Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmaspas7

Easiest Solution 2 Pass Your Certification Exams

SC-500 Microsoft Certified: Cloud and AI Security Engineer Associate Free Practice Exam Questions (2026 Updated)

Prepare effectively for your Microsoft SC-500 Microsoft Certified: Cloud and AI Security Engineer Associate certification with our extensive collection of free, high-quality practice questions. Each question is designed to mirror the actual exam format and objectives, complete with comprehensive answers and detailed explanations. Our materials are regularly updated for 2026, ensuring you have the most current resources to build confidence and succeed on your first attempt.

Page: 1 / 1
Total 68 questions

You have an Azure subscription that contains a resource group named RG1.

RG1 contains a Microsoft Security Copilot deployment that is integrated with a Microsoft Sentinel workspace named Workspace1.

Analysts use the Security Copilot standalone experience to retrieve incidents by using the Microsoft Sentinel plugin.

A user named User1 can sign in to Security Copilot but cannot retrieve incidents from Workspace1. You verify that User1 lias only the Security Copilot Contributor role.

You need to ensure that User1 can retrieve the incidents. The solution must follow the principle of least privilege and NOT require any configuration changes to Security Copilot.

Which role should you assign to User1?

A.

The Security Reader role in Microsoft Entra

B.

The Microsoft Sentinel Reader role for Workspace1

C.

The Security Copilot Owner role

D.

The Security Administrator role in Microsoft Entra

E.

The Contributor role in Azure for RG1

You have an Azure SQL Database logical server named Server1 that contains a database named DB1.

You need to configure authentication for Server1 to meet the following requirements;

•SQL authentication cannot be used for any databases on Server1.

•The solution must be enforced centrally at the server level.

What should you do?

A.

Configure a Microsoft Entra administrator for Server1.

B.

Enable a managed identity for Server1.

C.

Enable Microsoft Entra-only authentication for Server1.

D.

Remove SQL logins from DB1.

You have a Microsoft Entra tenant that has the following configurations:

•User consent for applications is disabled.

•Only administrators can grant permissions to applications.

You register an application named App1 that uses delegated Microsoft Graph permissions.

You need to configure App1 to meet the following requirements:

•Enable user sign-ins without interactive consent prompts.

•Enable App1 to access Microsoft Graph on behalf of the signed-in user.

What should you do?

A.

Configure enterprise applications to require user assignment and assign users to App1.

B.

Modify the app registration to use application permissions instead of delegated permissions.

C.

Add the required delegated Microsoft Graph permissions to the app registration and rely on user consent during sign-in.

D.

Grant admin consent to App1 for the required delegated permissions.

You have an Azure Logic Apps Consumption workflow that uses a Request trigger. All supported authentication methods are enabled on the Request trigger

You need to ensure that the endpoint accepts only OAuth-based requests. The solution must minimize costs.

What should you do?

A.

Use OAuth 2.0 authorization.

B.

Enable Secure Inputs and enable Secure Outputs for the Request trigger.

C.

Disable shared access signature (SAS) authentication for the Request trigger.

D.

Deploy Azure API Management.

You have an Azure subscription named Sub1 that contains a storage account named storage1. Sub1 has Microsoft Defender for Storage enabled. Defender for Storage has malware scanning enabled.

You need to configure a solution that automates the remediation of malware detected in storage1.

What should you include in the solution?

A.

Application Insights

B.

Azure Event Hubs

C.

Azure Event Grid

D.

Azure Policy

You have a Microsoft Sentinel workspace

You need to collect Windows security events from 200 Azure virtual machines that run Windows Server. The solution must meet the following requirements:

•Use direct agent based data collection from each virtual machine.

•Use a supported agent for new virtual machine deployments

Which Microsoft Sentinel connector should you use?

A.

Windows Forwarded Events

B.

Windows Security Events via AMA

C.

Security Events via Legacy Agent

D.

Syslog via AMA

E.

Azure Resource Graph

You have an Azure subscription that contains the following resources:

•An Azure SQL Database logical server named Server1 that contains a database named DB1

•An Azure SQL Managed Instance named Instance1 that contains a database named DB2

You need to configure database auditing. The solution must meet the following requirements:

•Ensure that audit data is centrally available in a location that supports for KQL queries.

•Minimize ongoing administrative effort as additional databases are added.

What should you configure? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

You have an Azure subscription named Sub1 that contains an Azure Database for PostgreSQL instance Sub1 has Microsoft Defender for Cloud enabled.

You need to configure Microsoft Defender for Databases to minimize costs.

Which Defender plan should you enable?

A.

Microsoft Defender for Servers

B.

Microsoft Defender for Open-Source Relational Databases

C.

Microsoft Defender for SQL Servers on Machines

D.

Microsoft Defender for Azure SQL Databases

E.

Microsoft Defender for Storage

You have a Microsoft Entra tenant that uses Privileged Identity Management (PIM).

You need to modify the AI Administrator role settings to meet the following requirements:

•Elevated access must be evaluated by another administrator before it is granted

•Privileged access must be removed automatically after a fixed period.

Which two settings should you configure? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A.

Expire active assignments after

B.

Require approval to activate

C.

Require justification on activation

D.

Expire eligible assignments after

E.

Activation maximum duration

You have a Microsoft Entra tenant.

You need to implement password less authentication. The solution must meet the following requirements:

•Users can sign in without a password by using a mobile device.

•New users that sign in for the first time must use a helpdesk issued sign in method that expires.

Which authentication method should you enable for each requirement? To answer, drag the appropriate methods to the correct requirements. Each method may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

You need to configure the AKS1 and ID 1 managed identities to meet the technical requirements. The solution must follow the principle of least privilege.

Which role should you assign to each identity? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

You need to delegate a user to implement the planned change for Defender for Cloud. The solution must follow the principle of least privilege.

Which user should you choose?

A.

Admin1

B.

Admin2

C.

Admin3

D.

Admin4

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You add each virtual machine to a security group, and then add the security group to a role on storage1.

Does this meet the goal?

A.

Yes

B.

No

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution: You create an automation rule.

Does this meet the goal?

A.

Yes

B.

No

User1 has requested to use the AI Administrator role.

Which approvers can approve the request, and how long will User1 be an AI administrator after the role is approved? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

You need to configure Server1 to meet the technical requirements.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

You need to protect the applications hosted on AKS1. The solution must meet the technical requirements.

Which Defender for Cloud plan should you enable?

A.

Microsoft Defender for Servers

B.

Microsoft Defender for App Service

C.

Microsoft Defender for Containers

D.

Microsoft Defender for Resource Manager

E.

Microsoft Defender for Storage

You need to implement the planned change for storage2 The solution must meet the technical requirements for storage encryption.

What should you do?

A.

Enable purge protection for storage2.

B.

Create an encryption scope in storage2.

C.

Configure storage2 to use an account encryption key.

D.

Assign an Azure role-based access control (Azure RBAC) role to storage2.

You need to implement the function apps to meet the technical requirements.

Which apps should you include in the implementation?

A.

Fa1 and Fa2 only

B.

Fa2 and Fa3 only

C.

Fa1 and Fa3 only

D.

Fa1, Fa2, and Fa3

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You create a private endpoint on storage1.

Does this meet the goal?

A.

Yes

B.

No

Page: 1 / 1
Total 68 questions
Copyright © 2014-2026 Solution2Pass. All Rights Reserved