Month End Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: stp75

Easiest Solution 2 Pass Your Certification Exams

SC-500 Microsoft Certified: Cloud and AI Security Engineer Associate Free Practice Exam Questions (2026 Updated)

Prepare effectively for your Microsoft SC-500 Microsoft Certified: Cloud and AI Security Engineer Associate certification with our extensive collection of free, high-quality practice questions. Each question is designed to mirror the actual exam format and objectives, complete with comprehensive answers and detailed explanations. Our materials are regularly updated for 2026, ensuring you have the most current resources to build confidence and succeed on your first attempt.

Page: 1 / 2
Total 135 questions

User1 has requested to use the AI Administrator role.

Which approvers can approve the request, and how long will User1 be an AI administrator after the role is approved? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You create a user-assigned managed identity, assign the identity to each virtual machine, and then add each managed identity to a role on storage1.

Does this meet the goal?

A.

Yes

B.

No

You have an Azure subscription named Sub1 that is linked to a Microsoft Entra tenant named contoso.com.

Sub1 contains a Recovery Services vault named RSVault1 that stores virtual machine backups.

Your company’s security team maintains a dedicated Microsoft Entra tenant named security.contoso.com.

You need to ensure that modifying the backup settings of RSVault1 requires approval from an approver in security.contoso.com.

What should you do in contoso.com?

A.

Enable immutability for RSVault1 and lock the immutability setting.

B.

Create a private endpoint for RSVault1 on the virtual network.

C.

Configure Privileged Identity Management (PIM) activation for the Backup Operator role.

D.

Enable Multi-user authorization (MUA) for RSVault1.

You have a Microsoft Entra tenant that uses Privileged Identity Management (PIM).

You need to modify the AI Administrator role settings to meet the following requirements:

•Elevated access must be evaluated by another administrator before it is granted

•Privileged access must be removed automatically after a fixed period.

Which two settings should you configure? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A.

Expire active assignments after

B.

Require approval to activate

C.

Require justification on activation

D.

Expire eligible assignments after

E.

Activation maximum duration

You have an Azure management group named MG1 that contains two subscriptions named Sub1 and Sub? Both subscriptions are linked to a Microsoft Entra tenant that contains a security group named Group!

You need to ensure that the members of Group1 can assign roles to the resources in Sub1 and Sub2. The solution must follow the principle of least privilege.

Which role should you assign to Group1?

A.

Contributor at the MG1 scope

B.

Contributor at the Sub1 and Sub2 scopes

C.

User Access Administrator at the MG1 scope

D.

Owner at the MG1 scope

You have an Azure key vault named Vault1 that stores the resources shown in the following table.

Which resources support the creation of a rotation policy?

A.

Key1 only

B.

Cert1 only

C.

Key1 and Secret1 only

D.

Secre1 and Cert1 only

E.

Secret1 and Cert1 only

F.

Key1, Secre1, end Cert1

You have an Azure subscription named Sub1 that contains a virtual network named VNet1.

VNet1 contains multiple virtual machines, including two virtual machines named VM1 and VM2.

Sub1 is linked to a Microsoft Entra tenant named contoso.com.

A partner company has an Azure subscription named Sub2 that contains a virtual network named VNet2. VNet2 contains a virtual machine named VM3.

Sub2 is linked to a Microsoft Entra tenant named fabrikam.com.

VM1 and VM2 contain data used by an application that runs on VM3.

You need to ensure that VM3 can access VM1 and VM2. The solution must deny VM3 access to any other resources in Sub1.

What should you configure on each virtual network? To answer, drag the components to the correct virtual networks. Each component may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

You use Azure Virtual Network Manager to manage multiple virtual networks organized into two network groups named Production and Development.

You need to configure Virtual Network Manager to meet the following requirements:

Allow traffic between all the virtual networks in Production.

Block traffic between Development and Production.

What should you use for each requirement? To answer, drag the components to the correct requirements. Each component may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

You have an Azure subscription named Sub1 that contains a resource group named RG1.

RG1 contains a virtual network named VNet1 and a storage account named storage1. Several engineers are assigned the Owner role for Sub1.

You need to prevent updates to and deletions from VNet1. The solution must ensure that engineers can continue updating other resources in RG1.

Which lock should you apply?

A.

a Read-only resource lock at the RG1 scope

B.

a Delete resource lock at the RG1 scope

C.

a Read-only resource lock at the VNet1 scope

D.

a Delete resource lock at the VNet1 scope

You have an Azure Functions app named App1 that uses an HTTP trigger, runs on an Elastic Premium plan, and uses virtual network integration.

A partner application sends requests to App1 from a public IP address of xxx.xxx.xxx.xx.

You need to ensure that the requests are accepted from only xxx.xxx.xxx.xx.

What should you do?

A.

Deploy an Azure Bastion host.

B.

Create a private endpoint for App1 and disable public network access.

C.

Apply a network security group (NSG) to a dedicated subnet for virtual network integration.

D.

Configure an inbound access restriction on App1.

E.

Deploy an Azure NAT Gateway.

You have an Azure subscription that contains an Azure Key vault. The role assignments for the vault are shown in the following.

You have a Microsoft Copilot Studio agent.

A Microsoft Power Platform administrator configures external threat detection for the agent by using a Microsoft Entra application.

You need to ensure that real-time protection is enabled during agent runtime.

What should you do in the Microsoft Defender portal?

A.

Configure Microsoft Defender for Cloud Apps session policies.

B.

Connect the Microsoft 365 app connector.

C.

Enable Global Secure Access for Agents.

D.

From Microsoft Sentinel, configure the Microsoft Purview data connector.

The subscription contains the virtual machines shown in the following table.

On Nl1I, you configure an application security group named ASG1.

On which other network interfaces can you configure ASG1?

A.

NIC2 only

B.

NIC2 and NlC3 only

C.

NIC2, NIC3, and NIC4 only

D.

NIC2, N1C3, NIC4, and NIC5

You have an Azure subscription that is linked to a Microsoft Entra tenant the tenant contains the groups shown in the following table.

The tenant contains the users shown in the following table.

The subscription contains the Azure SOL servers shown in the following table.

The servers are configured for Microsoft Entra-only authentication.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

You have a Microsoft Entra tenant that has user consent for applications disabled.

You register an application named App1 that requests the following Microsoft Graph delegated permissions:

•user.Read

•Mail.Read

You need to configure tenant permissions to meet the following requirements:

•Enable users to grant consent for low-risk permissions without administrator interaction.

•Ensure that applications requesting higher-privilege permissions require administrator approval.

What should you do?

A.

Grant tenant-wide admin consent to App1.

B.

Configure application assignments for App1.

C.

Configure Privileged Identity Management (PIM) role assignments.

D.

Create an app consent policy.

You have multiple Microsoft Security Copilot workspaces.

A user named User1 accesses Security Copilot by using the default workspace.

You create a new workspace named Workspace 1 and assign a capacity to Workspace1.

You plan to route Security Copilot agent traffic to Workspace1.

You need to ensure that User1 can use embedded experiences without errors.

What should you do before switching to Workspace1?

A.

Add User1 to Workspace1.

B.

Assign User1 the Security Operator role in Microsoft Entra.

C.

Disassociate the capacity from the default workspace.

D.

Create a new capacity for Workspace1.

You have an Azure subscription named Sub1 that contains 50 virtual machines. Sub1 has Microsoft Defender for Cloud enabled.

Sub1 contains an Azure key vault named KV1 and an Azure policy that enforces storing all secrets in KV1.

Occasionally, the developers at your company store plaintext tokens and SSH private keys on the virtual machines.

You need to configure Defender for Cloud to detect plaintext secrets on the virtual machines. The solution must minimize administrative changes to the virtual machines.

How should you configure Defender for Cloud? To answer, select the appropriate options in the answer area

NOTE: Each correct selection is worth one point.

You have a Microsoft Entra tenant that contains a group named Group1.

You plan to target Group1 to use the Microsoft Authenticator authentication method.

You need to ensure that the members in Group1 can use the Authenticator app as their primary authentication method.

What should you do?

A.

Enable one-time passcodes in Authenticator for Group1.

B.

Revoke the sessions for the Group1 members.

C.

Enable Authenticator push authentication mode for Group1.

D.

Enable the Authenticator passwordless authentication method for Group1.

You have an Azure subscription that contains the resources shown in the following table.

VM1 contains an application that accesses storage1. Another application accesses storage1 from a public IP address of 131.107.10.20.

For storage1, you set Public network access to Enabled from selected virtual networks and IP addresses. You add an IP network rule for 131.107.10.20.

After the configuration, only connections from 131.107.10.20 succeed.

You need to ensure that both VM1 and 131.107.10.20 can access storage1 over the public endpoint, while preventing all other access.

What should you do?

A.

Add a public IP address to VM1.

B.

Set Public network access to Enabled from all networks.

C.

Enable the Microsoft.Storage service endpoint for Subnet1.

You have an Azure subscription named Sub1 that contains a storage account named storage1

Sub1 has Microsoft Defender for Storage enabled. Defender for Storage has on-upload malware scanning enabled for a monthly cap of 10,000 GB per storage account.

You use a Microsoft Sentinel workspace to monitor security events on all Azure resources.

You need to configure storage1 to use a malware scanning cap of 2.000 GB per month.

What should you do?

A.

Enable Override Defender for Storage subscription-level settings for storage1.

B.

From Microsoft Sentinel, modify the data collection rule (DCR) to restrict log ingestion from storage1.

C.

Modify the malware scanning configuration of Sub1.

D.

From the Microsoft Sentinel workspace, modify the daily cap.

Page: 1 / 2
Total 135 questions
Copyright © 2014-2026 Solution2Pass. All Rights Reserved