This practice exam is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
Implementing End-to-End Security Controls for Cloud and AI Workloads
Section 1 — Manage identity, access, and governance
Question 1 — PIM activation and emergency access
A company has two requirements for subscription-level administrators:
- Routine administration must use just-in-time privileged access with approval.
- Emergency access must remain possible if the normal approval process is unavailable.
Which design best balances these requirements?
A. Assign every administrator permanent Owner access and monitor activity with Azure Activity Logs.
B. Use eligible PIM assignments with configured activation controls, and maintain separately governed emergency-access accounts with carefully restricted, monitored credentials and procedures.
C. Replace all privileged assignments with Reader access and grant Owner access manually when needed.
D. Use Azure Policy to require approval before each Azure Resource Manager operation.
Correct answer: B
Explanation: PIM reduces standing privilege by making eligible roles activatable under defined conditions. Emergency-access arrangements should be designed separately so that an outage or unavailable approver does not prevent recovery. Those accounts require strict protection, monitoring, and periodic validation. Azure Policy does not provide per-operation approval for every management-plane action.
Question 2 — Key Vault network and authorization controls
An application hosted in a virtual network must retrieve a secret from Azure Key Vault. The company requires that:
- The vault is not reachable through its public network endpoint.
- Only the application identity can read the required secret.
- Administrators can audit vault access.
Which design best satisfies all three requirements?
A. Enable public network access, allow all Azure services through the firewall, and give the application Contributor access.
B. Use a Key Vault resource lock and store the secret in the application’s configuration file.
C. Assign the Key Vault Administrator role to the application and disable diagnostic logging.
D. Configure a private endpoint and private DNS, disable public network access after validating connectivity, grant the application identity the required secret-read permission, and enable diagnostic logging to a suitable destination.
Correct answer: D
Explanation: These are separate control layers. Private Link and DNS provide private connectivity; disabling public network access removes the public access path. Key Vault data-plane permissions restrict which identity can read secrets, while diagnostic settings support audit and investigation. A resource lock does not provide these controls.
Question 3 — Infrastructure as code security
A development team deploys Azure infrastructure through Bicep templates and a CI/CD pipeline. Security requirements state that templates containing known security issues should be identified before deployment, and that noncompliant resource configurations must be blocked from production.
Which approach best meets these requirements?
A. Integrate supported infrastructure-as-code scanning into the development pipeline and enforce applicable Azure Policy controls during deployment.
B. Enable Microsoft Defender for Servers after all resources have been deployed.
C. Assign the deployment identity the Owner role and rely on developers to review templates manually.
D. Apply a CanNotDelete lock to the resource group before each deployment.
Correct answer: A
Explanation: Scanning templates in the development pipeline can identify security problems before resources are deployed. Azure Policy can enforce applicable resource requirements at deployment time, depending on the policy definition and effect. These controls complement each other: template scanning identifies issues early, while policy enforcement helps prevent noncompliant deployments.
Question 4 — OAuth application permissions
A background application needs to read files from a designated SharePoint site without a signed-in user. The application currently requests broad Microsoft Graph application permissions. The security team wants to minimize the data the application can access.
What should the team do?
A. Convert all application permissions to delegated permissions, even though no user will be signed in.
B. Assign the application Global Administrator so it can access only the intended site.
C. Review the required application permissions and implement a supported site-scoped authorization approach, such as appropriately configured selected-site permissions, granting access only to the required site.
D. Enable user consent for all application permissions and allow the application to choose its own access scope.
Correct answer: C
Explanation: Application permissions allow an application to act without a signed-in user and can be broad if not restricted. For supported SharePoint and Microsoft Graph scenarios, selected-site permissions can restrict an application’s access to designated sites, subject to the relevant permission model and setup. Granting tenant-wide administrative access would violate least privilege.
Question 5 — Microsoft Entra agent identity security
An organization uses autonomous AI agents that obtain Microsoft Entra tokens to access internal APIs. The security team wants to block high-risk agent identities and ensure that new agents in an approved category receive the same policy automatically.
Which TWO actions best support these requirements?
A. Configure an applicable Conditional Access policy to block agent identities identified as high risk.
B. Create an Azure resource lock on each API and use it as the agent access policy.
C. Use supported custom security attributes to categorize agent identities and target the appropriate Conditional Access policy so matching future identities are covered.
D. Create a policy targeting all human users and assume it automatically includes every agent identity and agent user account.
Correct answers: A and C
Explanation: Conditional Access can block risky agent identities where the relevant capabilities and licensing are available. Supported custom security attributes can help target policies by agent category, including matching future identities. Agent identities and agent user accounts are distinct identity types, so a policy targeting one should not be assumed to cover the other. Conditional Access also does not replace authorization checks on the target API.
Question 6 — Managed identity and Key Vault access
A Function App needs to retrieve a database password from Azure Key Vault. The organization prohibits storing credentials in application settings and source code. The Function App should have no permission to create or delete secrets.
Which configuration is most appropriate?
A. Create a service principal with a client secret and store the secret in an encrypted application setting.
B. Assign the Function App the Key Vault Administrator role and rotate the database password monthly.
C. Use the Function App’s system-assigned managed identity and assign it Owner at the subscription scope.
D. Enable a managed identity for the Function App and grant it only the required Key Vault secret-read permission through the supported authorization model.
Correct answer: D
Explanation: Managed identities allow supported Azure resources to authenticate to Microsoft Entra-protected services without managing application credentials. A narrowly scoped secret-read permission meets the stated need while avoiding unnecessary create and delete permissions. Subscription-level Owner and Key Vault Administrator are excessive for this scenario.
Question 7 — Regulatory compliance versus security enforcement
A company must evaluate its Azure environment against a regulatory compliance standard and identify which security controls are not satisfied. It also needs to prevent newly deployed storage accounts from violating a mandatory configuration requirement.
Which combination is most appropriate?
A. Use Azure Activity Logs to generate regulatory compliance assessments and resource locks to enforce all storage configuration rules.
B. Use Microsoft Defender for Cloud’s regulatory compliance capabilities to assess control status, and Azure Policy to enforce the applicable storage configuration requirement.
C. Use Microsoft Sentinel analytics rules to configure storage account properties and Defender EASM to block deployments.
D. Use Azure Backup reports to assess every regulatory control and PIM to enforce storage encryption.
Correct answer: B
Explanation: Defender for Cloud’s regulatory compliance dashboard helps assess security posture against supported standards and track control status. Azure Policy can audit, deny, or remediate supported resource configurations depending on the policy effect and resource provider support. Compliance assessment and configuration enforcement are related but distinct functions.
Section 2 — Secure storage, databases, and networking
Question 8 — Storage access for an external partner
A company must allow an external partner to upload files to one Azure Blob Storage container for the next two hours. The partner must not read existing blobs, list other containers, or access the storage account key.
Which approach best meets the requirement?
A. Assign the partner Storage Account Contributor at the subscription scope.
B. Enable anonymous read/write access on the storage account and disable it after two hours.
C. Issue a short-lived SAS restricted to the required container and create/write operations, with an appropriate validity period and secure distribution; use a user delegation SAS where supported and appropriate.
D. Give the partner the storage account key and request that it be deleted after the transfer.
Correct answer: C
Explanation: A narrowly scoped, short-lived SAS can grant only the required operations on the specified resource. A user delegation SAS uses Microsoft Entra credentials to obtain a user delegation key rather than relying on the storage account key. Because SAS tokens are bearer credentials, they must be protected and their validity and permissions kept as limited as practical.
Question 9 — Azure SQL private connectivity
An Azure SQL Database has a private endpoint. A workload in a connected on-premises network still resolves the SQL server hostname to a public IP address. The private endpoint itself reports as approved.
Which action is the best next step?
A. Verify the private DNS zone records and configure the appropriate DNS forwarding or resolution path so the on-premises workload resolves the SQL hostname to the private endpoint address.
B. Enable Transparent Data Encryption on the database.
C. Assign the on-premises server the SQL Server Contributor role.
D. Disable SQL auditing to prevent DNS conflicts.
Correct answer: A
Explanation: A private endpoint does not automatically ensure that every connected network resolves the service hostname to its private IP address. The DNS architecture must be configured for the client environment, including appropriate private DNS records and forwarding or resolver configuration. TDE and auditing do not resolve network names.
Question 10 — Azure Firewall versus NSGs
A company needs to enforce outbound access to approved internet FQDNs from multiple Azure subnets. It also needs centralized inspection and consistent policy management rather than separate FQDN rules on each subnet.
Which solution is most appropriate?
A. Configure a separate NSG on every subnet with rules for the domain names.
B. Use Azure Bastion and allow all outbound traffic from each VM.
C. Configure a private endpoint for every internet destination.
D. Route relevant outbound traffic through Azure Firewall and configure suitable application rules for the approved FQDNs, with a routing design that ensures traffic traverses the firewall.
Correct answer: D
Explanation: Azure Firewall provides centralized network traffic filtering, including FQDN-based application rules for supported protocols and configurations. Routing is essential: traffic that bypasses the firewall will not be inspected by it. NSGs primarily filter based on network attributes such as source and destination IP addresses, ports, and protocols.
Question 11 — Azure SQL security at rest and in use
Match each Azure SQL security control to its primary purpose.
| Control | Primary purpose |
|---|---|
| 1. Transparent Data Encryption (TDE) | A. Records selected database events for auditing and investigation |
| 2. SQL auditing | B. Helps identify potential database vulnerabilities and insecure configurations |
| 3. Microsoft Defender for Databases vulnerability assessment | C. Encrypts supported database data at rest |
| 4. Microsoft Entra authentication | D. Authenticates users or applications using Microsoft Entra identity |
Choose the correct mapping.
A. 1-A, 2-C, 3-D, 4-B
B. 1-C, 2-A, 3-B, 4-D
C. 1-D, 2-B, 3-A, 4-C
D. 1-C, 2-D, 3-B, 4-A
Correct answer: B
Explanation: TDE protects database data at rest. SQL auditing records configured database events. Defender for Databases vulnerability assessment helps identify potential weaknesses and misconfigurations. Microsoft Entra authentication provides an identity-based authentication mechanism. These controls are complementary, not interchangeable.
Question 12 — Network security group troubleshooting
A virtual machine can connect to an application server, but connections to a database subnet fail. An NSG is associated with both a subnet and a network interface. The team needs to determine whether the intended source-to-destination flow is denied by an effective rule.
Which action should the engineer take first?
A. Enable Defender for Storage on the database subnet.
B. Create a ReadOnly lock on the virtual network.
C. Use Azure Network Watcher’s IP flow verify for the relevant source, destination, protocol, and port, then inspect effective security rules if further analysis is needed.
D. Enable SQL auditing and use it to identify the NSG rule that blocked the packet.
Correct answer: C
Explanation: IP flow verify tests a specified flow and reports whether it is allowed or denied and which security rule determines the result. Effective security rules provide a broader view of rules applied to the network interface. SQL auditing records database activity; it does not identify an NSG rule that prevented a connection.
Question 13 — Protect storage from suspicious file uploads
A storage account receives files from multiple external partners. The security team wants to detect suspicious storage activity and scan uploaded blobs for malware where supported. The team does not want to expose the files publicly.
Which approach is best?
A. Enable anonymous access so Defender can inspect every file.
B. Assign every partner the Storage Blob Data Owner role.
C. Configure an Azure resource lock and assume it will detect malicious files.
D. Configure Microsoft Defender for Storage’s applicable threat detection and malware-scanning capabilities, while separately enforcing appropriate storage authorization and network restrictions.
Correct answer: D
Explanation: Defender for Storage offers security monitoring and, where supported and configured, malware scanning for uploaded blobs. Storage authorization and network controls still determine who can access the data and from where. Malware scanning does not require making blobs public, and a resource lock does not detect malicious content.
Question 14 — Azure VPN Gateway and Microsoft Entra Private Access
A company has two different connectivity requirements:
- Connect an on-premises network to an Azure virtual network using a site-to-site network tunnel.
- Allow individual remote employees to access specific private enterprise applications without giving them broad network access.
Which mapping is most appropriate?
A. Use Azure VPN Gateway for the site-to-site connection, and Microsoft Entra Private Access for identity-aware access to supported private applications.
B. Use Azure Bastion for the site-to-site tunnel, and an NSG for user identity verification.
C. Use Azure Private Link for the site-to-site tunnel, and Azure Firewall for all employee authentication.
D. Use Microsoft Entra Private Access for the virtual network gateway, and Azure Policy to authenticate employees.
Correct answer: A
Explanation: Azure VPN Gateway provides VPN connectivity, including site-to-site connectivity between networks. Microsoft Entra Private Access supports identity-aware access to supported private resources and applications. Bastion is designed for secure VM management connectivity, while NSGs and Azure Policy do not replace identity-aware application access.
Question 15 — Key Vault secret detection and remediation
A security engineer discovers that a developer accidentally committed a production credential to a source repository. The company wants to identify exposed secrets across supported cloud resources and reduce the chance that discovered credentials can be abused.
Which response is most appropriate?
A. Apply a CanNotDelete lock to the repository’s resource group.
B. Use Defender CSPM’s supported secret-scanning capabilities to identify relevant exposures, then rotate or revoke the exposed credential and remediate its storage location.
C. Enable TDE on all SQL databases and consider the incident resolved.
D. Disable all Key Vault diagnostic logs to prevent the secret from appearing in monitoring systems.
Correct answer: B
Explanation: Supported secret-scanning capabilities in Defender CSPM can help identify exposed credentials in applicable environments. Detection is only the first step: a leaked credential should be treated as compromised, rotated or revoked, and removed from inappropriate locations. Resource locks and database encryption do not invalidate an exposed secret.
Section 3 — Secure compute
Question 16 — Protecting a virtual machine’s boot chain
A security baseline requires supported Azure VMs to verify boot components and provide a virtualized hardware root of trust. The baseline also requires the organization to validate whether a VM image and size support these features before rollout.
Which approach best meets the requirement?
A. Enable JIT VM access and treat it as a replacement for boot integrity.
B. Enable Azure Disk Encryption alone.
C. Deploy supported VMs with Trusted Launch, enable Secure Boot and vTPM as appropriate, and validate compatibility before deployment.
D. Assign the VM a managed identity and enable a resource lock.
Correct answer: C
Explanation: Trusted Launch provides supported VM security features such as Secure Boot and vTPM. Secure Boot helps prevent unauthorized boot components from loading, while vTPM supports virtualized hardware-root-of-trust scenarios. Disk encryption and JIT access protect different parts of the VM security posture.
Question 17 — Disk encryption and key management
A company must protect data stored on supported VM disks and maintain control over the keys used for the selected encryption design. The security team also requires access to keys to be restricted and audited.
What should the engineer do?
A. Select an appropriate supported VM disk-encryption design, configure the required key management through the supported service, and apply least-privilege access and monitoring to the keys.
B. Enable a network security group and assume that all disk data is encrypted.
C. Give all VM administrators unrestricted Key Vault access to simplify recovery.
D. Disable encryption and rely on storage-account firewall rules.
Correct answer: A
Explanation: Disk encryption protects data at rest, while the selected encryption method determines how keys are managed. Key access should be restricted to required identities and monitored. The exact configuration depends on the VM, operating system, disk type, and supported encryption method; an NSG is not a disk-encryption control.
Question 18 — Secure access to Azure VMs
A security policy prohibits public IP addresses on management VMs. Administrators must connect to Windows and Linux VMs over RDP or SSH through the Azure portal or supported client workflows without exposing those management ports directly to the internet.
Which solution is most appropriate?
A. Allow inbound RDP and SSH from all IP addresses but require strong passwords.
B. Assign all administrators permanent Contributor access to the subscription.
C. Enable public IP addresses on every VM and use Azure Policy to record connections.
D. Deploy Azure Bastion in the appropriate virtual network design and restrict direct inbound management access to the VMs.
Correct answer: D
Explanation: Azure Bastion provides secure RDP and SSH connectivity to supported VMs without requiring a public IP address on each target VM. Direct inbound management ports should be restricted so the Bastion path is the intended access route. Bastion does not replace identity governance or OS-level security.
Question 19 — Azure Machine Configuration
A security team wants to assess supported operating-system settings on Azure VMs and Arc-enabled servers against required configurations. It also wants to enforce supported settings and track compliance.
Complete the statement:
Azure __________ can audit and enforce supported machine configuration settings.
A. Network Watcher
B. Machine Configuration
C. Private Link
D. Azure Firewall Manager
Correct answer: B — Machine Configuration
Explanation: Azure Machine Configuration supports auditing and enforcement of supported machine settings on applicable Azure and Arc-enabled machines. It can help detect configuration drift and maintain compliance with defined requirements. The other services focus on network diagnostics, private connectivity, or firewall management.
Question 20 — AI Gateway governance
A company has several AI applications calling models in Microsoft Foundry. It wants to centralize governance of model traffic, apply supported access restrictions, and monitor usage for signs of misuse rather than implementing separate gateway controls in every application.
Which approach is most appropriate?
A. Place a resource lock on every model deployment.
B. Configure only Microsoft Purview retention policies and assume they enforce runtime model access.
C. Configure the applicable AI Gateway in Microsoft Foundry, apply its supported access controls and monitoring, and ensure the applications route model traffic through the governed gateway.
D. Allow direct model access from every application and rely exclusively on Azure Activity Logs.
Correct answer: C
Explanation: AI Gateway provides a centralized approach to governing and monitoring AI model traffic. Its supported access restrictions and monitoring help apply consistent controls. Applications that bypass the gateway will not receive gateway-level enforcement, so the architecture must direct relevant traffic through it.
Question 21 — Copilot Studio agent protection
An organization deploys Copilot Studio agents that can interact with users and organizational data. The security team wants supported real-time protection to identify potentially risky interactions and help prevent harmful or malicious content from being processed.
Which approach is most appropriate?
A. Disable all authentication for the agents so that the protection service can inspect every request.
B. Use an Azure resource lock on the agent environment and assume it blocks prompt injection.
C. Use SQL auditing as the primary control for agent conversations.
D. Configure the applicable Microsoft Defender protection for Copilot Studio agents and validate the supported real-time protection settings, alongside appropriate identity and data-access controls.
Correct answer: D
Explanation: The relevant Defender capabilities can provide supported real-time protection for Copilot Studio agents. The available protection depends on the environment, configuration, and supported features. Identity permissions and data controls remain important because content inspection alone cannot eliminate all agent risks.
Question 22 — Managed identity in Azure Functions
An Azure Function must retrieve a secret from Key Vault and write results to a specific blob container. The organization wants to avoid credentials in code and minimize the blast radius if the Function is compromised.
Which design is best?
A. Use one shared service principal with subscription-level Owner access for both services.
B. Use a managed identity for the Function and grant only the required Key Vault secret-read and container-scoped storage data permissions, where supported.
C. Store the storage account key and Key Vault secret in the same environment variable.
D. Make the container public and remove the Function’s identity.
Correct answer: B
Explanation: Managed identities avoid storing application credentials. Separate, narrowly scoped permissions for Key Vault and Blob Storage reduce the impact of compromise. The identity should receive only the required data-plane permissions, not broad subscription management rights.
Question 23 — AI guardrails and data security
A team is deploying a generative AI application. It must reduce unsafe model responses and limit the risk that the model exposes sensitive organizational data. The team also wants visibility into AI-related security risks.
Which TWO measures address distinct parts of this requirement?
A. Configure appropriate model guardrails and content-safety controls for supported input and output risks.
B. Give the model identity broad read access to every SharePoint site so it can answer more questions.
C. Use a resource lock as the sole control for prompt injection and data leakage.
D. Use Microsoft Purview DSPM for AI and applicable Defender for Cloud AI security capabilities to identify and assess relevant data exposure and AI workload risks.
Correct answers: A and D
Explanation: Guardrails and content-safety controls can help mitigate specified unsafe input and output patterns. Purview DSPM for AI and Defender for Cloud’s applicable AI security capabilities provide complementary visibility into data exposure and AI workload risks. Neither makes broad data permissions safe, and no single safeguard guarantees prevention of all prompt-injection or data-leakage scenarios.
Section 4 — Manage and monitor security posture
Question 24 — Microsoft Sentinel data collection architecture
Match each collection method to the most appropriate description.
| Collection method | Description |
|---|---|
| 1. Windows event collection with Azure Monitor Agent | A. Ingest supported appliance logs formatted in a common security-event format using the supported forwarding architecture |
| 2. CEF ingestion | B. Collect selected Windows event channels or events using configured data collection |
| 3. Syslog ingestion | C. Collect supported syslog messages from configured Linux-based log sources or forwarders |
Choose the correct mapping.
A. 1-A, 2-C, 3-B
B. 1-C, 2-B, 3-A
C. 1-B, 2-A, 3-C
D. 1-B, 2-C, 3-A
Correct answer: C
Explanation: Azure Monitor Agent and Data Collection Rules support Windows event collection and other supported collection scenarios. CEF and syslog ingestion use supported forwarding architectures, often involving a Linux-based log forwarder and the relevant Sentinel connector configuration. The data source’s format and collection requirements determine the correct setup.
Question 25 — Microsoft Defender for Cloud multicloud posture
An organization uses Azure and another cloud provider. Its security team wants a consolidated view of security posture, applicable recommendations, and supported workload protection across environments.
Which approach is most appropriate?
A. Connect the supported multicloud environment to Microsoft Defender for Cloud using the appropriate cloud connector and configuration, then enable the relevant posture and workload-protection capabilities.
B. Install Azure Bastion in the other cloud and assume it imports all security findings.
C. Create a single Azure Policy assignment and assume it governs resources in every cloud provider without a connector or supported integration.
D. Export only Azure Activity Logs and treat them as a complete view of all cloud posture risks.
Correct answer: A
Explanation: Defender for Cloud supports multicloud security posture and workload protection through supported connectors and configuration. Coverage depends on the cloud provider, plan, and enabled capabilities. Azure Policy alone does not automatically govern all resources in another cloud provider, and activity logs do not provide a complete security posture assessment.
Question 26 — Microsoft Defender Vulnerability Management
A security team needs to identify vulnerable software on supported Azure VMs, prioritize findings, and track remediation. The team does not simply need to confirm that the VMs are reachable or that network rules are configured.
Which solution is the best fit?
A. Azure Network Watcher.
B. Azure Resource Health.
C. Azure Private DNS.
D. Configure the applicable Microsoft Defender for Servers and Defender Vulnerability Management capabilities, then review supported vulnerability findings and remediation recommendations.
Correct answer: D
Explanation: Defender for Servers and the applicable vulnerability-management capabilities help identify software vulnerabilities and prioritize remediation on supported machines. Network Watcher diagnoses network behavior, Resource Health reports service and resource availability, and Private DNS provides name resolution.
Question 27 — Sentinel automation and playbooks
A SOC wants to automatically assign newly generated incidents to the correct team based on incident properties. For incidents matching a high-priority condition, it also wants to invoke a workflow that notifies responders and performs supported response actions.
Which configuration is most appropriate?
A. Use an Azure Policy assignment to assign Sentinel incidents and configure a resource lock to execute the workflow.
B. Configure a Sentinel automation rule for the incident-handling logic and use a playbook for the required workflow actions.
C. Use a Data Collection Rule to assign incidents and an NSG to send notifications.
D. Use Defender EASM to classify every Sentinel incident and directly run Azure Backup.
Correct answer: B
Explanation: Sentinel automation rules can apply incident-management logic, such as assignment and status changes, based on configured conditions. Playbooks, commonly implemented using Azure Logic Apps, execute workflows such as notifications or supported response actions. The automation rule and playbook complement each other.
Question 28 — Attack path versus individual recommendation
Defender for Cloud reports several findings:
- A virtual machine is publicly accessible.
- The VM has a vulnerable software package.
- Its managed identity can access a sensitive storage resource.
The security team needs to understand how these conditions might combine into a path to a sensitive resource, rather than treating every finding independently.
Which capability should the team use?
A. Microsoft Sentinel workspace retention settings.
B. Azure Resource Health.
C. Defender for Cloud attack path analysis and related cloud security posture management tools.
D. Azure Key Vault certificate renewal.
Correct answer: C
Explanation: Attack path analysis helps connect exposures, vulnerabilities, identity permissions, and reachable resources to reveal potentially significant risk chains. It helps prioritize remediation based on the relationships between findings. Individual recommendations remain useful, but they may not show the combined path to a sensitive asset.
Question 29 — Security Copilot plugins and workspace permissions
A company allows security analysts to use Microsoft Security Copilot to investigate incidents. Some plugins can access sensitive security data or perform actions in connected services. The security team wants to ensure analysts receive only the capabilities required for their responsibilities.
Which approach is best?
A. Give every analyst unrestricted access to all plugins and agents so that investigations are never delayed.
B. Share one Global Administrator account for all Security Copilot investigations.
C. Disable audit logging and use the analysts’ team membership as the only security control.
D. Configure workspace roles and access according to least privilege, and review plugin and agent permissions and enablement before making capabilities available.
Correct answer: D
Explanation: Security Copilot governance requires appropriate workspace access controls and review of connected plugins and agents. The permissions available to a plugin or agent affect what it can access or do, so these capabilities should be enabled and assigned deliberately. Shared privileged accounts and unrestricted access weaken accountability and increase risk.
Question 30 — Data retention and audit investigation
An organization uses Microsoft Sentinel and Log Analytics to investigate security incidents. A policy requires selected security logs to be retained for an extended period, while keeping the cost of frequently queried data under control. Investigators must still be able to retrieve retained records when necessary.
Which approach is most appropriate?
A. Delete all records after seven days and rely on incident summaries.
B. Configure appropriate table-level retention and, where suitable and supported, long-term retention or archive settings for the relevant data, validating the retrieval and query limitations.
C. Apply a ReadOnly lock to the Log Analytics workspace and assume the lock enforces retention.
D. Turn off data collection after an incident so that the existing records remain available indefinitely.
Correct answer: B
Explanation: Retention should be configured according to the applicable policy, data table, and supported Log Analytics retention options. Long-term retention or archive options can help reduce the cost of keeping data that is accessed less frequently, but retrieval and query behavior may differ from interactive analytics. Resource locks do not define log retention, and stopping collection does not guarantee indefinite retention.
Final preparation advice:
Across all four exams and exam topics, prioritize understanding why a control is appropriate and what it does not do. For example, encryption does not replace authorization, a security recommendation does not necessarily enforce a configuration, and a detection tool does not automatically remediate the underlying issue.
Go to the SC-500 Exam Prep Hub main page
