This practice exam is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
Implementing End-to-End Security Controls for Cloud and AI Workloads
Section 1 — Manage identity, access, and governance
Question 1 — Privileged Identity Management (PIM)
A security administrator has a standing Owner role assignment at the subscription level. The organization wants to reduce standing privileges while allowing the administrator to perform emergency configuration changes when necessary. The administrator should provide justification, complete multifactor authentication, and have the activation approved by another administrator.
Which configuration best meets these requirements?
A. Assign the Contributor role permanently and use an Azure Policy exemption for emergency changes.
B. Create a custom Azure role and assign it permanently at the management group scope.
C. Convert the Owner assignment to an eligible PIM assignment and configure approval, justification, and MFA requirements for activation.
D. Create a resource lock and configure an alert to notify the security team whenever the administrator changes a resource.
Correct answer: C
Explanation: Microsoft Entra Privileged Identity Management (PIM) supports eligible role assignments that users activate only when needed. Activation requirements can include justification, MFA, and approval. This reduces standing privileged access while retaining a controlled emergency-access process. A resource lock or policy exemption does not replace privileged access management.
Question 2 — Azure Key Vault protection
A company stores encryption keys and application secrets in Azure Key Vault. Its security policy requires that deleted secrets and keys cannot be permanently purged by an administrator before the configured retention period expires, even if the administrator has elevated permissions.
Which setting most directly enforces this requirement?
A. Enable purge protection.
B. Enable diagnostic settings and send audit logs to Log Analytics.
C. Configure a private endpoint for the vault.
D. Assign the Key Vault Reader role to all administrators.
Correct answer: A
Explanation: Purge protection prevents a deleted vault object from being permanently purged during its retention period. Soft delete retains deleted objects for recovery; purge protection prevents early permanent deletion. Diagnostic logging, private endpoints, and reader permissions serve different security purposes.
Question 3 — Conditional Access for AI agent identities
An organization deploys dozens of autonomous AI agents using Microsoft Entra Agent ID. All agents created from a particular agent identity blueprint must be blocked from accessing corporate APIs if they are identified as high risk. New agents created from that blueprint must automatically receive the same protection.
What should the security engineer configure?
A. A Conditional Access policy targeting all human users and requiring MFA.
B. An Azure Policy definition that audits agent registrations.
C. An access review that periodically checks the agents’ API permissions.
D. A Conditional Access policy targeting the relevant agent identity blueprint, with a control that blocks access when the configured risk condition is met.
Correct answer: D
Explanation: Conditional Access can target agent identities and agent identity blueprints. A policy applied to a blueprint covers agent identities derived from it, including future agents. Risk-based controls can block access when the applicable risk condition is met. The policy must target the correct identity type; a policy targeting human users does not automatically cover agent identities.
Question 4 — Azure Policy versus resource locks
A team manages production resources in Azure. Security requirements state that storage accounts must have secure transfer enabled and that a specific production database must not be deleted accidentally.
Which combination best addresses both requirements?
A. Assign the Reader role to the application team and enable diagnostic logging on the database.
B. Use Azure Policy to enforce or audit the secure-transfer configuration, and apply a CanNotDelete resource lock to the database.
C. Apply a ReadOnly lock to the subscription and use a management group to enable secure transfer.
D. Use Microsoft Defender for Cloud recommendations to block storage configuration changes and assign the database the Contributor role.
Correct answer: B
Explanation: Azure Policy evaluates resource configurations against defined rules and can audit, deny, or remediate supported configurations. A CanNotDelete lock prevents deletion while allowing authorized modifications. A ReadOnly lock is more restrictive and can prevent updates. Defender for Cloud provides posture recommendations, but recommendations alone do not enforce these controls.
Question 5 — Least-privilege access to Azure resources
A deployment operator needs to start and stop virtual machines in one resource group. The operator must not create virtual machines, change their networking, modify role assignments, or access other resource groups.
Which TWO approaches best support least privilege?
A. Assign Owner at the subscription scope and use activity logs to detect excess permissions.
B. Assign Contributor at the resource-group scope and ask the operator not to modify networking.
C. Create or use a role that includes the required virtual machine start/stop actions, and assign it at the narrowest suitable scope.
D. Assign a suitable built-in virtual machine operator role at the target resource-group scope, after verifying that its permitted actions meet the requirements.
Correct answers: C and D
Explanation: Least privilege means granting only the permissions needed at the narrowest appropriate scope. A custom role can precisely define allowed actions, while a suitable built-in role may already provide the required permissions. The role’s actual actions and any applicable data-plane permissions should be checked before assignment. Owner and Contributor are broader than the stated requirement.
Question 6 — OAuth permissions and consent
A developer registers an application that calls Microsoft Graph on behalf of signed-in employees. The application requests delegated permissions that allow it to read users’ files. The security team wants to minimize the risk of excessive access being granted during application consent.
Which action is most appropriate?
A. Review the requested delegated permissions and configure consent policies so that only approved permissions and appropriate consent workflows are allowed.
B. Assign the application the Global Administrator role so it can request consent without interruption.
C. Enable public network access for the application registration.
D. Create a resource lock on the application registration and assume that this prevents overprivileged consent.
Correct answer: A
Explanation: Delegated permissions allow an application to act on behalf of a signed-in user within the permissions granted to it and the user. Reviewing requested permissions and controlling user and administrator consent helps prevent excessive access. Global Administrator is not an appropriate default application permission, and resource locks do not control OAuth consent.
Question 7 — Protecting backup data
A company is concerned that an attacker who compromises an administrator account could delete recovery points and then encrypt the production environment. The company wants to strengthen the resilience of its Azure Backup data against destructive administrative actions.
Which approach is most appropriate?
A. Store backup logs in the same production virtual machine that is being protected.
B. Give all backup operators the Backup Contributor and Owner roles at the subscription level.
C. Rely exclusively on Azure Policy to prevent all possible backup deletions, without reviewing the backup configuration.
D. Configure the applicable Azure Backup security features, including immutable vault protection where supported, and restrict privileged backup operations using least-privilege access and appropriate safeguards.
Correct answer: D
Explanation: Backup resilience depends on multiple layers: restricting privileged operations, protecting backup configuration, and enabling supported immutability and deletion safeguards. Exact capabilities vary by workload and vault configuration, so verify which protections are supported for the protected data source. Broad administrative roles and co-locating logs with production workloads do not adequately protect recovery points.
Section 2 — Secure storage, databases, and networking
Question 8 — Eliminate public exposure of Azure Storage
A storage account contains confidential documents used by an application hosted in an Azure virtual network. The application must continue to access the storage account, but the company wants to eliminate access through the storage account’s public network endpoint.
Which configuration best meets the requirement?
A. Allow all public IP addresses in the storage firewall and require HTTPS.
B. Configure a private endpoint, ensure the application resolves the storage account name to the private endpoint IP address, and disable public network access after validating the private connectivity.
C. Create an NSG rule that blocks inbound traffic to the storage account’s public endpoint.
D. Enable Microsoft Defender for Storage and leave the public network endpoint enabled.
Correct answer: B
Explanation: Azure Private Link provides private connectivity to supported Azure services through a private endpoint in a virtual network. Correct DNS configuration is essential so the application resolves the service name to the private IP address. Disabling public network access removes the public access path; Defender for Storage detects threats but does not itself remove public exposure.
Question 9 — Secure access to Azure Storage
A data-processing application needs temporary access to blobs in an Azure Storage account. The organization wants to avoid distributing the storage account key and wants to issue a time-limited token using Microsoft Entra credentials.
Which option is the best fit?
A. Embed the storage account access key in the application’s source code and rotate it every month.
B. Assign the application the Owner role at the subscription level.
C. Make the container public and rely on application-level authentication.
D. Use a user delegation SAS, generated using Microsoft Entra credentials, and restrict its permissions and validity period to the required operations.
Correct answer: D
Explanation: A user delegation SAS is signed using a user delegation key obtained through Microsoft Entra authorization rather than a storage account key. The SAS should have only the necessary permissions and a limited validity period. It remains a bearer token, so it must be protected against disclosure. Public containers and embedded account keys increase exposure.
Question 10 — Detect threats against Azure Storage
A company uses Azure Blob Storage to receive files from external partners. The security team wants threat detection that can identify suspicious storage activity and malware in uploaded files, using Microsoft Defender’s storage protections where supported.
What should the team implement?
A. Enable Microsoft Defender for Storage and configure the relevant malware-scanning and threat-detection capabilities for the storage environment.
B. Enable Azure SQL auditing on the storage account.
C. Assign the Storage Blob Data Reader role to every external partner.
D. Configure a ReadOnly resource lock on the storage account.
Correct answer: A
Explanation: Microsoft Defender for Storage provides security monitoring and threat detection for supported storage workloads. Its capabilities include identifying suspicious activities and, where configured and supported, scanning uploaded blobs for malware. SQL auditing applies to SQL services, while RBAC and resource locks do not provide malware detection.
Question 11 — Azure SQL auditing
A security operations team needs to investigate who accessed an Azure SQL Database, what database activities occurred, and when suspicious operations took place. The team wants to query the audit records centrally alongside other security events.
Which configuration best meets the requirement?
A. Enable Transparent Data Encryption (TDE) and use its encryption status as an audit trail.
B. Enable a database resource lock and review Azure Resource Health.
C. Configure Azure SQL auditing to send audit events to a suitable destination, such as Log Analytics, and query the collected records.
D. Enable SQL authentication for every user and rely on application logs alone.
Correct answer: C
Explanation: Azure SQL auditing records selected database events and can send audit data to supported destinations, including Log Analytics. Central collection enables investigation and correlation with other security information. TDE protects data at rest; it does not replace activity auditing.
Question 12 — Troubleshoot network security rules
A virtual machine cannot receive traffic from an approved application subnet. The network team believes an NSG rule allows the traffic, but the connection still fails. The team wants to determine which network security rules are effectively applied to the VM’s network interface.
Which tool should the team use first?
A. Microsoft Defender External Attack Surface Management.
B. Azure Network Watcher IP flow verify or effective security rules, selecting the appropriate feature to test the traffic or inspect the applied rules.
C. Azure Key Vault diagnostic settings.
D. Microsoft Purview Data Security Posture Management.
Correct answer: B
Explanation: Network Watcher provides diagnostic tools for Azure network connectivity. IP flow verify can determine whether a particular traffic flow is allowed or denied and identify the relevant rule. Effective security rules show the aggregate rules applied to a network interface. The choice depends on whether the team needs a specific flow decision or a complete view of applied rules.
Question 13 — Centralized outbound traffic inspection
An organization has several application subnets. It must centrally inspect outbound traffic and restrict access to specified fully qualified domain names (FQDNs), including when applications use changing destination IP addresses. The solution should reduce duplicated outbound filtering rules across subnets.
Which service is the most appropriate?
A. Azure Network Security Groups alone.
B. Azure Private Link.
C. Azure Bastion.
D. Azure Firewall with suitable application rules and a routing design that directs the relevant outbound traffic through the firewall.
Correct answer: D
Explanation: Azure Firewall supports centralized traffic filtering, including application rules based on FQDNs, when the relevant traffic is routed through it. NSGs filter traffic using network-layer attributes such as IP addresses, ports, and protocols; they do not provide equivalent centralized FQDN-based application filtering. Private Link and Bastion solve different problems.
Question 14 — Private endpoint DNS
An application connects to an Azure SQL logical server through a private endpoint. The private endpoint has been created successfully, and the application can reach other resources in its virtual network. However, the SQL hostname still resolves to a public IP address.
What should the engineer investigate first?
A. Whether the appropriate Private DNS zone is configured, linked to the virtual network, and contains the expected private endpoint DNS records.
B. Whether the application has the Azure Owner role.
C. Whether Microsoft Defender for Servers is enabled.
D. Whether the SQL database has Transparent Data Encryption enabled.
Correct answer: A
Explanation: Private endpoint connectivity typically relies on DNS resolution to map the service hostname to the private endpoint’s IP address. A correctly configured private DNS zone and virtual network link are common requirements. Database encryption and VM security settings do not fix an incorrect DNS resolution path.
Question 15 — Azure SQL vulnerability assessment
A security engineer must identify potential database misconfigurations and vulnerabilities, review findings against security baselines, and track recommendations for remediation. The organization also wants to detect suspicious database activities.
Which approach best addresses both needs?
A. Use TDE for vulnerability discovery and NSGs for SQL auditing.
B. Use Azure resource locks to identify database vulnerabilities and Azure Policy to record each query.
C. Use Microsoft Defender for Databases for supported database threat protection and vulnerability-assessment capabilities, configuring the relevant settings and reviewing findings.
D. Enable public access to the database so that the security scanner can reach it from anywhere.
Correct answer: C
Explanation: Microsoft Defender for Databases provides supported database security capabilities, including threat detection and vulnerability-assessment functionality, depending on the database type and configuration. Findings help identify weaknesses and prioritize remediation. TDE protects data at rest, while resource locks and NSGs are not substitutes for database security assessment.
Section 3 — Secure compute
Question 16 — Azure VM Trusted Launch
A company wants to strengthen the boot integrity of supported Azure virtual machines. Its requirements include protection against bootkits and verification of the boot chain, together with a virtualized hardware root of trust for supported security scenarios.
Which configuration is the best fit?
A. Enable Trusted Launch with Secure Boot and virtual TPM (vTPM), after verifying that the VM size, image, and operating system support it.
B. Enable Azure Bastion and disable the VM’s operating system updates.
C. Enable Azure Disk Encryption and assume that it prevents bootkits.
D. Assign the VM a managed identity and remove all network security groups.
Correct answer: A
Explanation: Trusted Launch adds security features such as Secure Boot and vTPM for supported Azure VMs. Secure Boot helps prevent unauthorized boot components from loading, while vTPM provides a protected virtualized hardware trust capability. Disk encryption protects data at rest but does not provide the same boot-integrity controls.
Question 17 — Secure workload identity in AKS
An application running in Azure Kubernetes Service (AKS) must access a specific Azure Key Vault. The security team wants to avoid storing long-lived service principal credentials in Kubernetes secrets and wants the workload to obtain Microsoft Entra tokens using a federated identity configuration.
Which approach should the team use?
A. Place a subscription Owner credential in a Kubernetes secret and mount it into the pod.
B. Enable anonymous access to Key Vault and filter requests in application code.
C. Configure Microsoft Entra Workload ID for AKS, use the appropriate federated identity credential and Kubernetes service account, and grant the workload identity only the necessary Key Vault permissions.
D. Give every node in the cluster the same permanent client secret.
Correct answer: C
Explanation: Microsoft Entra Workload ID for AKS uses workload identity federation so Kubernetes workloads can authenticate to Microsoft Entra ID without managing long-lived application secrets. The federated credential links the Kubernetes service account identity to the Entra application or managed identity. Least-privilege permissions should then be granted to the identity for the required Key Vault operations.
Question 18 — Just-in-time VM access
A security review finds that administrators can connect to Azure virtual machines over RDP from broad source IP ranges at all times. The company wants to reduce exposure by opening management ports only when an authorized administrator requests access, for a limited duration and from an approved source.
Which control most directly meets this requirement?
A. Assign the VM the Security Reader role.
B. Enable a ReadOnly resource lock.
C. Configure an NSG rule that permanently allows RDP from the corporate network.
D. Enable and configure just-in-time (JIT) VM access through Microsoft Defender for Cloud, setting approved ports, source IP restrictions, and permitted access duration.
Correct answer: D
Explanation: JIT VM access reduces the time that management ports are exposed. A request can temporarily open the required port according to configured rules and duration limits. A permanently allowed NSG rule does not provide the same time-bound access model. JIT requirements and supported VM configurations should be verified before deployment.
Question 19 — Web Application Firewall (WAF)
A company hosts a public web application behind a supported Azure application delivery service. The security team wants to inspect incoming HTTP(S) requests and detect or block common web attacks, such as SQL injection and cross-site scripting, using managed rule sets.
Which control should the team configure?
A. An NSG that allows only TCP port 443.
B. A Web Application Firewall policy with an appropriate managed rule set, initially validating detection and false positives before enforcing blocking as appropriate.
C. Azure Disk Encryption on the web server’s operating system disk.
D. A private endpoint for the public-facing website that allows every internet client to connect privately.
Correct answer: B
Explanation: A WAF evaluates HTTP(S) traffic and can detect or block common web application attacks using managed rules and custom rules. An NSG filters network traffic but does not inspect requests for application-layer attack patterns in the same way. A staged rollout helps reduce false positives while establishing effective protection.
Question 20 — Secure API backends with Azure API Management
An organization publishes an API through Azure API Management (APIM). Clients must present Microsoft Entra access tokens, and APIM must reject requests when the token’s issuer, audience, or signature is invalid. The backend should receive only requests that pass the gateway’s validation policy.
Which approach is most appropriate?
A. Configure APIM policy-based JWT validation, such as validate-jwt or the applicable Entra-aware validation policy, with the expected issuer, audience, and signing-key configuration.
B. Place the token in a URL query string and let the backend decide whether to inspect it.
C. Enable anonymous access at APIM and use a network security group to validate token claims.
D. Assign all API callers the API Management service’s Contributor role.
Correct answer: A
Explanation: APIM policies can validate JWTs before forwarding requests to the backend. Validation should enforce the expected issuer and audience and verify the token using trusted signing keys. Tokens should be sent in the authorization header rather than exposed in URLs. Azure RBAC roles for managing APIM resources do not authenticate API consumers.
Question 21 — Enforce VM security configuration
A company needs to assess and enforce supported operating-system security settings on Azure VMs and Arc-enabled servers, such as required configuration values. The team wants configuration compliance and remediation capabilities rather than only network-level filtering.
Complete the statement:
Azure __________ can be used to audit and enforce supported machine configuration settings on applicable Azure and Arc-enabled machines.
A. Private Link
B. Network Watcher
C. Machine Configuration
D. Application Gateway
Correct answer: C — Machine Configuration
Explanation: Azure Machine Configuration provides capabilities to audit and enforce supported configuration settings on applicable machines, including Azure VMs and Arc-enabled servers. It can help assess compliance against configuration requirements and remediate supported deviations. Network Watcher and Private Link serve networking purposes, while Application Gateway provides application delivery capabilities.
Question 22 — Container security in Azure
An organization runs containerized applications in AKS. The security team wants to identify container-related risks, monitor supported runtime threats, and receive security recommendations through Microsoft’s cloud security platform.
Which solution is the most appropriate starting point?
A. Use Azure SQL auditing for all container events.
B. Enable the applicable Microsoft Defender for Containers plan in Microsoft Defender for Cloud and configure the required components and data collection for the desired protections.
C. Use Azure Policy alone as a replacement for container threat detection.
D. Enable a resource lock on the AKS cluster and assume that the lock prevents malicious activity inside containers.
Correct answer: B
Explanation: Microsoft Defender for Containers provides supported security capabilities for container environments, including recommendations and threat detection features. The exact coverage depends on the environment and configuration, so required components and data collection should be verified. Azure Policy can enforce supported configurations, but it does not replace runtime threat detection.
Question 23 — AI workload protection
A team deploys an AI application using Microsoft Foundry. The application must reduce the risk of unsafe model outputs and prompt-based attacks, and the security team wants to apply configurable safeguards to model interactions. The team also wants centralized security visibility for the AI workload.
Which approach best meets the requirements?
A. Use an NSG as the only AI safety control and allow all model requests.
B. Store all prompts and API keys in source code so that developers can debug issues quickly.
C. Enable Azure Backup and rely on recovery points to prevent unsafe AI responses.
D. Configure appropriate Microsoft Foundry guardrails and content-safety controls, and use the relevant Microsoft Defender for Cloud AI workload protection capabilities for security visibility and threat detection.
Correct answer: D
Explanation: Foundry guardrails and content-safety controls help mitigate specified risks in model inputs and outputs, depending on the model, configuration, and supported features. Microsoft Defender for Cloud’s AI security capabilities provide additional workload protection and visibility. No single guardrail guarantees that all harmful or adversarial interactions will be prevented, so controls should be tested and layered.
Section 4 — Manage and monitor security posture
Question 24 — Defender for Cloud attack path analysis
Microsoft Defender for Cloud identifies a public-facing virtual machine with a vulnerability. The VM has a managed identity with access to a storage account containing sensitive data. The security team wants to understand whether the exposed VM could provide a path to the sensitive storage resource and prioritize remediation based on the potential impact.
Which capability is most appropriate?
A. Microsoft Sentinel’s data retention settings.
B. Azure SQL auditing.
C. Defender for Cloud’s attack path analysis and related cloud security posture management tools.
D. Azure Resource Manager deployment history alone.
Correct answer: C
Explanation: Defender for Cloud’s cloud security posture management capabilities can help identify attack paths that connect exposures, misconfigurations, identities, and sensitive resources. Attack path analysis supports prioritization based on potential risk and reachable assets. It complements, rather than replaces, vulnerability remediation and identity-permission reviews.
Question 25 — Ingest Common Event Format logs into Microsoft Sentinel
A company has a network security appliance that exports security events in Common Event Format (CEF). The SOC wants those events available in Microsoft Sentinel for analytics rules and incident investigation.
Which approach is most appropriate?
A. Configure the supported CEF ingestion architecture, including the required Linux-based log forwarder and Azure Monitor Agent setup, and enable the applicable Microsoft Sentinel data connector.
B. Install the Windows Event Forwarding collector on the network appliance and assume it can ingest CEF directly.
C. Enable Azure SQL auditing on the Sentinel workspace.
D. Create an Azure Policy assignment that converts CEF messages into Sentinel incidents.
Correct answer: A
Explanation: Microsoft Sentinel supports CEF ingestion using a supported log-forwarding architecture. The appropriate connector and agent configuration must be implemented so the appliance’s CEF events reach the workspace and can be queried. Windows Event Forwarding serves Windows event collection scenarios, while Azure Policy does not perform log ingestion or event conversion.
Question 26 — Collect Windows security events
An organization needs to collect Windows security events from servers into Microsoft Sentinel. The team wants to control which Windows events are collected and manage the collection configuration centrally through Azure Monitor.
Which approach is the best fit?
A. Use a private endpoint for each Windows event log.
B. Enable Microsoft Defender for Storage on every server.
C. Configure an Azure Firewall application rule to forward Windows events directly into Sentinel.
D. Configure the appropriate Azure Monitor Agent deployment and a Data Collection Rule (DCR) that specifies the Windows event channels or event selection required for collection.
Correct answer: D
Explanation: Azure Monitor Agent and Data Collection Rules are used to define and manage supported log collection. For Windows security events, the DCR specifies the event selection and destination configuration appropriate to the chosen collection method. Azure Firewall and Defender for Storage do not configure Windows event ingestion into Sentinel.
Question 27 — Automate incident handling in Microsoft Sentinel
Match each Microsoft Sentinel capability to its primary purpose.
| Capability | Primary purpose |
|---|---|
| 1. Analytics rule | A. Perform response actions through an automation workflow, such as notifying a team or invoking a supported remediation action |
| 2. Automation rule | B. Detect suspicious patterns in collected data and generate alerts or incidents according to the rule configuration |
| 3. Playbook | C. Apply incident-handling logic, such as assigning an incident, changing its status, or triggering a playbook based on configured conditions |
Choose the correct mapping.
A. 1-C, 2-B, 3-A
B. 1-B, 2-C, 3-A
C. 1-A, 2-C, 3-B
D. 1-B, 2-A, 3-C
Correct answer: B
Explanation: Analytics rules identify suspicious activity and can generate alerts or incidents. Automation rules apply incident-management logic and can trigger playbooks. Playbooks are workflows, commonly built with Azure Logic Apps, that carry out response or integration actions. Together, these capabilities help automate detection and incident handling.
Question 28 — Discover external attack surface exposure
A company suspects that teams have deployed internet-facing assets outside the approved cloud inventory. The security team needs to discover externally visible assets associated with the organization, including assets that might not be registered in its current Azure resource inventory.
Which service is designed for this purpose?
A. Azure Network Watcher.
B. Microsoft Defender for Storage.
C. Microsoft Defender External Attack Surface Management (Defender EASM).
D. Microsoft Entra Privileged Identity Management.
Correct answer: C
Explanation: Microsoft Defender EASM helps discover and inventory an organization’s externally exposed digital assets and identify potential external exposure and vulnerabilities. It can help uncover assets that are not evident from the organization’s known cloud resource inventory. Network Watcher focuses on Azure network diagnostics, and PIM manages privileged access.
Question 29 — Microsoft Security Copilot access control
A security team is deploying Microsoft Security Copilot. Analysts should be able to use the capabilities and data sources appropriate to their assigned responsibilities, but they must not automatically receive administrative control over the workspace, all plugins, or all agents.
What is the best administrative approach?
A. Configure Security Copilot workspace access and roles using least privilege, and review the permissions and enablement of plugins and agents before making them available.
B. Give every analyst the same highest-privilege administrative role to simplify support.
C. Share a single administrator account among the analysts.
D. Disable all role-based access controls and rely on the analysts’ job titles.
Correct answer: A
Explanation: Security Copilot access should be governed through the applicable workspace roles, permissions, and controls for plugins and agents. Least privilege helps ensure that analysts can perform their assigned tasks without automatically receiving broad administrative capabilities. Shared accounts and blanket administrative access undermine accountability and increase risk.
Question 30 — Identify AI-related data exposure risks
A company is rolling out AI assistants that can search organizational content. The security team is concerned that sensitive information may be overexposed through existing permissions, shared content, or AI-enabled access paths. The team wants to identify and assess AI-related data security risks across supported data sources.
Which solution is most appropriate?
A. Use Azure Bastion to identify overshared documents.
B. Use Microsoft Purview Data Security Posture Management (DSPM) for AI to assess relevant AI-related data risks and help identify oversharing or sensitive-data exposure in supported environments.
C. Use an Azure SQL resource lock to prevent AI assistants from reading documents.
D. Use Microsoft Defender External Attack Surface Management to inspect all internal document permissions.
Correct answer: B
Explanation: Microsoft Purview DSPM for AI helps organizations assess data security risks associated with AI usage, including relevant sensitive-data exposure and oversharing risks in supported environments. Findings should guide remediation of permissions, data controls, and AI access paths. Bastion provides secure VM connectivity, while EASM focuses on external attack surface discovery.
Exam 3 — Final review
Use your results to identify the topics that need more practice before attempting Exam 4.
| Skill domain | Questions | Main areas tested |
|---|---|---|
| Identity, access, and governance | 1–7 | PIM, Key Vault, agent identity, Conditional Access, Azure Policy, RBAC, OAuth consent, backup protection |
| Storage, databases, and networking | 8–15 | Private Link, SAS, Defender for Storage, SQL auditing, Network Watcher, Azure Firewall, private DNS, database protection |
| Secure compute | 16–23 | Trusted Launch, AKS workload identity, JIT access, WAF, API security, Machine Configuration, container security, AI guardrails |
| Security posture and monitoring | 24–30 | Attack path analysis, Sentinel ingestion, Windows event collection, automation, EASM, Security Copilot, Purview DSPM for AI |
Suggested review strategy: For any question you missed, focus on the difference between controls that prevent access, controls that detect risk, and tools that investigate or remediate issues. Many certification questions test whether you can select the right control for a specific requirement rather than simply recognize a product name.
Go to the SC-500 Exam Prep Hub main page
