disk encryption protects data stored on disks.
Question 21 — Scenario — Single Answer
An organization runs containers in Azure Kubernetes Service. The security team wants to identify container vulnerabilities, misconfigurations, and runtime security risks.
Which service should be used?
A. Microsoft Defender for Containers
B. Azure Key Vault
C. Microsoft Defender EASM
D. Microsoft Purview Audit
Answer: A. Microsoft Defender for Containers
Explanation:
Microsoft Defender for Containers provides security capabilities for containerized workloads, including Kubernetes environments.
The SC-500 application-platform objectives specifically include detecting container risks using Defender for Containers and implementing security controls for AKS.
Manage and Monitor Security Posture
Question 22 — Single Answer
Skill area: Manage and monitor security posture
A security team wants to identify and prioritize security risks across Azure resources using posture information, recommendations, attack paths, and risk-based analysis.
Which Defender for Cloud capability should they primarily use?
A. Cloud Security Posture Management (CSPM)
B. Microsoft Sentinel playbooks
C. Azure Bastion
D. Microsoft Purview Audit
Answer: A. Cloud Security Posture Management (CSPM)
Explanation:
Defender CSPM provides posture visibility and capabilities for identifying and prioritizing cloud security risks. Current Microsoft training describes capabilities including Secure Score, attack-path analysis, and Cloud Security Explorer.
Question 23 — Scenario — Single Answer
A company has Azure, AWS, and GCP resources. The security team wants centralized security visibility across these environments through Microsoft Defender for Cloud.
What should the security team configure?
A. Microsoft Sentinel CEF collection only
B. Defender for Cloud multicloud connectors
C. Azure Private Link for every workload
D. Azure Bastion for every server
Answer: B. Defender for Cloud multicloud connectors
Explanation:
Microsoft Defender for Cloud supports connecting hybrid and multicloud environments, including AWS and GCP, to provide unified security visibility.
Microsoft’s current training specifically covers native AWS and GCP connectors and Azure Arc for hybrid servers.
Question 24 — Multiple Answer
Which two capabilities are associated with Microsoft Defender for Cloud’s Cloud Security Posture Management functionality?
A. Attack path analysis
B. Cloud Security Explorer
C. RDP access through Azure Bastion
D. Azure Storage lifecycle management
Answer: A and B
Explanation:
Current Microsoft Defender for Cloud CSPM training includes:
- risk-prioritized security recommendations
- attack-path analysis
- Cloud Security Explorer
- Secure Score-related posture capabilities
These help security teams identify and investigate cloud security risks.
Question 25 — Scenario — Single Answer
A security team wants to discover unknown internet-facing assets belonging to its organization, including assets that may not have been previously inventoried.
Which Microsoft security capability should they use?
A. Azure Machine Configuration
B. Microsoft Defender for Storage
C. Microsoft Entra PIM
D. Microsoft Defender External Attack Surface Management (EASM)
Answer: D. Microsoft Defender External Attack Surface Management (EASM)
Explanation:
Microsoft Defender EASM provides outside-in discovery of an organization’s external attack surface. Microsoft describes its recursive discovery capabilities as a way to find unknown internet-facing assets and surface vulnerabilities and security hygiene risks.
Question 26 — Scenario — Multiple Answer
A security operations team is implementing Microsoft Sentinel.
Which two activities are explicitly part of the SC-500 Sentinel objectives?
A. Configure syslog and CEF event collection
B. Configure Azure Bastion
C. Implement automation rules and playbooks
D. Configure Key Vault certificates
Answer: A and C
Explanation:
The SC-500 study guide specifically includes:
- implementing and configuring syslog and CEF event collection
- implementing automation rules and playbooks
Other Sentinel objectives include workspaces, Microsoft data connectors, Windows Security events using DCRs/WEF, custom log tables, retention, and querying Microsoft Purview Audit in Defender XDR.
Question 27 — Scenario — Single Answer
A Windows server sends security events to Microsoft Sentinel through Windows Event Forwarding (WEF). The organization wants to define which events are collected using centralized configuration.
Which Azure capability should be used?
A. Azure Firewall policy
B. Azure Machine Configuration
C. Data Collection Rules (DCRs)
D. Azure Policy initiatives
Answer: C. Data Collection Rules (DCRs)
Explanation:
Microsoft Sentinel supports collecting Windows Security events using Data Collection Rules, including scenarios involving Windows Event Forwarding.
The SC-500 study guide explicitly identifies collection of Windows Security events using DCRs, including WEF, as an exam objective.
Question 28 — Scenario — Multiple Answer
An organization is configuring Microsoft Security Copilot.
Which two areas are specifically included in the SC-500 Security Copilot objectives?
A. Configure Security Copilot workspaces
B. Manage permissions and roles in Security Copilot
C. Configure Azure Storage lifecycle management
D. Configure VM disk encryption
Answer: A and B
Explanation:
The SC-500 study guide identifies the following Security Copilot objectives:
- configure workspaces
- manage permissions and roles
- enable and configure plugins
- enable and configure Microsoft agents and Security Store agents
The Microsoft Security Copilot learning path also covers workspace segmentation, SCU capacity, workspace roles, plugins, and the lifecycle of Microsoft-built and partner-built agents.
Question 29 — Scenario — Single Answer
A security administrator wants to acquire a partner-built security agent for Microsoft Security Copilot. The organization has identified the agent in the Security Store and wants to complete the acquisition process.
Where are the partner agent’s purchase or subscription activities handled?
A. Only in Microsoft Sentinel
B. Only in Azure Policy
C. Microsoft Security Store
D. Only in Microsoft Entra ID
Answer: C. Microsoft Security Store
Explanation:
Microsoft Security Store is the security-focused storefront for discovering, acquiring, and deploying Microsoft and partner-built security solutions and agents.
For Security Copilot, Microsoft distinguishes between acquiring/subscribing to partner agents through Security Store and configuring/operating the agent through Security Copilot. Microsoft also notes that Security Copilot SCU consumption is separate from any partner-agent subscription fees.
Question 30 — Scenario — Multiple Answer
A company wants to improve its overall security posture for AI workloads in Defender for Cloud.
Which three capabilities are relevant to this goal?
A. Enable the AI workloads protection plan
B. Review insights in the Data & AI security dashboard
C. Assess AI posture using Cloud Security Posture Management
D. Use Azure Bastion to provide RDP access to the AI model
Answer: A, B, and C
Explanation:
Microsoft Defender for Cloud provides multiple layers of AI security. Current Microsoft training describes:
- enabling the AI workloads plan
- reviewing the Data & AI security dashboard
- assessing AI security posture through CSPM
- detecting runtime threats through Cloud Workload Protection
- investigating incidents through Microsoft Defender XDR
Azure Bastion is unrelated to AI workload posture management and is primarily a secure administrative-access service for Azure VMs.
Key exam concepts reinforced in Practice Exam 1
A useful way to mentally organize the material is:
Identity → Data → Network → Compute → AI → Posture → Detection/Response
- Identity: Entra ID, PIM, Conditional Access, managed identities
- Secrets: Key Vault
- Governance: Azure Policy, RBAC, resource locks
- Data: Storage and Azure SQL security
- Network: NSGs, Firewall, VPN, Private Link
- Compute: VMs, Trusted Launch, disk encryption, Bastion, JIT
- Application platform: AKS, containers, App Services, Functions, Logic Apps, API Management
- AI: Agent ID, AI Gateway, Foundry guardrails, Purview DSPM, Defender for AI
- Posture: Defender CSPM, Secure Score, attack paths, EASM
- Security operations: Sentinel, DCRs, WEF, CEF, syslog, automation
- Security Copilot: workspaces, roles, plugins, Microsoft agents, Security Store agents
Microsoft’s current training describes Defender for Cloud as providing posture management, attack-path analysis, Cloud Security Explorer, external attack-surface discovery, compliance assessment, workload protection, and vulnerability-management capabilities, making these particularly important concepts to distinguish from one another on scenario questions.
Go to the SC-500 Exam Prep Hub main page
