Tag: SC-500 Practice Exam

SC-500 Practice Exam #2

This practice exam is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.

Implementing End-to-End Security Controls for Cloud and AI Workloads


Section 1: Manage Identity, Access, and Governance


Question 1 — Privileged Identity Management

A company uses Microsoft Entra Privileged Identity Management (PIM) to control access to privileged roles. A security administrator must ensure that administrators cannot retain permanent active assignments to a highly privileged role. Administrators must request access when needed, provide justification, and activate the role for a limited period.

Which configuration best meets these requirements?

A. Assign the role permanently as active and require multifactor authentication at every sign-in.

B. Create eligible assignments, configure activation requirements, and set a maximum activation duration.

C. Assign the role through an Azure Policy initiative and configure a resource lock.

D. Create a Conditional Access policy that blocks all users outside the corporate network.

Answer: B

Explanation: Eligible assignments allow users to activate a role when required rather than having permanent active privileges. PIM can require justification, multifactor authentication, approval, and a limited activation duration, depending on the role and configuration.

Conditional Access can add authentication and access restrictions, but it does not replace PIM’s eligible-assignment and activation workflow. Azure Policy and resource locks govern Azure resources, not Microsoft Entra privileged-role activation.


Question 2 — Authentication Methods

A company wants employees to sign in using phishing-resistant authentication. The security team wants to prioritize a method that does not rely on a password and is designed to resist credential phishing.

Which option is the best fit?

A. SMS one-time passcodes

B. Email one-time passcodes

C. Security questions

D. Passkeys using FIDO2 security keys

Answer: D

Explanation: FIDO2 security keys and supported passkey implementations provide phishing-resistant authentication. Authentication is cryptographically bound to the legitimate relying party, helping prevent credentials from being reused on a fraudulent website.

SMS and email codes can be vulnerable to phishing or interception, and security questions are not a strong authentication method.

Exam tip: Distinguish between merely adding another authentication step and using a phishing-resistant authentication method.


Question 3 — Azure RBAC and Least Privilege

A developer must restart virtual machines in a specific resource group. The developer must not be able to create virtual machines, modify network security groups, or assign roles to other users.

Which approach best follows least privilege?

A. Assign Owner at the subscription scope.

B. Assign Contributor at the subscription scope.

C. Assign a suitable narrowly scoped role that permits the required VM restart operation at the resource group or resource scope.

D. Assign User Access Administrator at the resource group scope.

Answer: C

Explanation: Azure RBAC assignments should grant only the required actions at the narrowest practical scope. A suitable built-in role or custom role can permit VM restart operations without granting broad resource-management or role-assignment permissions.

Owner and Contributor are too broad for this requirement. User Access Administrator focuses on managing access assignments rather than restarting VMs.


Question 4 — Scenario: Azure Policy and Resource Locks

A production resource group contains a critical Azure resource. The organization wants to accomplish two things:

  1. Prevent accidental deletion of the resource.
  2. Require newly deployed storage accounts to use secure transfer.

Which combination of controls should be used?

A. A CanNotDelete resource lock and an Azure Policy definition enforcing secure transfer.

B. A ReadOnly resource lock and a Microsoft Sentinel automation rule.

C. A PIM eligible assignment and a Key Vault certificate.

D. A Defender for Cloud recommendation and a network security group.

Answer: A

Explanation: A CanNotDelete lock prevents deletion while allowing permitted modifications. Azure Policy can audit or deny storage-account configurations that do not meet the secure-transfer requirement.

A ReadOnly lock is more restrictive and can prevent many write operations. Sentinel automation rules and PIM do not directly enforce these two resource requirements.

Important distinction: Resource locks protect resources from certain management operations. Azure Policy evaluates and enforces resource configuration requirements.


Question 5 — Fill in the Blank: Azure Resource Access

An application hosted on an Azure resource must access Azure Key Vault without embedding a client secret in its code. The application should authenticate using an identity managed by Azure.

The capability to configure is a __________ identity.

A. guest

B. managed

C. consumer

D. shared

Answer: B. managed

Explanation: Managed identities provide Azure resources with identities that can authenticate to supported services. Azure manages the credentials, reducing the need to store and rotate application secrets.

Authentication alone does not grant access to Key Vault. The managed identity must also receive the appropriate authorization, such as a suitable Key Vault data-plane role when using Azure RBAC authorization.


Question 6 — Multiple Answer: Azure Backup Security

An organization wants to strengthen the security of its Azure Backup recovery points against accidental or malicious deletion.

Which two controls should the security team consider?

A. Configure Azure Bastion for all backup vaults.

B. Enable Microsoft Sentinel syslog collection.

C. Use Azure Backup security features such as soft delete and, where supported, immutability.

D. Configure Multi-User Authorization (MUA) for supported critical backup operations.

Answer: C and D

Explanation: Azure Backup provides several layers of protection for recovery points and critical operations.

  • Soft delete helps protect backup data from accidental or malicious deletion by retaining deleted backup data for a configured or service-defined period.
  • Immutability, where supported and appropriately configured, helps prevent protected backup data from being modified or deleted.
  • Multi-User Authorization (MUA) adds an approval layer for supported critical operations, reducing the risk of a single compromised administrator destroying backups.

Bastion is for secure VM administration. Syslog collection supports monitoring but does not itself protect recovery points.


Question 7 — Scenario: Securing an API Plugin


A developer is building an API plugin for a declarative agent. The API accesses confidential business data and must verify the identity of the caller. The team wants delegated access so that the API can act within the signed-in user’s permitted access.

Which authentication approach most directly supports this requirement?

A. Publish the API without authentication and rely on network restrictions.

B. Embed a shared administrator password in the plugin definition.

C. Use a managed identity for the API and assume it automatically represents every user’s delegated permissions.

D. Configure an appropriate Microsoft identity platform OAuth authentication flow with delegated permissions and consent.

Answer: D

Explanation: OAuth-based authentication with delegated permissions allows an application to access an API on behalf of a signed-in user, within the granted permissions and consent framework.

A managed identity can authenticate an Azure-hosted workload as itself, but it does not automatically represent the user’s delegated permissions. Network restrictions are useful defense in depth, not a replacement for API authentication and authorization.


Section 2: Secure Storage, Databases, and Networking


Question 8 — Scenario: Azure Storage Network Restrictions

A company stores confidential files in an Azure Storage account. Only clients on approved corporate networks should be able to connect to the storage service. The security team also wants to retain identity-based authorization for users accessing blobs.

Which configuration best meets these requirements?

A. Enable anonymous blob access and use Azure Policy to audit downloads.

B. Assign Storage Blob Data Contributor to all employees and rely on storage-account keys for network restrictions.

C. Configure the storage firewall to allow approved network paths and use Microsoft Entra ID-based authorization with appropriate data-plane permissions.

D. Enable Microsoft Defender for Storage and leave the storage account’s network access unrestricted.

Answer: C

Explanation: The storage firewall or network access settings restrict which network paths can reach the storage account. Microsoft Entra ID-based authorization and appropriate data-plane roles control what an authenticated identity can do with blob data.

Defender for Storage provides additional threat protection, but it does not replace network restrictions or authorization.


Question 9 — Multiple Answer: Azure SQL Security

A financial application uses Azure SQL Database. Auditors require a record of database activity, and the security team wants to detect suspicious database behavior and potential threats.

Which two capabilities should be configured?

A. Azure SQL auditing

B. Azure Bastion

C. Microsoft Defender for Databases

D. Azure Firewall Manager only

Answer: A and C

Explanation:

  • Azure SQL auditing records database events to support investigation, accountability, and compliance.
  • Microsoft Defender for Databases adds database threat-protection capabilities and can surface suspicious activities and security recommendations.

Bastion provides secure administrative access to VMs. Azure Firewall Manager manages firewall deployments and policies, not SQL auditing.


Question 10 — Scenario: Network Security Groups

An application has a web tier and a database tier in separate subnets. The database must accept connections from the web tier on TCP port 1433 but must not accept direct connections from the internet.

Which design is most appropriate?

A. Assign a public IP address to the database and use a broad outbound NSG rule.

B. Use an NSG rule to allow the required database traffic from the web tier, with other inbound traffic denied by the applicable rules.

C. Configure Azure Bastion to forward all application traffic to the database.

D. Enable Microsoft Defender for SQL and remove the database subnet’s network controls.

Answer: B

Explanation: Network security groups filter inbound and outbound traffic using rules that specify source, destination, port, protocol, and priority. An appropriately scoped rule can allow the web tier to connect to the database while blocking other unwanted connections.

NSGs are stateful, and their rules are evaluated by priority. Ensure that the effective rules and network architecture actually prevent direct internet access; simply adding an allow rule is not enough.


Question 11 — Matching: Private Connectivity

Match each Azure networking capability to its primary purpose.

CapabilityPurpose
1. Azure Private EndpointA. Encrypted connectivity between networks over a VPN
2. Azure VPN GatewayB. Filter traffic using network security rules at a subnet or network interface
3. Network Security GroupC. Provide a private IP-based connection to a supported service
4. Azure FirewallD. Centralized network traffic inspection and filtering

Answer

  • 1 → C
  • 2 → A
  • 3 → B
  • 4 → D

Explanation: A private endpoint maps a supported service to a private IP address in a virtual network. VPN Gateway provides VPN connectivity. NSGs filter network traffic at subnet or network-interface scope. Azure Firewall provides centralized network traffic filtering and inspection.

Exam trap: Private Link, VPN Gateway, NSGs, and Azure Firewall are complementary controls, not interchangeable services.


Question 12 — Scenario: Azure Key Vault Authorization

An application can successfully authenticate to Azure Key Vault using its managed identity, but it receives an authorization error when attempting to retrieve a secret. The vault uses Azure role-based access control for its data plane.

What should the administrator do?

A. Assign the managed identity an appropriate Key Vault data-plane role, such as Key Vault Secrets User, at the appropriate scope.

B. Assign the managed identity Reader at the subscription scope.

C. Enable Azure Bastion on the Key Vault.

D. Create a Sentinel playbook that retries the secret request.

Answer: A

Explanation: Authentication establishes the identity; authorization determines what that identity can access. With the Azure RBAC permission model, retrieving secrets requires an appropriate data-plane role, such as Key Vault Secrets User, at a suitable scope.

The Reader role generally provides control-plane read access to Azure resources; it does not grant permission to read secret values. A playbook cannot correct a missing authorization assignment.


Question 13 — Multiple Answer: Azure SQL Data Protection

A company wants to protect sensitive information in Azure SQL Database. Its requirements include encrypting stored database data and maintaining an audit trail of database activity.

Which two features best address these requirements?

A. Azure Bastion and JIT VM access

B. Azure Private Link and NSGs only

C. Microsoft Sentinel automation rules and Azure Policy only

D. Transparent Data Encryption (TDE) and Azure SQL auditing

Answer: D

Explanation: TDE encrypts database files and associated data at rest. Azure SQL auditing records selected database events for security investigation and compliance.

These controls address different objectives: encryption protects data at rest, while auditing supports accountability and investigation. Neither feature alone replaces identity controls, network security, or other data-protection measures.


Question 14 — Fill in the Blank: Azure Network Diagnostics

An administrator wants to determine which network security rules apply to a network interface and investigate why traffic is being allowed or denied.

The administrator should use Azure Network Watcher __________ security rules.

A. export

B. effective

C. privileged

D. delegated

Answer: B. effective

Explanation: Azure Network Watcher provides tools for examining effective security rules on a network interface. These help administrators understand the combined effect of applicable NSG rules and troubleshoot connectivity.

This is particularly useful when subnet-level and network-interface-level rules interact.


Question 15 — Scenario: Azure Private Link

An organization hosts a database service that supports Azure Private Link. The company wants clients in a virtual network to connect using a private IP address and wants to disable public network access where the service supports that configuration.

Which approach is most appropriate?

A. Create a public IP address and restrict access using a password.

B. Configure an NSG without creating a private connection to the service.

C. Create a private endpoint, configure the required name resolution, and disable public network access if supported and required.

D. Enable Microsoft Defender for Databases and assume the service no longer has a public endpoint.

Answer: C

Explanation: A private endpoint provides private IP-based connectivity to a supported service. Correct DNS configuration is important so that clients resolve the service name to the intended private endpoint. Where supported, disabling public network access provides an additional control.

A private endpoint does not automatically mean the public endpoint is disabled; that must be configured separately when the service supports it.


Section 3: Secure Compute


Question 16 — Scenario: Trusted Launch and Disk Encryption

A company is deploying a new Azure VM for a sensitive workload. The security team requires protection against boot-level attacks and encryption of data stored on the VM’s disks.

Which combination most directly addresses both requirements?

A. Azure Bastion and Microsoft Sentinel

B. Trusted Launch and an appropriate VM disk-encryption configuration

C. Azure Policy and Microsoft Entra PIM only

D. A network security group and a public IP address

Answer: B

Explanation: Trusted Launch provides VM security features such as Secure Boot and virtual TPM. Disk encryption protects data stored on supported VM disks.

These controls protect different layers. Trusted Launch does not, by itself, mean that all disk-encryption requirements have been met.


Question 17 — Multiple Answer: Azure Kubernetes Service

A security team is reviewing an Azure Kubernetes Service (AKS) deployment. It wants to reduce workload exposure and improve container security.

Which two actions are appropriate?

A. Review and apply AKS network and workload-isolation controls.

B. Enable Microsoft Defender for Containers for relevant protection and security insights.

C. Give every workload cluster Owner permissions on the subscription.

D. Make all container images publicly accessible to simplify deployment.

Answer: A and B

Explanation: AKS security is layered. Network policies and appropriate isolation controls help restrict workload communication, while Defender for Containers provides security capabilities for containerized environments.

Broad subscription permissions and publicly exposing container images increase risk rather than reducing it.


Question 18 — Scenario: Just-in-Time VM Access

Administrators need occasional RDP access to a group of Azure VMs. Security policy requires that management ports not remain unnecessarily exposed and that access requests be time-limited.

Which capability best meets this requirement?

A. Azure Storage firewall rules

B. Microsoft Purview DSPM

C. Azure SQL auditing

D. Just-in-time (JIT) VM access

Answer: D

Explanation: JIT VM access reduces persistent exposure of management ports by allowing access to be requested for a limited time under configured conditions. It is commonly used to reduce exposure of ports such as RDP and SSH.

JIT is not a replacement for identity authorization, network controls, or monitoring, but it directly addresses the requirement for time-limited management-port access.


Question 19 — Scenario: Azure App Service and Web Traffic

A company hosts a public web application on Azure App Service. The security team wants to protect the application from common web attacks, including malicious HTTP requests that match known attack patterns.

Which option is the best fit when the design calls for a Web Application Firewall (WAF)?

A. Azure Machine Configuration

B. Azure Backup soft delete

C. A supported WAF deployment, such as Azure Application Gateway WAF or Azure Front Door WAF, positioned to inspect the application’s web traffic

D. Microsoft Entra PIM

Answer: C

Explanation: A WAF can inspect HTTP(S) traffic and help protect web applications against common web exploits. The appropriate WAF product and deployment pattern depend on the application’s ingress architecture and requirements.

PIM controls privileged identity access, Azure Machine Configuration assesses or enforces machine configuration, and Backup soft delete protects backup data.


Question 20 — Matching: Application and Container Security

Match each technology or capability with its primary purpose.

TechnologyPurpose
1. Microsoft Defender for ContainersA. Secure API access, traffic policies, and backend integration
2. Azure API ManagementB. Assess or enforce supported machine configuration settings
3. Azure Machine ConfigurationC. Detect container-related risks and provide container security capabilities
4. Azure BastionD. Secure administrative access to Azure VMs

Answer

  • 1 → C
  • 2 → A
  • 3 → B
  • 4 → D

Explanation: Defender for Containers supports container security. API Management helps secure and govern APIs and their backend access. Azure Machine Configuration helps assess and enforce supported configuration settings on machines. Bastion provides secure RDP/SSH access to VMs.


Question 21 — Scenario: AI Guardrails

A company deploys an AI application using Microsoft Foundry. Testing reveals that the model sometimes returns harmful content and can be manipulated by adversarial prompts. The company wants to apply configurable controls to evaluate prompts and responses.

Which approach is most appropriate?

A. Enable Azure Bastion and restrict RDP access.

B. Configure and test appropriate Foundry guardrails, including relevant content filters and Prompt Shields.

C. Enable Azure SQL auditing.

D. Assign the AI application the Contributor role at the subscription scope.

Answer: B

Explanation: Microsoft Foundry guardrails can evaluate model interactions and apply controls such as content filters, blocklists, and Prompt Shields. The appropriate controls should be configured and validated against the application’s risk profile.

Guardrails help mitigate unsafe interactions and prompt-injection risks, but they do not eliminate all AI risks. Identity, data access, monitoring, and application-layer controls remain necessary.


Question 22 — Multiple Answer: AI Identity and Data Security

An organization has deployed AI agents that can access Microsoft 365 data and Azure resources. Security wants to assess risks caused by excessive agent permissions and overexposed organizational data.

Which two actions are appropriate?

A. Use Microsoft Defender XDR to investigate AI agent identities and assess potential blast radius.

B. Enable anonymous access to SharePoint so that agents do not need authorization.

C. Use Microsoft Purview Data Security Posture Management to identify relevant AI data risks and overexposure.

D. Replace all agent identities with a single shared administrator account.

Answer: A and C

Explanation: Microsoft Defender XDR can help discover AI agents and analyze identity-related risks and attack paths. Microsoft Purview DSPM helps identify data security risks associated with AI usage and data exposure.

Shared administrator accounts and anonymous access undermine least privilege and make it harder to establish accountability. Microsoft’s current AI security learning path covers both Entra Agent ID risk analysis and Purview DSPM for AI data risks.


Question 23 — Fill in the Blank: AI Traffic Security

An organization wants to apply centralized security and governance controls to model traffic for AI applications built with Microsoft Foundry. The relevant capability in the SC-500 learning path is AI Gateway in Azure __________ Management.

A. Identity

B. Storage

C. Firewall

D. API

Answer: D. API

Explanation: The SC-500 AI security learning path covers configuring AI Gateway in Azure API Management for Microsoft Foundry. The gateway can provide a centralized point for applying access restrictions, governance, and monitoring to AI model traffic.

AI Gateway complements other controls, including agent identity security, Foundry guardrails, and Defender for Cloud workload protection.


Section 4: Manage and Monitor Security Posture


Question 24 — Scenario: Prioritizing Cloud Security Risks

A security team uses Microsoft Defender for Cloud to assess hundreds of security recommendations. The team wants to identify issues that could contribute to a realistic attack path to a critical database, rather than simply fixing recommendations in alphabetical order.

Which capability is most appropriate?

A. Azure Backup soft delete

B. Microsoft Entra password protection

C. Defender CSPM attack path analysis

D. Microsoft Sentinel workspace retention

Answer: C

Explanation: Defender CSPM attack path analysis helps identify chains of security issues that could expose important resources to attack. It provides context for prioritizing risks based on potential attack paths rather than treating every recommendation as equally urgent.

For example, an internet-exposed workload with excessive permissions and access to a sensitive database may deserve higher priority than an isolated configuration issue. Attack path analysis and Cloud Security Explorer are covered in Microsoft’s Defender for Cloud learning path.


Question 25 — Multiple Answer: Microsoft Sentinel Data Collection

A company is onboarding network security appliances and Windows servers to Microsoft Sentinel. The appliances can send Common Event Format (CEF) messages, while Windows servers use Windows Event Forwarding (WEF).

Which two statements are correct?

A. CEF collection and Windows Security event collection using DCRs are distinct ingestion configurations.

B. Enabling a Sentinel automation rule automatically configures every appliance to send logs.

C. WEF eliminates the need to configure the appropriate data collection path into Azure Monitor and Sentinel.

D. A Sentinel playbook must be used to parse every CEF message before it can be ingested.

Answer: A

Explanation: CEF and Windows Security events use different collection configurations. For Windows Security events, DCRs can define which events are collected, including scenarios involving WEF. CEF collection requires the appropriate forwarding and ingestion setup for the source appliance.

Automation rules and playbooks help automate security operations; they do not automatically configure log sources or replace ingestion pipelines.

Important: This is a multiple-answer-style question, but only A is correct as written. In a live exam, always follow the number of answers requested and evaluate each option independently.


Question 26 — Scenario: Defender for Cloud Multicloud Coverage

An organization has workloads in Azure and AWS. The security team can see Azure recommendations in Defender for Cloud but does not have the expected security posture visibility for its AWS environment.

What should the team do first?

A. Deploy Azure Bastion in the AWS account.

B. Configure the appropriate AWS connector and required integration settings in Defender for Cloud, then verify the connected resources and enabled capabilities.

C. Create an Azure Policy assignment directly on the AWS resources.

D. Enable Microsoft Sentinel’s Windows Security Events connector.

Answer: B

Explanation: Defender for Cloud can integrate with AWS to provide security posture visibility and, depending on the configured plans and integration, workload protection. The security team should configure the appropriate connector, authentication, scope, and required plans, then verify that the intended resources are covered.

Azure Policy does not directly govern AWS resources in the same way it governs Azure resources. A Sentinel Windows event connector does not establish Defender for Cloud’s AWS integration.


Question 27 — Matching: Security Posture Tools

Match each capability with the task it most directly supports.

CapabilityTask
1. Defender CSPMA. Assess compliance against regulatory frameworks and identify control gaps.
2. Defender for Cloud regulatory complianceB. Discover and investigate external attack-surface exposure
3. Microsoft Defender EASMC. Assess cloud posture and prioritize security risks
4. Microsoft Defender for Servers vulnerability assessmentD. Identify vulnerabilities on covered servers and VMs

Answer

  • 1 → C
  • 2 → A
  • 3 → B
  • 4 → D

Explanation: These tools support related but different security outcomes:

  • Defender CSPM identifies posture issues and helps prioritize risk.
  • Regulatory compliance evaluates the environment against selected security standards and frameworks.
  • Defender EASM discovers and assesses externally visible assets.
  • Defender for Servers vulnerability assessment identifies vulnerabilities on covered servers and VMs.

Question 28 — Scenario: Security Copilot Agent Permissions

A company wants to deploy a partner-built agent from Microsoft Security Store. During setup, the agent requests permissions to access Microsoft security product data. The agent cannot be fully configured until the required permissions are approved.

Which action should the organization expect to take?

A. Grant the agent unrestricted subscription Owner access without reviewing its requested permissions.

B. Disable all Microsoft Entra authentication requirements for the agent.

C. Remove all plugins and assume the agent will retain its original capabilities.

D. Have an appropriately authorized Global Administrator review and approve the required Microsoft product permissions, then complete the remaining setup using an authorized Security Copilot role.

Answer: D

Explanation: Partner-built Security Copilot agents that require access to Microsoft product data can require Global Administrator approval of their requested permissions. The administrator should review the requested permissions and approve only as appropriate. An authorized Security Copilot Owner or Contributor can then complete the remaining setup steps.

The key principle is to review and approve permissions deliberately rather than granting broad access by default. Acquiring a partner agent and configuring its operational permissions are related but distinct steps.


Question 29 — Fill in the Blank: Defender for Cloud AI Protection

A company wants to secure AI workloads through Microsoft Defender for Cloud. The team wants to review AI-related security posture insights, detect runtime threats, and investigate security alerts.

The Microsoft Defender for Cloud dashboard specifically associated with these AI-related posture insights is the Data & __________ security dashboard.

A. Identity

B. Network

C. AI

D. Backup

Answer: C

Explanation: The dashboard is called the Data & AI security dashboard. It helps teams review insights related to AI security posture.

Defender for Cloud AI workload protection also involves enabling the appropriate AI protection plan, assessing posture through CSPM, detecting runtime threats through workload protection, and investigating incidents in Microsoft Defender XDR.


Question 30 — Scenario: Investigating a Suspicious AI Agent

An organization detects an AI agent that appears to have access to more resources than it needs. The security team wants to understand which resources could be affected if the agent’s identity were compromised and whether the agent has risky paths to sensitive data.

Which approach is most appropriate?

A. Use Microsoft Defender XDR to discover the agent and investigate its identity-related risks and potential blast radius.

B. Use Azure Storage lifecycle management to delete old files.

C. Use Azure Bastion to rotate the agent’s permissions.

D. Use Azure SQL auditing as the sole tool for analyzing all agent identity relationships.

Answer: A

Explanation: Microsoft Defender XDR can help security teams discover AI agents and investigate identity-related risks, including potential blast radius and attack paths. This helps determine which resources or data might be exposed if an agent identity is compromised.

The investigation should be followed by remediation, such as reducing excessive permissions, correcting access assignments, and reviewing the agent’s identity lifecycle. Microsoft’s current AI security learning path specifically covers discovering AI agents and assessing their blast radius.


What to review after this exam

Focus especially on the distinctions that commonly drive scenario questions:

  • Authentication vs. authorization: successful sign-in does not automatically grant access to Key Vault or other resources.
  • Azure Policy vs. resource locks: configuration governance is different from protection against resource deletion or modification.
  • Private endpoints vs. public access: creating a private endpoint does not necessarily disable a service’s public endpoint.
  • Trusted Launch vs. disk encryption: boot integrity and encryption at rest solve different problems.
  • Defender CSPM vs. workload protection: posture management identifies and prioritizes weaknesses; workload protection detects threats to supported workloads.
  • Sentinel ingestion vs. automation: connectors and collection configurations bring logs into the workspace; automation rules and playbooks support response workflows.
  • AI guardrails vs. AI identity controls: guardrails evaluate model interactions, while identity and access controls govern which resources an agent can reach.

Go to the SC-500 Exam Prep Hub main page

SC-500 Practice Exam #3

This practice exam is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.

Implementing End-to-End Security Controls for Cloud and AI Workloads


Section 1 — Manage identity, access, and governance


Question 1 — Privileged Identity Management (PIM)

A security administrator has a standing Owner role assignment at the subscription level. The organization wants to reduce standing privileges while allowing the administrator to perform emergency configuration changes when necessary. The administrator should provide justification, complete multifactor authentication, and have the activation approved by another administrator.

Which configuration best meets these requirements?

A. Assign the Contributor role permanently and use an Azure Policy exemption for emergency changes.

B. Create a custom Azure role and assign it permanently at the management group scope.

C. Convert the Owner assignment to an eligible PIM assignment and configure approval, justification, and MFA requirements for activation.

D. Create a resource lock and configure an alert to notify the security team whenever the administrator changes a resource.

Correct answer: C

Explanation: Microsoft Entra Privileged Identity Management (PIM) supports eligible role assignments that users activate only when needed. Activation requirements can include justification, MFA, and approval. This reduces standing privileged access while retaining a controlled emergency-access process. A resource lock or policy exemption does not replace privileged access management.


Question 2 — Azure Key Vault protection

A company stores encryption keys and application secrets in Azure Key Vault. Its security policy requires that deleted secrets and keys cannot be permanently purged by an administrator before the configured retention period expires, even if the administrator has elevated permissions.

Which setting most directly enforces this requirement?

A. Enable purge protection.

B. Enable diagnostic settings and send audit logs to Log Analytics.

C. Configure a private endpoint for the vault.

D. Assign the Key Vault Reader role to all administrators.

Correct answer: A

Explanation: Purge protection prevents a deleted vault object from being permanently purged during its retention period. Soft delete retains deleted objects for recovery; purge protection prevents early permanent deletion. Diagnostic logging, private endpoints, and reader permissions serve different security purposes.


Question 3 — Conditional Access for AI agent identities

An organization deploys dozens of autonomous AI agents using Microsoft Entra Agent ID. All agents created from a particular agent identity blueprint must be blocked from accessing corporate APIs if they are identified as high risk. New agents created from that blueprint must automatically receive the same protection.

What should the security engineer configure?

A. A Conditional Access policy targeting all human users and requiring MFA.

B. An Azure Policy definition that audits agent registrations.

C. An access review that periodically checks the agents’ API permissions.

D. A Conditional Access policy targeting the relevant agent identity blueprint, with a control that blocks access when the configured risk condition is met.

Correct answer: D

Explanation: Conditional Access can target agent identities and agent identity blueprints. A policy applied to a blueprint covers agent identities derived from it, including future agents. Risk-based controls can block access when the applicable risk condition is met. The policy must target the correct identity type; a policy targeting human users does not automatically cover agent identities.


Question 4 — Azure Policy versus resource locks

A team manages production resources in Azure. Security requirements state that storage accounts must have secure transfer enabled and that a specific production database must not be deleted accidentally.

Which combination best addresses both requirements?

A. Assign the Reader role to the application team and enable diagnostic logging on the database.

B. Use Azure Policy to enforce or audit the secure-transfer configuration, and apply a CanNotDelete resource lock to the database.

C. Apply a ReadOnly lock to the subscription and use a management group to enable secure transfer.

D. Use Microsoft Defender for Cloud recommendations to block storage configuration changes and assign the database the Contributor role.

Correct answer: B

Explanation: Azure Policy evaluates resource configurations against defined rules and can audit, deny, or remediate supported configurations. A CanNotDelete lock prevents deletion while allowing authorized modifications. A ReadOnly lock is more restrictive and can prevent updates. Defender for Cloud provides posture recommendations, but recommendations alone do not enforce these controls.


Question 5 — Least-privilege access to Azure resources

A deployment operator needs to start and stop virtual machines in one resource group. The operator must not create virtual machines, change their networking, modify role assignments, or access other resource groups.

Which TWO approaches best support least privilege?

A. Assign Owner at the subscription scope and use activity logs to detect excess permissions.

B. Assign Contributor at the resource-group scope and ask the operator not to modify networking.

C. Create or use a role that includes the required virtual machine start/stop actions, and assign it at the narrowest suitable scope.

D. Assign a suitable built-in virtual machine operator role at the target resource-group scope, after verifying that its permitted actions meet the requirements.

Correct answers: C and D

Explanation: Least privilege means granting only the permissions needed at the narrowest appropriate scope. A custom role can precisely define allowed actions, while a suitable built-in role may already provide the required permissions. The role’s actual actions and any applicable data-plane permissions should be checked before assignment. Owner and Contributor are broader than the stated requirement.


Question 6 — OAuth permissions and consent

A developer registers an application that calls Microsoft Graph on behalf of signed-in employees. The application requests delegated permissions that allow it to read users’ files. The security team wants to minimize the risk of excessive access being granted during application consent.

Which action is most appropriate?

A. Review the requested delegated permissions and configure consent policies so that only approved permissions and appropriate consent workflows are allowed.

B. Assign the application the Global Administrator role so it can request consent without interruption.

C. Enable public network access for the application registration.

D. Create a resource lock on the application registration and assume that this prevents overprivileged consent.

Correct answer: A

Explanation: Delegated permissions allow an application to act on behalf of a signed-in user within the permissions granted to it and the user. Reviewing requested permissions and controlling user and administrator consent helps prevent excessive access. Global Administrator is not an appropriate default application permission, and resource locks do not control OAuth consent.


Question 7 — Protecting backup data

A company is concerned that an attacker who compromises an administrator account could delete recovery points and then encrypt the production environment. The company wants to strengthen the resilience of its Azure Backup data against destructive administrative actions.

Which approach is most appropriate?

A. Store backup logs in the same production virtual machine that is being protected.

B. Give all backup operators the Backup Contributor and Owner roles at the subscription level.

C. Rely exclusively on Azure Policy to prevent all possible backup deletions, without reviewing the backup configuration.

D. Configure the applicable Azure Backup security features, including immutable vault protection where supported, and restrict privileged backup operations using least-privilege access and appropriate safeguards.

Correct answer: D

Explanation: Backup resilience depends on multiple layers: restricting privileged operations, protecting backup configuration, and enabling supported immutability and deletion safeguards. Exact capabilities vary by workload and vault configuration, so verify which protections are supported for the protected data source. Broad administrative roles and co-locating logs with production workloads do not adequately protect recovery points.


Section 2 — Secure storage, databases, and networking


Question 8 — Eliminate public exposure of Azure Storage

A storage account contains confidential documents used by an application hosted in an Azure virtual network. The application must continue to access the storage account, but the company wants to eliminate access through the storage account’s public network endpoint.

Which configuration best meets the requirement?

A. Allow all public IP addresses in the storage firewall and require HTTPS.

B. Configure a private endpoint, ensure the application resolves the storage account name to the private endpoint IP address, and disable public network access after validating the private connectivity.

C. Create an NSG rule that blocks inbound traffic to the storage account’s public endpoint.

D. Enable Microsoft Defender for Storage and leave the public network endpoint enabled.

Correct answer: B

Explanation: Azure Private Link provides private connectivity to supported Azure services through a private endpoint in a virtual network. Correct DNS configuration is essential so the application resolves the service name to the private IP address. Disabling public network access removes the public access path; Defender for Storage detects threats but does not itself remove public exposure.


Question 9 — Secure access to Azure Storage

A data-processing application needs temporary access to blobs in an Azure Storage account. The organization wants to avoid distributing the storage account key and wants to issue a time-limited token using Microsoft Entra credentials.

Which option is the best fit?

A. Embed the storage account access key in the application’s source code and rotate it every month.

B. Assign the application the Owner role at the subscription level.

C. Make the container public and rely on application-level authentication.

D. Use a user delegation SAS, generated using Microsoft Entra credentials, and restrict its permissions and validity period to the required operations.

Correct answer: D

Explanation: A user delegation SAS is signed using a user delegation key obtained through Microsoft Entra authorization rather than a storage account key. The SAS should have only the necessary permissions and a limited validity period. It remains a bearer token, so it must be protected against disclosure. Public containers and embedded account keys increase exposure.


Question 10 — Detect threats against Azure Storage

A company uses Azure Blob Storage to receive files from external partners. The security team wants threat detection that can identify suspicious storage activity and malware in uploaded files, using Microsoft Defender’s storage protections where supported.

What should the team implement?

A. Enable Microsoft Defender for Storage and configure the relevant malware-scanning and threat-detection capabilities for the storage environment.

B. Enable Azure SQL auditing on the storage account.

C. Assign the Storage Blob Data Reader role to every external partner.

D. Configure a ReadOnly resource lock on the storage account.

Correct answer: A

Explanation: Microsoft Defender for Storage provides security monitoring and threat detection for supported storage workloads. Its capabilities include identifying suspicious activities and, where configured and supported, scanning uploaded blobs for malware. SQL auditing applies to SQL services, while RBAC and resource locks do not provide malware detection.


Question 11 — Azure SQL auditing

A security operations team needs to investigate who accessed an Azure SQL Database, what database activities occurred, and when suspicious operations took place. The team wants to query the audit records centrally alongside other security events.

Which configuration best meets the requirement?

A. Enable Transparent Data Encryption (TDE) and use its encryption status as an audit trail.

B. Enable a database resource lock and review Azure Resource Health.

C. Configure Azure SQL auditing to send audit events to a suitable destination, such as Log Analytics, and query the collected records.

D. Enable SQL authentication for every user and rely on application logs alone.

Correct answer: C

Explanation: Azure SQL auditing records selected database events and can send audit data to supported destinations, including Log Analytics. Central collection enables investigation and correlation with other security information. TDE protects data at rest; it does not replace activity auditing.


Question 12 — Troubleshoot network security rules

A virtual machine cannot receive traffic from an approved application subnet. The network team believes an NSG rule allows the traffic, but the connection still fails. The team wants to determine which network security rules are effectively applied to the VM’s network interface.

Which tool should the team use first?

A. Microsoft Defender External Attack Surface Management.

B. Azure Network Watcher IP flow verify or effective security rules, selecting the appropriate feature to test the traffic or inspect the applied rules.

C. Azure Key Vault diagnostic settings.

D. Microsoft Purview Data Security Posture Management.

Correct answer: B

Explanation: Network Watcher provides diagnostic tools for Azure network connectivity. IP flow verify can determine whether a particular traffic flow is allowed or denied and identify the relevant rule. Effective security rules show the aggregate rules applied to a network interface. The choice depends on whether the team needs a specific flow decision or a complete view of applied rules.


Question 13 — Centralized outbound traffic inspection

An organization has several application subnets. It must centrally inspect outbound traffic and restrict access to specified fully qualified domain names (FQDNs), including when applications use changing destination IP addresses. The solution should reduce duplicated outbound filtering rules across subnets.

Which service is the most appropriate?

A. Azure Network Security Groups alone.

B. Azure Private Link.

C. Azure Bastion.

D. Azure Firewall with suitable application rules and a routing design that directs the relevant outbound traffic through the firewall.

Correct answer: D

Explanation: Azure Firewall supports centralized traffic filtering, including application rules based on FQDNs, when the relevant traffic is routed through it. NSGs filter traffic using network-layer attributes such as IP addresses, ports, and protocols; they do not provide equivalent centralized FQDN-based application filtering. Private Link and Bastion solve different problems.


Question 14 — Private endpoint DNS

An application connects to an Azure SQL logical server through a private endpoint. The private endpoint has been created successfully, and the application can reach other resources in its virtual network. However, the SQL hostname still resolves to a public IP address.

What should the engineer investigate first?

A. Whether the appropriate Private DNS zone is configured, linked to the virtual network, and contains the expected private endpoint DNS records.

B. Whether the application has the Azure Owner role.

C. Whether Microsoft Defender for Servers is enabled.

D. Whether the SQL database has Transparent Data Encryption enabled.

Correct answer: A

Explanation: Private endpoint connectivity typically relies on DNS resolution to map the service hostname to the private endpoint’s IP address. A correctly configured private DNS zone and virtual network link are common requirements. Database encryption and VM security settings do not fix an incorrect DNS resolution path.


Question 15 — Azure SQL vulnerability assessment

A security engineer must identify potential database misconfigurations and vulnerabilities, review findings against security baselines, and track recommendations for remediation. The organization also wants to detect suspicious database activities.

Which approach best addresses both needs?

A. Use TDE for vulnerability discovery and NSGs for SQL auditing.

B. Use Azure resource locks to identify database vulnerabilities and Azure Policy to record each query.

C. Use Microsoft Defender for Databases for supported database threat protection and vulnerability-assessment capabilities, configuring the relevant settings and reviewing findings.

D. Enable public access to the database so that the security scanner can reach it from anywhere.

Correct answer: C

Explanation: Microsoft Defender for Databases provides supported database security capabilities, including threat detection and vulnerability-assessment functionality, depending on the database type and configuration. Findings help identify weaknesses and prioritize remediation. TDE protects data at rest, while resource locks and NSGs are not substitutes for database security assessment.


Section 3 — Secure compute


Question 16 — Azure VM Trusted Launch

A company wants to strengthen the boot integrity of supported Azure virtual machines. Its requirements include protection against bootkits and verification of the boot chain, together with a virtualized hardware root of trust for supported security scenarios.

Which configuration is the best fit?

A. Enable Trusted Launch with Secure Boot and virtual TPM (vTPM), after verifying that the VM size, image, and operating system support it.

B. Enable Azure Bastion and disable the VM’s operating system updates.

C. Enable Azure Disk Encryption and assume that it prevents bootkits.

D. Assign the VM a managed identity and remove all network security groups.

Correct answer: A

Explanation: Trusted Launch adds security features such as Secure Boot and vTPM for supported Azure VMs. Secure Boot helps prevent unauthorized boot components from loading, while vTPM provides a protected virtualized hardware trust capability. Disk encryption protects data at rest but does not provide the same boot-integrity controls.


Question 17 — Secure workload identity in AKS

An application running in Azure Kubernetes Service (AKS) must access a specific Azure Key Vault. The security team wants to avoid storing long-lived service principal credentials in Kubernetes secrets and wants the workload to obtain Microsoft Entra tokens using a federated identity configuration.

Which approach should the team use?

A. Place a subscription Owner credential in a Kubernetes secret and mount it into the pod.

B. Enable anonymous access to Key Vault and filter requests in application code.

C. Configure Microsoft Entra Workload ID for AKS, use the appropriate federated identity credential and Kubernetes service account, and grant the workload identity only the necessary Key Vault permissions.

D. Give every node in the cluster the same permanent client secret.

Correct answer: C

Explanation: Microsoft Entra Workload ID for AKS uses workload identity federation so Kubernetes workloads can authenticate to Microsoft Entra ID without managing long-lived application secrets. The federated credential links the Kubernetes service account identity to the Entra application or managed identity. Least-privilege permissions should then be granted to the identity for the required Key Vault operations.


Question 18 — Just-in-time VM access

A security review finds that administrators can connect to Azure virtual machines over RDP from broad source IP ranges at all times. The company wants to reduce exposure by opening management ports only when an authorized administrator requests access, for a limited duration and from an approved source.

Which control most directly meets this requirement?

A. Assign the VM the Security Reader role.

B. Enable a ReadOnly resource lock.

C. Configure an NSG rule that permanently allows RDP from the corporate network.

D. Enable and configure just-in-time (JIT) VM access through Microsoft Defender for Cloud, setting approved ports, source IP restrictions, and permitted access duration.

Correct answer: D

Explanation: JIT VM access reduces the time that management ports are exposed. A request can temporarily open the required port according to configured rules and duration limits. A permanently allowed NSG rule does not provide the same time-bound access model. JIT requirements and supported VM configurations should be verified before deployment.


Question 19 — Web Application Firewall (WAF)

A company hosts a public web application behind a supported Azure application delivery service. The security team wants to inspect incoming HTTP(S) requests and detect or block common web attacks, such as SQL injection and cross-site scripting, using managed rule sets.

Which control should the team configure?

A. An NSG that allows only TCP port 443.

B. A Web Application Firewall policy with an appropriate managed rule set, initially validating detection and false positives before enforcing blocking as appropriate.

C. Azure Disk Encryption on the web server’s operating system disk.

D. A private endpoint for the public-facing website that allows every internet client to connect privately.

Correct answer: B

Explanation: A WAF evaluates HTTP(S) traffic and can detect or block common web application attacks using managed rules and custom rules. An NSG filters network traffic but does not inspect requests for application-layer attack patterns in the same way. A staged rollout helps reduce false positives while establishing effective protection.


Question 20 — Secure API backends with Azure API Management

An organization publishes an API through Azure API Management (APIM). Clients must present Microsoft Entra access tokens, and APIM must reject requests when the token’s issuer, audience, or signature is invalid. The backend should receive only requests that pass the gateway’s validation policy.

Which approach is most appropriate?

A. Configure APIM policy-based JWT validation, such as validate-jwt or the applicable Entra-aware validation policy, with the expected issuer, audience, and signing-key configuration.

B. Place the token in a URL query string and let the backend decide whether to inspect it.

C. Enable anonymous access at APIM and use a network security group to validate token claims.

D. Assign all API callers the API Management service’s Contributor role.

Correct answer: A

Explanation: APIM policies can validate JWTs before forwarding requests to the backend. Validation should enforce the expected issuer and audience and verify the token using trusted signing keys. Tokens should be sent in the authorization header rather than exposed in URLs. Azure RBAC roles for managing APIM resources do not authenticate API consumers.


Question 21 — Enforce VM security configuration

A company needs to assess and enforce supported operating-system security settings on Azure VMs and Arc-enabled servers, such as required configuration values. The team wants configuration compliance and remediation capabilities rather than only network-level filtering.

Complete the statement:

Azure __________ can be used to audit and enforce supported machine configuration settings on applicable Azure and Arc-enabled machines.

A. Private Link

B. Network Watcher

C. Machine Configuration

D. Application Gateway

Correct answer: C — Machine Configuration

Explanation: Azure Machine Configuration provides capabilities to audit and enforce supported configuration settings on applicable machines, including Azure VMs and Arc-enabled servers. It can help assess compliance against configuration requirements and remediate supported deviations. Network Watcher and Private Link serve networking purposes, while Application Gateway provides application delivery capabilities.


Question 22 — Container security in Azure

An organization runs containerized applications in AKS. The security team wants to identify container-related risks, monitor supported runtime threats, and receive security recommendations through Microsoft’s cloud security platform.

Which solution is the most appropriate starting point?

A. Use Azure SQL auditing for all container events.

B. Enable the applicable Microsoft Defender for Containers plan in Microsoft Defender for Cloud and configure the required components and data collection for the desired protections.

C. Use Azure Policy alone as a replacement for container threat detection.

D. Enable a resource lock on the AKS cluster and assume that the lock prevents malicious activity inside containers.

Correct answer: B

Explanation: Microsoft Defender for Containers provides supported security capabilities for container environments, including recommendations and threat detection features. The exact coverage depends on the environment and configuration, so required components and data collection should be verified. Azure Policy can enforce supported configurations, but it does not replace runtime threat detection.


Question 23 — AI workload protection

A team deploys an AI application using Microsoft Foundry. The application must reduce the risk of unsafe model outputs and prompt-based attacks, and the security team wants to apply configurable safeguards to model interactions. The team also wants centralized security visibility for the AI workload.

Which approach best meets the requirements?

A. Use an NSG as the only AI safety control and allow all model requests.

B. Store all prompts and API keys in source code so that developers can debug issues quickly.

C. Enable Azure Backup and rely on recovery points to prevent unsafe AI responses.

D. Configure appropriate Microsoft Foundry guardrails and content-safety controls, and use the relevant Microsoft Defender for Cloud AI workload protection capabilities for security visibility and threat detection.

Correct answer: D

Explanation: Foundry guardrails and content-safety controls help mitigate specified risks in model inputs and outputs, depending on the model, configuration, and supported features. Microsoft Defender for Cloud’s AI security capabilities provide additional workload protection and visibility. No single guardrail guarantees that all harmful or adversarial interactions will be prevented, so controls should be tested and layered.


Section 4 — Manage and monitor security posture


Question 24 — Defender for Cloud attack path analysis

Microsoft Defender for Cloud identifies a public-facing virtual machine with a vulnerability. The VM has a managed identity with access to a storage account containing sensitive data. The security team wants to understand whether the exposed VM could provide a path to the sensitive storage resource and prioritize remediation based on the potential impact.

Which capability is most appropriate?

A. Microsoft Sentinel’s data retention settings.

B. Azure SQL auditing.

C. Defender for Cloud’s attack path analysis and related cloud security posture management tools.

D. Azure Resource Manager deployment history alone.

Correct answer: C

Explanation: Defender for Cloud’s cloud security posture management capabilities can help identify attack paths that connect exposures, misconfigurations, identities, and sensitive resources. Attack path analysis supports prioritization based on potential risk and reachable assets. It complements, rather than replaces, vulnerability remediation and identity-permission reviews.


Question 25 — Ingest Common Event Format logs into Microsoft Sentinel

A company has a network security appliance that exports security events in Common Event Format (CEF). The SOC wants those events available in Microsoft Sentinel for analytics rules and incident investigation.

Which approach is most appropriate?

A. Configure the supported CEF ingestion architecture, including the required Linux-based log forwarder and Azure Monitor Agent setup, and enable the applicable Microsoft Sentinel data connector.

B. Install the Windows Event Forwarding collector on the network appliance and assume it can ingest CEF directly.

C. Enable Azure SQL auditing on the Sentinel workspace.

D. Create an Azure Policy assignment that converts CEF messages into Sentinel incidents.

Correct answer: A

Explanation: Microsoft Sentinel supports CEF ingestion using a supported log-forwarding architecture. The appropriate connector and agent configuration must be implemented so the appliance’s CEF events reach the workspace and can be queried. Windows Event Forwarding serves Windows event collection scenarios, while Azure Policy does not perform log ingestion or event conversion.


Question 26 — Collect Windows security events

An organization needs to collect Windows security events from servers into Microsoft Sentinel. The team wants to control which Windows events are collected and manage the collection configuration centrally through Azure Monitor.

Which approach is the best fit?

A. Use a private endpoint for each Windows event log.

B. Enable Microsoft Defender for Storage on every server.

C. Configure an Azure Firewall application rule to forward Windows events directly into Sentinel.

D. Configure the appropriate Azure Monitor Agent deployment and a Data Collection Rule (DCR) that specifies the Windows event channels or event selection required for collection.

Correct answer: D

Explanation: Azure Monitor Agent and Data Collection Rules are used to define and manage supported log collection. For Windows security events, the DCR specifies the event selection and destination configuration appropriate to the chosen collection method. Azure Firewall and Defender for Storage do not configure Windows event ingestion into Sentinel.


Question 27 — Automate incident handling in Microsoft Sentinel

Match each Microsoft Sentinel capability to its primary purpose.

CapabilityPrimary purpose
1. Analytics ruleA. Perform response actions through an automation workflow, such as notifying a team or invoking a supported remediation action
2. Automation ruleB. Detect suspicious patterns in collected data and generate alerts or incidents according to the rule configuration
3. PlaybookC. Apply incident-handling logic, such as assigning an incident, changing its status, or triggering a playbook based on configured conditions

Choose the correct mapping.

A. 1-C, 2-B, 3-A

B. 1-B, 2-C, 3-A

C. 1-A, 2-C, 3-B

D. 1-B, 2-A, 3-C

Correct answer: B

Explanation: Analytics rules identify suspicious activity and can generate alerts or incidents. Automation rules apply incident-management logic and can trigger playbooks. Playbooks are workflows, commonly built with Azure Logic Apps, that carry out response or integration actions. Together, these capabilities help automate detection and incident handling.


Question 28 — Discover external attack surface exposure

A company suspects that teams have deployed internet-facing assets outside the approved cloud inventory. The security team needs to discover externally visible assets associated with the organization, including assets that might not be registered in its current Azure resource inventory.

Which service is designed for this purpose?

A. Azure Network Watcher.

B. Microsoft Defender for Storage.

C. Microsoft Defender External Attack Surface Management (Defender EASM).

D. Microsoft Entra Privileged Identity Management.

Correct answer: C

Explanation: Microsoft Defender EASM helps discover and inventory an organization’s externally exposed digital assets and identify potential external exposure and vulnerabilities. It can help uncover assets that are not evident from the organization’s known cloud resource inventory. Network Watcher focuses on Azure network diagnostics, and PIM manages privileged access.


Question 29 — Microsoft Security Copilot access control

A security team is deploying Microsoft Security Copilot. Analysts should be able to use the capabilities and data sources appropriate to their assigned responsibilities, but they must not automatically receive administrative control over the workspace, all plugins, or all agents.

What is the best administrative approach?

A. Configure Security Copilot workspace access and roles using least privilege, and review the permissions and enablement of plugins and agents before making them available.

B. Give every analyst the same highest-privilege administrative role to simplify support.

C. Share a single administrator account among the analysts.

D. Disable all role-based access controls and rely on the analysts’ job titles.

Correct answer: A

Explanation: Security Copilot access should be governed through the applicable workspace roles, permissions, and controls for plugins and agents. Least privilege helps ensure that analysts can perform their assigned tasks without automatically receiving broad administrative capabilities. Shared accounts and blanket administrative access undermine accountability and increase risk.


Question 30 — Identify AI-related data exposure risks

A company is rolling out AI assistants that can search organizational content. The security team is concerned that sensitive information may be overexposed through existing permissions, shared content, or AI-enabled access paths. The team wants to identify and assess AI-related data security risks across supported data sources.

Which solution is most appropriate?

A. Use Azure Bastion to identify overshared documents.

B. Use Microsoft Purview Data Security Posture Management (DSPM) for AI to assess relevant AI-related data risks and help identify oversharing or sensitive-data exposure in supported environments.

C. Use an Azure SQL resource lock to prevent AI assistants from reading documents.

D. Use Microsoft Defender External Attack Surface Management to inspect all internal document permissions.

Correct answer: B

Explanation: Microsoft Purview DSPM for AI helps organizations assess data security risks associated with AI usage, including relevant sensitive-data exposure and oversharing risks in supported environments. Findings should guide remediation of permissions, data controls, and AI access paths. Bastion provides secure VM connectivity, while EASM focuses on external attack surface discovery.


Exam 3 — Final review

Use your results to identify the topics that need more practice before attempting Exam 4.

Skill domainQuestionsMain areas tested
Identity, access, and governance1–7PIM, Key Vault, agent identity, Conditional Access, Azure Policy, RBAC, OAuth consent, backup protection
Storage, databases, and networking8–15Private Link, SAS, Defender for Storage, SQL auditing, Network Watcher, Azure Firewall, private DNS, database protection
Secure compute16–23Trusted Launch, AKS workload identity, JIT access, WAF, API security, Machine Configuration, container security, AI guardrails
Security posture and monitoring24–30Attack path analysis, Sentinel ingestion, Windows event collection, automation, EASM, Security Copilot, Purview DSPM for AI

Suggested review strategy: For any question you missed, focus on the difference between controls that prevent access, controls that detect risk, and tools that investigate or remediate issues. Many certification questions test whether you can select the right control for a specific requirement rather than simply recognize a product name.


Go to the SC-500 Exam Prep Hub main page

SC-500 Practice Exam #4

This practice exam is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.

Implementing End-to-End Security Controls for Cloud and AI Workloads


Section 1 — Manage identity, access, and governance


Question 1 — PIM activation and emergency access

A company has two requirements for subscription-level administrators:

  • Routine administration must use just-in-time privileged access with approval.
  • Emergency access must remain possible if the normal approval process is unavailable.

Which design best balances these requirements?

A. Assign every administrator permanent Owner access and monitor activity with Azure Activity Logs.

B. Use eligible PIM assignments with configured activation controls, and maintain separately governed emergency-access accounts with carefully restricted, monitored credentials and procedures.

C. Replace all privileged assignments with Reader access and grant Owner access manually when needed.

D. Use Azure Policy to require approval before each Azure Resource Manager operation.

Correct answer: B

Explanation: PIM reduces standing privilege by making eligible roles activatable under defined conditions. Emergency-access arrangements should be designed separately so that an outage or unavailable approver does not prevent recovery. Those accounts require strict protection, monitoring, and periodic validation. Azure Policy does not provide per-operation approval for every management-plane action.


Question 2 — Key Vault network and authorization controls

An application hosted in a virtual network must retrieve a secret from Azure Key Vault. The company requires that:

  • The vault is not reachable through its public network endpoint.
  • Only the application identity can read the required secret.
  • Administrators can audit vault access.

Which design best satisfies all three requirements?

A. Enable public network access, allow all Azure services through the firewall, and give the application Contributor access.

B. Use a Key Vault resource lock and store the secret in the application’s configuration file.

C. Assign the Key Vault Administrator role to the application and disable diagnostic logging.

D. Configure a private endpoint and private DNS, disable public network access after validating connectivity, grant the application identity the required secret-read permission, and enable diagnostic logging to a suitable destination.

Correct answer: D

Explanation: These are separate control layers. Private Link and DNS provide private connectivity; disabling public network access removes the public access path. Key Vault data-plane permissions restrict which identity can read secrets, while diagnostic settings support audit and investigation. A resource lock does not provide these controls.


Question 3 — Infrastructure as code security

A development team deploys Azure infrastructure through Bicep templates and a CI/CD pipeline. Security requirements state that templates containing known security issues should be identified before deployment, and that noncompliant resource configurations must be blocked from production.

Which approach best meets these requirements?

A. Integrate supported infrastructure-as-code scanning into the development pipeline and enforce applicable Azure Policy controls during deployment.

B. Enable Microsoft Defender for Servers after all resources have been deployed.

C. Assign the deployment identity the Owner role and rely on developers to review templates manually.

D. Apply a CanNotDelete lock to the resource group before each deployment.

Correct answer: A

Explanation: Scanning templates in the development pipeline can identify security problems before resources are deployed. Azure Policy can enforce applicable resource requirements at deployment time, depending on the policy definition and effect. These controls complement each other: template scanning identifies issues early, while policy enforcement helps prevent noncompliant deployments.


Question 4 — OAuth application permissions

A background application needs to read files from a designated SharePoint site without a signed-in user. The application currently requests broad Microsoft Graph application permissions. The security team wants to minimize the data the application can access.

What should the team do?

A. Convert all application permissions to delegated permissions, even though no user will be signed in.

B. Assign the application Global Administrator so it can access only the intended site.

C. Review the required application permissions and implement a supported site-scoped authorization approach, such as appropriately configured selected-site permissions, granting access only to the required site.

D. Enable user consent for all application permissions and allow the application to choose its own access scope.

Correct answer: C

Explanation: Application permissions allow an application to act without a signed-in user and can be broad if not restricted. For supported SharePoint and Microsoft Graph scenarios, selected-site permissions can restrict an application’s access to designated sites, subject to the relevant permission model and setup. Granting tenant-wide administrative access would violate least privilege.


Question 5 — Microsoft Entra agent identity security

An organization uses autonomous AI agents that obtain Microsoft Entra tokens to access internal APIs. The security team wants to block high-risk agent identities and ensure that new agents in an approved category receive the same policy automatically.

Which TWO actions best support these requirements?

A. Configure an applicable Conditional Access policy to block agent identities identified as high risk.

B. Create an Azure resource lock on each API and use it as the agent access policy.

C. Use supported custom security attributes to categorize agent identities and target the appropriate Conditional Access policy so matching future identities are covered.

D. Create a policy targeting all human users and assume it automatically includes every agent identity and agent user account.

Correct answers: A and C

Explanation: Conditional Access can block risky agent identities where the relevant capabilities and licensing are available. Supported custom security attributes can help target policies by agent category, including matching future identities. Agent identities and agent user accounts are distinct identity types, so a policy targeting one should not be assumed to cover the other. Conditional Access also does not replace authorization checks on the target API.


Question 6 — Managed identity and Key Vault access

A Function App needs to retrieve a database password from Azure Key Vault. The organization prohibits storing credentials in application settings and source code. The Function App should have no permission to create or delete secrets.

Which configuration is most appropriate?

A. Create a service principal with a client secret and store the secret in an encrypted application setting.

B. Assign the Function App the Key Vault Administrator role and rotate the database password monthly.

C. Use the Function App’s system-assigned managed identity and assign it Owner at the subscription scope.

D. Enable a managed identity for the Function App and grant it only the required Key Vault secret-read permission through the supported authorization model.

Correct answer: D

Explanation: Managed identities allow supported Azure resources to authenticate to Microsoft Entra-protected services without managing application credentials. A narrowly scoped secret-read permission meets the stated need while avoiding unnecessary create and delete permissions. Subscription-level Owner and Key Vault Administrator are excessive for this scenario.


Question 7 — Regulatory compliance versus security enforcement

A company must evaluate its Azure environment against a regulatory compliance standard and identify which security controls are not satisfied. It also needs to prevent newly deployed storage accounts from violating a mandatory configuration requirement.

Which combination is most appropriate?

A. Use Azure Activity Logs to generate regulatory compliance assessments and resource locks to enforce all storage configuration rules.

B. Use Microsoft Defender for Cloud’s regulatory compliance capabilities to assess control status, and Azure Policy to enforce the applicable storage configuration requirement.

C. Use Microsoft Sentinel analytics rules to configure storage account properties and Defender EASM to block deployments.

D. Use Azure Backup reports to assess every regulatory control and PIM to enforce storage encryption.

Correct answer: B

Explanation: Defender for Cloud’s regulatory compliance dashboard helps assess security posture against supported standards and track control status. Azure Policy can audit, deny, or remediate supported resource configurations depending on the policy effect and resource provider support. Compliance assessment and configuration enforcement are related but distinct functions.


Section 2 — Secure storage, databases, and networking


Question 8 — Storage access for an external partner

A company must allow an external partner to upload files to one Azure Blob Storage container for the next two hours. The partner must not read existing blobs, list other containers, or access the storage account key.

Which approach best meets the requirement?

A. Assign the partner Storage Account Contributor at the subscription scope.

B. Enable anonymous read/write access on the storage account and disable it after two hours.

C. Issue a short-lived SAS restricted to the required container and create/write operations, with an appropriate validity period and secure distribution; use a user delegation SAS where supported and appropriate.

D. Give the partner the storage account key and request that it be deleted after the transfer.

Correct answer: C

Explanation: A narrowly scoped, short-lived SAS can grant only the required operations on the specified resource. A user delegation SAS uses Microsoft Entra credentials to obtain a user delegation key rather than relying on the storage account key. Because SAS tokens are bearer credentials, they must be protected and their validity and permissions kept as limited as practical.


Question 9 — Azure SQL private connectivity

An Azure SQL Database has a private endpoint. A workload in a connected on-premises network still resolves the SQL server hostname to a public IP address. The private endpoint itself reports as approved.

Which action is the best next step?

A. Verify the private DNS zone records and configure the appropriate DNS forwarding or resolution path so the on-premises workload resolves the SQL hostname to the private endpoint address.

B. Enable Transparent Data Encryption on the database.

C. Assign the on-premises server the SQL Server Contributor role.

D. Disable SQL auditing to prevent DNS conflicts.

Correct answer: A

Explanation: A private endpoint does not automatically ensure that every connected network resolves the service hostname to its private IP address. The DNS architecture must be configured for the client environment, including appropriate private DNS records and forwarding or resolver configuration. TDE and auditing do not resolve network names.


Question 10 — Azure Firewall versus NSGs

A company needs to enforce outbound access to approved internet FQDNs from multiple Azure subnets. It also needs centralized inspection and consistent policy management rather than separate FQDN rules on each subnet.

Which solution is most appropriate?

A. Configure a separate NSG on every subnet with rules for the domain names.

B. Use Azure Bastion and allow all outbound traffic from each VM.

C. Configure a private endpoint for every internet destination.

D. Route relevant outbound traffic through Azure Firewall and configure suitable application rules for the approved FQDNs, with a routing design that ensures traffic traverses the firewall.

Correct answer: D

Explanation: Azure Firewall provides centralized network traffic filtering, including FQDN-based application rules for supported protocols and configurations. Routing is essential: traffic that bypasses the firewall will not be inspected by it. NSGs primarily filter based on network attributes such as source and destination IP addresses, ports, and protocols.


Question 11 — Azure SQL security at rest and in use

Match each Azure SQL security control to its primary purpose.

ControlPrimary purpose
1. Transparent Data Encryption (TDE)A. Records selected database events for auditing and investigation
2. SQL auditingB. Helps identify potential database vulnerabilities and insecure configurations
3. Microsoft Defender for Databases vulnerability assessmentC. Encrypts supported database data at rest
4. Microsoft Entra authenticationD. Authenticates users or applications using Microsoft Entra identity

Choose the correct mapping.

A. 1-A, 2-C, 3-D, 4-B

B. 1-C, 2-A, 3-B, 4-D

C. 1-D, 2-B, 3-A, 4-C

D. 1-C, 2-D, 3-B, 4-A

Correct answer: B

Explanation: TDE protects database data at rest. SQL auditing records configured database events. Defender for Databases vulnerability assessment helps identify potential weaknesses and misconfigurations. Microsoft Entra authentication provides an identity-based authentication mechanism. These controls are complementary, not interchangeable.


Question 12 — Network security group troubleshooting

A virtual machine can connect to an application server, but connections to a database subnet fail. An NSG is associated with both a subnet and a network interface. The team needs to determine whether the intended source-to-destination flow is denied by an effective rule.

Which action should the engineer take first?

A. Enable Defender for Storage on the database subnet.

B. Create a ReadOnly lock on the virtual network.

C. Use Azure Network Watcher’s IP flow verify for the relevant source, destination, protocol, and port, then inspect effective security rules if further analysis is needed.

D. Enable SQL auditing and use it to identify the NSG rule that blocked the packet.

Correct answer: C

Explanation: IP flow verify tests a specified flow and reports whether it is allowed or denied and which security rule determines the result. Effective security rules provide a broader view of rules applied to the network interface. SQL auditing records database activity; it does not identify an NSG rule that prevented a connection.


Question 13 — Protect storage from suspicious file uploads

A storage account receives files from multiple external partners. The security team wants to detect suspicious storage activity and scan uploaded blobs for malware where supported. The team does not want to expose the files publicly.

Which approach is best?

A. Enable anonymous access so Defender can inspect every file.

B. Assign every partner the Storage Blob Data Owner role.

C. Configure an Azure resource lock and assume it will detect malicious files.

D. Configure Microsoft Defender for Storage’s applicable threat detection and malware-scanning capabilities, while separately enforcing appropriate storage authorization and network restrictions.

Correct answer: D

Explanation: Defender for Storage offers security monitoring and, where supported and configured, malware scanning for uploaded blobs. Storage authorization and network controls still determine who can access the data and from where. Malware scanning does not require making blobs public, and a resource lock does not detect malicious content.


Question 14 — Azure VPN Gateway and Microsoft Entra Private Access

A company has two different connectivity requirements:

  • Connect an on-premises network to an Azure virtual network using a site-to-site network tunnel.
  • Allow individual remote employees to access specific private enterprise applications without giving them broad network access.

Which mapping is most appropriate?

A. Use Azure VPN Gateway for the site-to-site connection, and Microsoft Entra Private Access for identity-aware access to supported private applications.

B. Use Azure Bastion for the site-to-site tunnel, and an NSG for user identity verification.

C. Use Azure Private Link for the site-to-site tunnel, and Azure Firewall for all employee authentication.

D. Use Microsoft Entra Private Access for the virtual network gateway, and Azure Policy to authenticate employees.

Correct answer: A

Explanation: Azure VPN Gateway provides VPN connectivity, including site-to-site connectivity between networks. Microsoft Entra Private Access supports identity-aware access to supported private resources and applications. Bastion is designed for secure VM management connectivity, while NSGs and Azure Policy do not replace identity-aware application access.


Question 15 — Key Vault secret detection and remediation

A security engineer discovers that a developer accidentally committed a production credential to a source repository. The company wants to identify exposed secrets across supported cloud resources and reduce the chance that discovered credentials can be abused.

Which response is most appropriate?

A. Apply a CanNotDelete lock to the repository’s resource group.

B. Use Defender CSPM’s supported secret-scanning capabilities to identify relevant exposures, then rotate or revoke the exposed credential and remediate its storage location.

C. Enable TDE on all SQL databases and consider the incident resolved.

D. Disable all Key Vault diagnostic logs to prevent the secret from appearing in monitoring systems.

Correct answer: B

Explanation: Supported secret-scanning capabilities in Defender CSPM can help identify exposed credentials in applicable environments. Detection is only the first step: a leaked credential should be treated as compromised, rotated or revoked, and removed from inappropriate locations. Resource locks and database encryption do not invalidate an exposed secret.


Section 3 — Secure compute


Question 16 — Protecting a virtual machine’s boot chain

A security baseline requires supported Azure VMs to verify boot components and provide a virtualized hardware root of trust. The baseline also requires the organization to validate whether a VM image and size support these features before rollout.

Which approach best meets the requirement?

A. Enable JIT VM access and treat it as a replacement for boot integrity.

B. Enable Azure Disk Encryption alone.

C. Deploy supported VMs with Trusted Launch, enable Secure Boot and vTPM as appropriate, and validate compatibility before deployment.

D. Assign the VM a managed identity and enable a resource lock.

Correct answer: C

Explanation: Trusted Launch provides supported VM security features such as Secure Boot and vTPM. Secure Boot helps prevent unauthorized boot components from loading, while vTPM supports virtualized hardware-root-of-trust scenarios. Disk encryption and JIT access protect different parts of the VM security posture.


Question 17 — Disk encryption and key management

A company must protect data stored on supported VM disks and maintain control over the keys used for the selected encryption design. The security team also requires access to keys to be restricted and audited.

What should the engineer do?

A. Select an appropriate supported VM disk-encryption design, configure the required key management through the supported service, and apply least-privilege access and monitoring to the keys.

B. Enable a network security group and assume that all disk data is encrypted.

C. Give all VM administrators unrestricted Key Vault access to simplify recovery.

D. Disable encryption and rely on storage-account firewall rules.

Correct answer: A

Explanation: Disk encryption protects data at rest, while the selected encryption method determines how keys are managed. Key access should be restricted to required identities and monitored. The exact configuration depends on the VM, operating system, disk type, and supported encryption method; an NSG is not a disk-encryption control.


Question 18 — Secure access to Azure VMs

A security policy prohibits public IP addresses on management VMs. Administrators must connect to Windows and Linux VMs over RDP or SSH through the Azure portal or supported client workflows without exposing those management ports directly to the internet.

Which solution is most appropriate?

A. Allow inbound RDP and SSH from all IP addresses but require strong passwords.

B. Assign all administrators permanent Contributor access to the subscription.

C. Enable public IP addresses on every VM and use Azure Policy to record connections.

D. Deploy Azure Bastion in the appropriate virtual network design and restrict direct inbound management access to the VMs.

Correct answer: D

Explanation: Azure Bastion provides secure RDP and SSH connectivity to supported VMs without requiring a public IP address on each target VM. Direct inbound management ports should be restricted so the Bastion path is the intended access route. Bastion does not replace identity governance or OS-level security.


Question 19 — Azure Machine Configuration

A security team wants to assess supported operating-system settings on Azure VMs and Arc-enabled servers against required configurations. It also wants to enforce supported settings and track compliance.

Complete the statement:

Azure __________ can audit and enforce supported machine configuration settings.

A. Network Watcher

B. Machine Configuration

C. Private Link

D. Azure Firewall Manager

Correct answer: B — Machine Configuration

Explanation: Azure Machine Configuration supports auditing and enforcement of supported machine settings on applicable Azure and Arc-enabled machines. It can help detect configuration drift and maintain compliance with defined requirements. The other services focus on network diagnostics, private connectivity, or firewall management.


Question 20 — AI Gateway governance

A company has several AI applications calling models in Microsoft Foundry. It wants to centralize governance of model traffic, apply supported access restrictions, and monitor usage for signs of misuse rather than implementing separate gateway controls in every application.

Which approach is most appropriate?

A. Place a resource lock on every model deployment.

B. Configure only Microsoft Purview retention policies and assume they enforce runtime model access.

C. Configure the applicable AI Gateway in Microsoft Foundry, apply its supported access controls and monitoring, and ensure the applications route model traffic through the governed gateway.

D. Allow direct model access from every application and rely exclusively on Azure Activity Logs.

Correct answer: C

Explanation: AI Gateway provides a centralized approach to governing and monitoring AI model traffic. Its supported access restrictions and monitoring help apply consistent controls. Applications that bypass the gateway will not receive gateway-level enforcement, so the architecture must direct relevant traffic through it.


Question 21 — Copilot Studio agent protection

An organization deploys Copilot Studio agents that can interact with users and organizational data. The security team wants supported real-time protection to identify potentially risky interactions and help prevent harmful or malicious content from being processed.

Which approach is most appropriate?

A. Disable all authentication for the agents so that the protection service can inspect every request.

B. Use an Azure resource lock on the agent environment and assume it blocks prompt injection.

C. Use SQL auditing as the primary control for agent conversations.

D. Configure the applicable Microsoft Defender protection for Copilot Studio agents and validate the supported real-time protection settings, alongside appropriate identity and data-access controls.

Correct answer: D

Explanation: The relevant Defender capabilities can provide supported real-time protection for Copilot Studio agents. The available protection depends on the environment, configuration, and supported features. Identity permissions and data controls remain important because content inspection alone cannot eliminate all agent risks.


Question 22 — Managed identity in Azure Functions

An Azure Function must retrieve a secret from Key Vault and write results to a specific blob container. The organization wants to avoid credentials in code and minimize the blast radius if the Function is compromised.

Which design is best?

A. Use one shared service principal with subscription-level Owner access for both services.

B. Use a managed identity for the Function and grant only the required Key Vault secret-read and container-scoped storage data permissions, where supported.

C. Store the storage account key and Key Vault secret in the same environment variable.

D. Make the container public and remove the Function’s identity.

Correct answer: B

Explanation: Managed identities avoid storing application credentials. Separate, narrowly scoped permissions for Key Vault and Blob Storage reduce the impact of compromise. The identity should receive only the required data-plane permissions, not broad subscription management rights.


Question 23 — AI guardrails and data security

A team is deploying a generative AI application. It must reduce unsafe model responses and limit the risk that the model exposes sensitive organizational data. The team also wants visibility into AI-related security risks.

Which TWO measures address distinct parts of this requirement?

A. Configure appropriate model guardrails and content-safety controls for supported input and output risks.

B. Give the model identity broad read access to every SharePoint site so it can answer more questions.

C. Use a resource lock as the sole control for prompt injection and data leakage.

D. Use Microsoft Purview DSPM for AI and applicable Defender for Cloud AI security capabilities to identify and assess relevant data exposure and AI workload risks.

Correct answers: A and D

Explanation: Guardrails and content-safety controls can help mitigate specified unsafe input and output patterns. Purview DSPM for AI and Defender for Cloud’s applicable AI security capabilities provide complementary visibility into data exposure and AI workload risks. Neither makes broad data permissions safe, and no single safeguard guarantees prevention of all prompt-injection or data-leakage scenarios.


Section 4 — Manage and monitor security posture


Question 24 — Microsoft Sentinel data collection architecture

Match each collection method to the most appropriate description.

Collection methodDescription
1. Windows event collection with Azure Monitor AgentA. Ingest supported appliance logs formatted in a common security-event format using the supported forwarding architecture
2. CEF ingestionB. Collect selected Windows event channels or events using configured data collection
3. Syslog ingestionC. Collect supported syslog messages from configured Linux-based log sources or forwarders

Choose the correct mapping.

A. 1-A, 2-C, 3-B

B. 1-C, 2-B, 3-A

C. 1-B, 2-A, 3-C

D. 1-B, 2-C, 3-A

Correct answer: C

Explanation: Azure Monitor Agent and Data Collection Rules support Windows event collection and other supported collection scenarios. CEF and syslog ingestion use supported forwarding architectures, often involving a Linux-based log forwarder and the relevant Sentinel connector configuration. The data source’s format and collection requirements determine the correct setup.


Question 25 — Microsoft Defender for Cloud multicloud posture

An organization uses Azure and another cloud provider. Its security team wants a consolidated view of security posture, applicable recommendations, and supported workload protection across environments.

Which approach is most appropriate?

A. Connect the supported multicloud environment to Microsoft Defender for Cloud using the appropriate cloud connector and configuration, then enable the relevant posture and workload-protection capabilities.

B. Install Azure Bastion in the other cloud and assume it imports all security findings.

C. Create a single Azure Policy assignment and assume it governs resources in every cloud provider without a connector or supported integration.

D. Export only Azure Activity Logs and treat them as a complete view of all cloud posture risks.

Correct answer: A

Explanation: Defender for Cloud supports multicloud security posture and workload protection through supported connectors and configuration. Coverage depends on the cloud provider, plan, and enabled capabilities. Azure Policy alone does not automatically govern all resources in another cloud provider, and activity logs do not provide a complete security posture assessment.


Question 26 — Microsoft Defender Vulnerability Management

A security team needs to identify vulnerable software on supported Azure VMs, prioritize findings, and track remediation. The team does not simply need to confirm that the VMs are reachable or that network rules are configured.

Which solution is the best fit?

A. Azure Network Watcher.

B. Azure Resource Health.

C. Azure Private DNS.

D. Configure the applicable Microsoft Defender for Servers and Defender Vulnerability Management capabilities, then review supported vulnerability findings and remediation recommendations.

Correct answer: D

Explanation: Defender for Servers and the applicable vulnerability-management capabilities help identify software vulnerabilities and prioritize remediation on supported machines. Network Watcher diagnoses network behavior, Resource Health reports service and resource availability, and Private DNS provides name resolution.


Question 27 — Sentinel automation and playbooks

A SOC wants to automatically assign newly generated incidents to the correct team based on incident properties. For incidents matching a high-priority condition, it also wants to invoke a workflow that notifies responders and performs supported response actions.

Which configuration is most appropriate?

A. Use an Azure Policy assignment to assign Sentinel incidents and configure a resource lock to execute the workflow.

B. Configure a Sentinel automation rule for the incident-handling logic and use a playbook for the required workflow actions.

C. Use a Data Collection Rule to assign incidents and an NSG to send notifications.

D. Use Defender EASM to classify every Sentinel incident and directly run Azure Backup.

Correct answer: B

Explanation: Sentinel automation rules can apply incident-management logic, such as assignment and status changes, based on configured conditions. Playbooks, commonly implemented using Azure Logic Apps, execute workflows such as notifications or supported response actions. The automation rule and playbook complement each other.


Question 28 — Attack path versus individual recommendation

Defender for Cloud reports several findings:

  • A virtual machine is publicly accessible.
  • The VM has a vulnerable software package.
  • Its managed identity can access a sensitive storage resource.

The security team needs to understand how these conditions might combine into a path to a sensitive resource, rather than treating every finding independently.

Which capability should the team use?

A. Microsoft Sentinel workspace retention settings.

B. Azure Resource Health.

C. Defender for Cloud attack path analysis and related cloud security posture management tools.

D. Azure Key Vault certificate renewal.

Correct answer: C

Explanation: Attack path analysis helps connect exposures, vulnerabilities, identity permissions, and reachable resources to reveal potentially significant risk chains. It helps prioritize remediation based on the relationships between findings. Individual recommendations remain useful, but they may not show the combined path to a sensitive asset.


Question 29 — Security Copilot plugins and workspace permissions

A company allows security analysts to use Microsoft Security Copilot to investigate incidents. Some plugins can access sensitive security data or perform actions in connected services. The security team wants to ensure analysts receive only the capabilities required for their responsibilities.

Which approach is best?

A. Give every analyst unrestricted access to all plugins and agents so that investigations are never delayed.

B. Share one Global Administrator account for all Security Copilot investigations.

C. Disable audit logging and use the analysts’ team membership as the only security control.

D. Configure workspace roles and access according to least privilege, and review plugin and agent permissions and enablement before making capabilities available.

Correct answer: D

Explanation: Security Copilot governance requires appropriate workspace access controls and review of connected plugins and agents. The permissions available to a plugin or agent affect what it can access or do, so these capabilities should be enabled and assigned deliberately. Shared privileged accounts and unrestricted access weaken accountability and increase risk.


Question 30 — Data retention and audit investigation

An organization uses Microsoft Sentinel and Log Analytics to investigate security incidents. A policy requires selected security logs to be retained for an extended period, while keeping the cost of frequently queried data under control. Investigators must still be able to retrieve retained records when necessary.

Which approach is most appropriate?

A. Delete all records after seven days and rely on incident summaries.

B. Configure appropriate table-level retention and, where suitable and supported, long-term retention or archive settings for the relevant data, validating the retrieval and query limitations.

C. Apply a ReadOnly lock to the Log Analytics workspace and assume the lock enforces retention.

D. Turn off data collection after an incident so that the existing records remain available indefinitely.

Correct answer: B

Explanation: Retention should be configured according to the applicable policy, data table, and supported Log Analytics retention options. Long-term retention or archive options can help reduce the cost of keeping data that is accessed less frequently, but retrieval and query behavior may differ from interactive analytics. Resource locks do not define log retention, and stopping collection does not guarantee indefinite retention.


Final preparation advice:

Across all four exams and exam topics, prioritize understanding why a control is appropriate and what it does not do. For example, encryption does not replace authorization, a security recommendation does not necessarily enforce a configuration, and a detection tool does not automatically remediate the underlying issue.


Go to the SC-500 Exam Prep Hub main page

SC-500 Practice Exam #1

This practice exam is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.

Implementing End-to-End Security Controls for Cloud and AI Workloads


Question 1 — Single Answer

Skill area: Manage identity, access, and governance

A company wants administrators to have access to privileged Azure roles only when they actually need them. Administrators should activate their privileges for a limited period and provide an appropriate justification.

Which Microsoft Entra capability should you implement?

A. Privileged Identity Management (PIM)
B. Microsoft Entra Password Protection
C. Microsoft Entra Domain Services
D. Application Proxy

Answer: A. Privileged Identity Management (PIM)

Explanation:
Microsoft Entra Privileged Identity Management (PIM) is designed to manage, control, and monitor access to important resources. It supports just-in-time access, activation requirements, time-limited privileged access, and auditing of privileged role usage.

The other options address different identity scenarios. Password Protection helps prevent weak passwords, Domain Services provides managed domain services, and Application Proxy provides access to on-premises applications.

PIM is specifically identified in the SC-500 study guide as a required capability.


Question 2 — Multiple Answer

Skill area: Manage identity, access, and governance

You are securing access to an Azure Key Vault.

Which two actions can help restrict access to the Key Vault?

A. Configure Key Vault networking/firewall settings
B. Assign appropriate permissions to users, groups, or managed identities
C. Enable Azure Bastion
D. Create a Microsoft Sentinel playbook

Answer: A and B

Explanation:
Key Vault security uses multiple layers.

  • A is correct: Key Vault firewall and networking controls can restrict which networks can reach the vault.
  • B is correct: Access to keys, secrets, and certificates must be controlled through appropriate authorization.
  • C is incorrect: Azure Bastion provides secure administrative access to VMs; it does not control Key Vault authorization.
  • D is incorrect: A Sentinel playbook can automate security operations but isn’t a Key Vault access-control mechanism.

The SC-500 study guide specifically includes deploying Key Vault, configuring access, firewall settings, and managing keys, secrets, and certificates.


Question 3 — Scenario — Single Answer

Skill area: Manage identity, access, and governance

A development team deploys Azure resources through infrastructure-as-code pipelines. Security requires that all storage accounts must use secure transfer and that resources must comply with organizational security requirements.

You want Azure to evaluate resources against these requirements and prevent noncompliant deployments where appropriate.

Which service should you use?

A. Microsoft Sentinel
B. Azure Policy
C. Azure Bastion
D. Microsoft Defender External Attack Surface Management

Answer: B. Azure Policy

Explanation:
Azure Policy allows organizations to define and enforce organizational standards for Azure resources. Policies can audit resources, deny noncompliant configurations, and support remediation.

This makes Azure Policy appropriate for enforcing governance requirements during infrastructure deployment.

Microsoft specifically includes Azure Policy and resource locks in the SC-500 governance objectives.


Question 4 — Fill in the Blank

Skill area: Manage identity, access, and governance

A developer needs an Azure application to access an Azure resource without storing a password, client secret, or certificate in application code.

The recommended identity capability is an Azure __________ identity.

A. guest
B. managed
C. external
D. federated

Answer: B. managed

Explanation:
Azure managed identities allow Azure resources to authenticate to supported services without developers having to manage credentials such as passwords or client secrets.

The SC-500 study guide specifically identifies implementation and configuration of managed identities for Azure resources as an exam objective.


Question 5 — Matching

Skill area: Manage identity, access, and governance

Match each security capability with its primary purpose.

CapabilityPurpose
1. PIMA. Authenticate applications without storing credentials
2. Managed identityB. Manage temporary privileged access
3. Conditional AccessC. Apply access decisions based on conditions
4. Azure PolicyD. Enforce organizational resource configuration standards

Answer

  • 1 → B
  • 2 → A
  • 3 → C
  • 4 → D

Explanation:

  • PIM controls privileged access and supports just-in-time activation.
  • Managed identities provide Azure resources with identities that can authenticate without application-managed secrets.
  • Conditional Access evaluates conditions such as user, device, location, risk, and application before granting access.
  • Azure Policy governs resource configurations and compliance.

These capabilities belong to different security layers, so understanding their boundaries is important for SC-500 scenario questions.


Question 6 — Scenario — Single Answer

Skill area: Manage identity, access, and governance

A company has a production Key Vault containing encryption keys and application secrets. Security wants applications to access the vault, but the vault should not be broadly reachable from the public internet.

Which control most directly addresses the network exposure requirement?

A. Azure Policy
B. Microsoft Entra PIM
C. Key Vault firewall/networking configuration
D. Microsoft Sentinel automation rules

Answer: C. Key Vault firewall/networking configuration

Explanation:
Authorization controls determine who can access Key Vault. Network controls determine where requests can originate from.

The requirement in this scenario specifically concerns network exposure, so Key Vault’s networking and firewall configuration is the appropriate control.


Secure Storage, Databases, and Networking

Question 7 — Single Answer

Skill area: Secure storage, databases, and networking

An organization wants to prevent anonymous access to data stored in Azure Blob Storage.

Which control should be reviewed first?

A. Azure Bastion
B. Storage account access configuration
C. Microsoft Sentinel automation rules
D. Azure Firewall Premium

Answer: B. Storage account access configuration

Explanation:
Azure Storage security includes configuring storage-account access settings and authorization mechanisms.

The SC-500 storage objectives include implementing security and managing access for Azure Storage.

Azure Firewall and Bastion solve different networking and administrative-access problems.


Question 8 — Multiple Answer

Skill area: Secure storage, databases, and networking

A security engineer wants to reduce public network exposure for an Azure PaaS service.

Which two technologies can be used to provide private connectivity?

A. Azure Bastion
B. Azure Private Link
C. Private endpoints
D. Microsoft Entra PIM

Answer: B and C

Explanation:
Azure Private Link provides private connectivity to Azure PaaS services through private endpoints.

A private endpoint provides a private IP address in a virtual network that maps to the supported service.

Bastion is intended for secure RDP/SSH access to VMs, while PIM manages privileged identity access.

The SC-500 networking objectives explicitly include eliminating public network exposure of Azure PaaS services using Private Link.


Question 9 — Scenario — Single Answer

Skill area: Secure storage, databases, and networking

An organization has several Azure VNets containing application, database, and management workloads. The security team wants to isolate traffic between workload tiers and control which network flows are allowed.

Which capability should form part of the network segmentation design?

A. Microsoft Purview Audit
B. Azure Key Vault certificates
C. Network security groups (NSGs)
D. Microsoft Defender Vulnerability Management

Answer: C. Network security groups (NSGs)

Explanation:
NSGs provide network traffic filtering for Azure resources and subnets. They can be used as part of a segmentation strategy to control allowed inbound and outbound traffic.

The SC-500 networking objectives include segmenting and isolating Azure workloads using network security controls.


Question 10 — Multiple Answer

Skill area: Secure storage, databases, and networking

Which two capabilities are directly associated with securing Azure SQL databases?

A. Auditing
B. Microsoft Defender External Attack Surface Management
C. Azure Bastion
D. Microsoft Defender for Databases

Answer: A and D

Explanation:
Azure SQL security includes auditing capabilities and Microsoft Defender for Databases.

Auditing provides records of database activity for security and compliance analysis. Defender for Databases provides additional security monitoring and threat protection capabilities.

The SC-500 study guide explicitly includes platform-level Azure SQL security, auditing for Azure SQL Database and SQL Managed Instance, and Defender for Databases.


Question 11 — Scenario — Single Answer

A company needs centralized inspection and enforcement of network traffic across several Azure networks.

Which Azure service is specifically designed to provide centralized network traffic inspection and filtering?

A. Azure Storage
B. Azure Key Vault
C. Azure Firewall
D. Microsoft Entra ID

Answer: C. Azure Firewall

Explanation:
Azure Firewall is a managed, centralized network security service that can inspect and control network traffic.

This is different from an NSG, which provides network traffic filtering at the subnet or network-interface level.

The SC-500 networking learning path specifically covers centralizing and enforcing traffic inspection using Azure Firewall.


Question 12 — Matching

Skill area: Secure storage, databases, and networking

Match each technology with the scenario it most directly addresses.

TechnologyScenario
1. Azure FirewallA. Private connectivity to a PaaS resource
2. Private LinkB. Centralized network traffic inspection
3. VPN GatewayC. Encrypted connectivity between networks
4. Azure BastionD. Browser-based secure administration of Azure VMs

Answer

  • 1 → B
  • 2 → A
  • 3 → C
  • 4 → D

Explanation:
These services are frequently confused because they all participate in Azure security architectures.

  • Azure Firewall → centralized network traffic inspection
  • Private Link → private access to supported Azure services
  • VPN Gateway → encrypted VPN connectivity
  • Azure Bastion → secure RDP/SSH connectivity to VMs without exposing those VMs directly to the public internet

Question 13 — Scenario — Multiple Answer

A company stores sensitive business files in Azure Storage. Security wants to strengthen protection against malware and suspicious activity involving the storage environment.

Which two actions are appropriate?

A. Enable Microsoft Defender for Storage
B. Configure appropriate storage access controls
C. Deploy Azure Bastion into the storage account
D. Replace the storage account with Azure SQL Database

Answer: A and B

Explanation:
Security should be layered.

  • Microsoft Defender for Storage provides additional security monitoring and threat protection for Azure Storage.
  • Storage access controls limit who and what can access the data.

Bastion isn’t a storage-security mechanism, and moving the workload to SQL Database is not inherently a security control.


Question 14 — Fill in the Blank

Skill area: Secure storage, databases, and networking

To eliminate public network exposure for a supported Azure PaaS resource while allowing access from a virtual network, configure an Azure __________ endpoint.

A. service
B. public
C. private
D. management

Answer: C. private

Explanation:
A private endpoint provides a private IP address in an Azure virtual network for supported Azure services. This enables private connectivity rather than requiring clients to access the service through its public endpoint.

Private Link and private endpoints are specifically included in the SC-500 networking objectives.


Secure Compute

Question 15 — Scenario — Single Answer

Skill area: Secure compute

A company runs Azure VMs containing sensitive workloads. Security wants protection against boot-level attacks and wants the VM to use a virtual Trusted Platform Module.

Which capability should you configure?

A. Microsoft Sentinel
B. Azure Policy only
C. Azure Bastion
D. Trusted Launch

Answer: D. Trusted Launch

Explanation:
Azure Trusted Launch provides enhanced VM security features including Secure Boot and vTPM, along with integrity monitoring capabilities.

The SC-500 study guide specifically identifies secure boot, vTPM, integrity monitoring, and VM security type as VM security objectives.


Question 16 — Multiple Answer

Skill area: Secure compute

Which two capabilities are associated with securing Azure virtual machines?

A. Just-in-time VM access
B. Disk encryption
C. Microsoft Purview DSPM
D. Azure Storage lifecycle management

Answer: A and B

Explanation:
Both capabilities directly protect Azure VMs:

  • JIT VM access restricts management-port exposure and provides access only when required.
  • Disk encryption protects data stored on VM disks.

The SC-500 VM objectives specifically include disk encryption and JIT VM access.


Question 17 — Scenario — Single Answer

A security administrator wants to allow administrators to connect to Azure VMs through RDP and SSH without assigning public IP addresses directly to the VMs.

Which service should be implemented?

A. Azure Firewall
B. Azure Bastion
C. Azure Private Link
D. Microsoft Sentinel

Answer: B. Azure Bastion

Explanation:
Azure Bastion provides secure RDP and SSH connectivity to Azure VMs over the Azure portal without requiring public IP addresses on the VMs.

Bastion is specifically included in the SC-500 secure-compute objectives.


Question 18 — Scenario — Multiple Answer

A company operates AI workloads and wants to identify security risks associated with AI identities and AI data.

Which two capabilities are relevant?

A. Azure Bastion
B. Azure Storage lifecycle policies
C. Microsoft Purview Data Security Posture Management (DSPM)
D. Microsoft Defender XDR analysis of Entra Agent ID risks

Answer: C and D

Explanation:
The SC-500 AI-security objectives include:

  • identifying AI data risks using Microsoft Purview DSPM
  • analyzing security risks and blast radius associated with Microsoft Entra Agent ID using Microsoft Defender XDR

These address different layers of AI security: data risk and identity-related risk.


Question 19 — Scenario — Single Answer

A company deploys generative AI applications using Microsoft Foundry. Security wants a centralized gateway through which AI model traffic can be inspected and controlled.

Which capability should be configured?

A. Azure Bastion
B. Microsoft Defender for Storage
C. AI Gateway in Azure API Management
D. Azure VPN Gateway

Answer: C. AI Gateway in Azure API Management

Explanation:
The SC-500 AI security objectives include configuring and deploying AI Gateway in Azure API Management for Microsoft Foundry.

The AI Gateway is intended to provide governance and security controls around AI traffic and interactions.


Question 20 — Matching

Skill area: Secure compute

Match the security control to its primary purpose.

ControlPurpose
1. Trusted LaunchA. Secure administrative access to VMs
2. Azure BastionB. Protect VM disks
3. JIT VM accessC. Protect VM boot process and establish hardware-backed trust
4. Disk encryptionD. Limit management-port exposure

Answer

  • 1 → C
  • 2 → A
  • 3 → D
  • 4 → B

Explanation:
Understanding these distinctions is important because SC-500 scenario questions may provide several controls that appear applicable.

Trusted Launch protects the VM boot chain and provides security capabilities such as Secure Boot and vTPM. Bastion provides administrative connectivity. JIT controls management-port exposure. Disk encryption protects data stored on disks.


Question 21 — Scenario — Single Answer

An organization runs containers in Azure Kubernetes Service. The security team wants to identify container vulnerabilities, misconfigurations, and runtime security risks.

Which service should be used?

A. Microsoft Defender for Containers
B. Azure Key Vault
C. Microsoft Defender EASM
D. Microsoft Purview Audit

Answer: A. Microsoft Defender for Containers

Explanation:
Microsoft Defender for Containers provides security capabilities for containerized workloads, including Kubernetes environments.

The SC-500 application-platform objectives specifically include detecting container risks using Defender for Containers and implementing security controls for AKS.


Manage and Monitor Security Posture

Question 22 — Single Answer

Skill area: Manage and monitor security posture

A security team wants to identify and prioritize security risks across Azure resources using posture information, recommendations, attack paths, and risk-based analysis.

Which Defender for Cloud capability should they primarily use?

A. Cloud Security Posture Management (CSPM)
B. Microsoft Sentinel playbooks
C. Azure Bastion
D. Microsoft Purview Audit

Answer: A. Cloud Security Posture Management (CSPM)

Explanation:
Defender CSPM provides posture visibility and capabilities for identifying and prioritizing cloud security risks. Current Microsoft training describes capabilities including Secure Score, attack-path analysis, and Cloud Security Explorer.


Question 23 — Scenario — Single Answer

A company has Azure, AWS, and GCP resources. The security team wants centralized security visibility across these environments through Microsoft Defender for Cloud.

What should the security team configure?

A. Microsoft Sentinel CEF collection only
B. Defender for Cloud multicloud connectors
C. Azure Private Link for every workload
D. Azure Bastion for every server

Answer: B. Defender for Cloud multicloud connectors

Explanation:
Microsoft Defender for Cloud supports connecting hybrid and multicloud environments, including AWS and GCP, to provide unified security visibility.

Microsoft’s current training specifically covers native AWS and GCP connectors and Azure Arc for hybrid servers.


Question 24 — Multiple Answer

Which two capabilities are associated with Microsoft Defender for Cloud’s Cloud Security Posture Management functionality?

A. Attack path analysis
B. Cloud Security Explorer
C. RDP access through Azure Bastion
D. Azure Storage lifecycle management

Answer: A and B

Explanation:
Current Microsoft Defender for Cloud CSPM training includes:

  • risk-prioritized security recommendations
  • attack-path analysis
  • Cloud Security Explorer
  • Secure Score-related posture capabilities

These help security teams identify and investigate cloud security risks.


Question 25 — Scenario — Single Answer

A security team wants to discover unknown internet-facing assets belonging to its organization, including assets that may not have been previously inventoried.

Which Microsoft security capability should they use?

A. Azure Machine Configuration
B. Microsoft Defender for Storage
C. Microsoft Entra PIM
D. Microsoft Defender External Attack Surface Management (EASM)

Answer: D. Microsoft Defender External Attack Surface Management (EASM)

Explanation:
Microsoft Defender EASM provides outside-in discovery of an organization’s external attack surface. Microsoft describes its recursive discovery capabilities as a way to find unknown internet-facing assets and surface vulnerabilities and security hygiene risks.


Question 26 — Scenario — Multiple Answer

A security operations team is implementing Microsoft Sentinel.

Which two activities are explicitly part of the SC-500 Sentinel objectives?

A. Configure syslog and CEF event collection
B. Configure Azure Bastion
C. Implement automation rules and playbooks
D. Configure Key Vault certificates

Answer: A and C

Explanation:
The SC-500 study guide specifically includes:

  • implementing and configuring syslog and CEF event collection
  • implementing automation rules and playbooks

Other Sentinel objectives include workspaces, Microsoft data connectors, Windows Security events using DCRs/WEF, custom log tables, retention, and querying Microsoft Purview Audit in Defender XDR.


Question 27 — Scenario — Single Answer

A Windows server sends security events to Microsoft Sentinel through Windows Event Forwarding (WEF). The organization wants to define which events are collected using centralized configuration.

Which Azure capability should be used?

A. Azure Firewall policy
B. Azure Machine Configuration
C. Data Collection Rules (DCRs)
D. Azure Policy initiatives

Answer: C. Data Collection Rules (DCRs)

Explanation:
Microsoft Sentinel supports collecting Windows Security events using Data Collection Rules, including scenarios involving Windows Event Forwarding.

The SC-500 study guide explicitly identifies collection of Windows Security events using DCRs, including WEF, as an exam objective.


Question 28 — Scenario — Multiple Answer

An organization is configuring Microsoft Security Copilot.

Which two areas are specifically included in the SC-500 Security Copilot objectives?

A. Configure Security Copilot workspaces
B. Manage permissions and roles in Security Copilot
C. Configure Azure Storage lifecycle management
D. Configure VM disk encryption

Answer: A and B

Explanation:
The SC-500 study guide identifies the following Security Copilot objectives:

  • configure workspaces
  • manage permissions and roles
  • enable and configure plugins
  • enable and configure Microsoft agents and Security Store agents

The Microsoft Security Copilot learning path also covers workspace segmentation, SCU capacity, workspace roles, plugins, and the lifecycle of Microsoft-built and partner-built agents.


Question 29 — Scenario — Single Answer

A security administrator wants to acquire a partner-built security agent for Microsoft Security Copilot. The organization has identified the agent in the Security Store and wants to complete the acquisition process.

Where are the partner agent’s purchase or subscription activities handled?

A. Only in Microsoft Sentinel
B. Only in Azure Policy
C. Microsoft Security Store
D. Only in Microsoft Entra ID

Answer: C. Microsoft Security Store

Explanation:
Microsoft Security Store is the security-focused storefront for discovering, acquiring, and deploying Microsoft and partner-built security solutions and agents.

For Security Copilot, Microsoft distinguishes between acquiring/subscribing to partner agents through Security Store and configuring/operating the agent through Security Copilot. Microsoft also notes that Security Copilot SCU consumption is separate from any partner-agent subscription fees.


Question 30 — Scenario — Multiple Answer

A company wants to improve its overall security posture for AI workloads in Defender for Cloud.

Which three capabilities are relevant to this goal?

A. Enable the AI workloads protection plan
B. Review insights in the Data & AI security dashboard
C. Assess AI posture using Cloud Security Posture Management
D. Use Azure Bastion to provide RDP access to the AI model

Answer: A, B, and C

Explanation:
Microsoft Defender for Cloud provides multiple layers of AI security. Current Microsoft training describes:

  • enabling the AI workloads plan
  • reviewing the Data & AI security dashboard
  • assessing AI security posture through CSPM
  • detecting runtime threats through Cloud Workload Protection
  • investigating incidents through Microsoft Defender XDR

Azure Bastion is unrelated to AI workload posture management and is primarily a secure administrative-access service for Azure VMs.


Key exam concepts reinforced in Practice Exam 1

A useful way to mentally organize the material is:

Identity → Data → Network → Compute → AI → Posture → Detection/Response

  • Identity: Entra ID, PIM, Conditional Access, managed identities
  • Secrets: Key Vault
  • Governance: Azure Policy, RBAC, resource locks
  • Data: Storage and Azure SQL security
  • Network: NSGs, Firewall, VPN, Private Link
  • Compute: VMs, Trusted Launch, disk encryption, Bastion, JIT
  • Application platform: AKS, containers, App Services, Functions, Logic Apps, API Management
  • AI: Agent ID, AI Gateway, Foundry guardrails, Purview DSPM, Defender for AI
  • Posture: Defender CSPM, Secure Score, attack paths, EASM
  • Security operations: Sentinel, DCRs, WEF, CEF, syslog, automation
  • Security Copilot: workspaces, roles, plugins, Microsoft agents, Security Store agents

Microsoft’s current training describes Defender for Cloud as providing posture management, attack-path analysis, Cloud Security Explorer, external attack-surface discovery, compliance assessment, workload protection, and vulnerability-management capabilities, making these particularly important concepts to distinguish from one another on scenario questions.


Go to the SC-500 Exam Prep Hub main page