Microsoft Implementing End-to-End Security Controls for Cloud and AI Workloads SC-500 Exam Questions

Page: 1 / 14
Total 135 questions
Question 1

You have Microsoft Security Copilot agents that authenticate by using Microsoft Entra service principals.

You receive a Microsoft Defender alert triggered by the anomalous OAuth authentication of an agent's Microsoft Entra service principal.

You need to assess the impact of the agent identity and identify which resources are affected if the identity is abused for lateral movement The solution must minimize administrative effort.

What should you do?



Answer : B

The security team needs impact and lateral-movement exposure for an abused service principal. Defender XDR attack paths show the identity blast radius by connecting permissions, exposed resources, and reachable assets. Advanced hunting and audit logs can provide raw evidence, but they require more manual analysis. AI Observability and incident review do not directly answer which resources are affected by identity abuse across the environment. The compute domain tests whether protection is applied before deployment, during runtime, or through posture assessment. The selected answer matches the phase described in the requirement. Detection-only tools are not acceptable when the requirement says prevent, and local installation methods are inferior when Defender for Cloud, Azure Policy, or Azure Machine Configuration can enforce the control centrally. The result is a direct exam-style implementation choice: it changes the required security behavior without relying on unrelated monitoring, manual cleanup, or excessive privilege. Official Microsoft source/topic: SC-500 Study Guide > analyze blast radius by using Defender XDR; Microsoft Learn > attack paths for identity risk.

==============================================================


Question 2

You have a Microsoft Entra tenant that contains the users shown in the following table.

You have a Microsoft Security Copilot workspace.

From Microsoft Security Store, you plan to deploy a partner-built agent named Agent1 that requires access to Microsoft Intune.

When User1 selects Agent1, the Get agent option is unavailable.

You need to enable User1 to complete the agent setup. The solution must follow the principle of least privilege.

What should you do first?



Answer : E

For a partner-built Security Copilot agent that accesses a Microsoft product such as Microsoft Intune, Microsoft requires a Global Administrator in the tenant to approve the permissions requested by the agent. After that approval is granted, users who are Security Copilot owners or contributors can complete the remaining agent configuration. User2 already holds the Global Administrator role, while User1 already has Security Copilot Contributor, so User2 should perform the required approval first.

This also satisfies the principle of least privilege. Assigning User1 the AI Administrator or Agent ID Administrator role would unnecessarily elevate User1's Microsoft Entra privileges. The Agent ID Administrator role, for example, can manage the full lifecycle of agent identities, agent identity blueprints, blueprint principals, and agent users---far broader authority than is necessary merely to finish this Security Copilot agent deployment.

Creating an agent identity or configuring the Intune data source occurs during or after agent setup and does not replace the tenant-level consent requirement. Microsoft specifically distinguishes the initial administrator approval for partner agents requiring Microsoft product permissions from the subsequent configuration steps that Security Copilot contributors can perform.

Therefore, User2 must first approve Agent1's requested permissions, after which User1 can continue the setup.


Question 3

You have an Azure Functions app named App1 that uses an HTTP trigger, runs on an Elastic Premium plan, and uses virtual network integration.

A partner application sends requests to App1 from a public IP address of xxx.xxx.xxx.xx.

You need to ensure that the requests are accepted from only xxx.xxx.xxx.xx.

What should you do?



Answer : D

Configure an inbound access restriction on App1 that explicitly allows the partner's public IP address. Azure Functions running on App Service infrastructure support access restriction rules that operate as an inbound network ACL. Microsoft states that these rules can contain individual IPv4/IPv6 addresses or ranges and that once one or more rules are configured, unmatched traffic can be denied. This directly supports the requirement to accept HTTP requests only from the specified partner IP.

The existing virtual network integration does not control inbound access. Microsoft specifically defines VNet integration as an outbound networking capability. Consequently, an NSG associated with the integration subnet affects traffic originating from the Function App but does not filter requests arriving at the Function App's public endpoint.

A private endpoint would eliminate normal public access and therefore would not support a partner that connects from a public Internet IP unless additional private connectivity were implemented. Azure Bastion is for administrative connectivity to VMs, while NAT Gateway controls outbound source addressing.

The SC-500 study guide explicitly includes configuring Azure Functions authentication and network access under Secure compute.

===============


Question 4

You have an Azure SQL Database logical server named Server1 that contains multiple databases.

The databases contain legacy SQL authentication logins that must no longer be usable for sign-in but must NOT be removed from the databases.

You need to ensure that SQL authentication is denied for connections.

What should you do?



Answer : C

Microsoft Entra-only authentication at the logical server level disables SQL authentication for all databases on that server while leaving existing SQL principals in place. That matches the requirement to deny SQL authentication without removing legacy logins. Creating external-provider users adds Entra users; it does not block SQL logins. Conditional Access can govern Entra sign-ins but cannot disable SQL authentication. SQL Server Contributor is an Azure management role, not an authentication mode. The exam objective emphasizes practical identity enforcement rather than cosmetic configuration. A valid answer must identify who authenticates, what permission is granted, where the scope is applied, and whether the method continues to work without passwords or secrets. That is why the selected answer is preferred over broader administrative roles or unrelated access settings. The result is a direct exam-style implementation choice: it changes the required security behavior without relying on unrelated monitoring, manual cleanup, or excessive privilege. Official Microsoft source/topic: SC-500 Study Guide > Azure SQL platform security; Microsoft Learn > Microsoft Entra-only authentication.

==============================================================


Question 5

The subscription contains the virtual machines shown in the following table.

On Nl1I, you configure an application security group named ASG1.

On which other network interfaces can you configure ASG1?



Answer : B


Question 6

You have an Azure virtual network named VNet1 that contains a subnet named Subnet1.

You create a storage account named storage1.

You need to ensure that access to storage1 can be managed only by a network security group (NSG) linked to Subnet1.

What should you use?



Answer : C

A private endpoint is the appropriate mechanism because it exposes the Azure Storage service through a private IP address associated with Subnet1. Private endpoints support Azure virtual network network policies, including network security groups (NSGs). When private-endpoint network policies are enabled for the subnet, NSG rules can be applied to traffic destined for the private endpoint, allowing network access to be controlled through the NSG associated with Subnet1.

This differs materially from a service endpoint. Service endpoints continue to access Azure Storage through its public service endpoint and require service-side virtual network ACL/firewall configuration to restrict which subnets may access the storage account. Microsoft explicitly states that enabling a service endpoint alone is insufficient: the Azure service must also be configured with appropriate virtual-network access controls. Therefore, access would not be governed only by the NSG.

An Azure Private Link service is used to privately publish a customer-owned service, typically behind a load balancer; it is not required to consume Azure Storage privately. A UDR controls routing and does not establish private access to Storage.

For a complete private-access design, the storage account's public endpoint should also be restricted or disabled. Microsoft recommends private endpoints when private network access to Azure Storage is required.


Question 7

You have an Azure subscription.

You need to deploy an Azure virtual WAN to meet the following requirements:

*Create three secured virtual hubs located in the East US. West US, and North Europe Azure regions.

*Ensure that security rules sync between the regions.

What should you use?



Answer : B

Secured virtual hubs in Virtual WAN are managed through Azure Firewall Manager. Firewall Manager can deploy and manage Azure Firewall policies across secured virtual hubs and keep policy configuration consistent across regions. Azure Virtual Network Manager is designed for virtual network topology and security admin rules, not Virtual WAN secured hub policy synchronization. Azure Front Door and Network Function Manager address different perimeter or network appliance scenarios. The important exam skill is separating data-plane access, management-plane administration, and network reachability. A storage, database, or firewall setting must be selected because it enforces the exact path requested in the scenario. Distractors often look plausible because they improve security generally, but they do not satisfy the protocol, scope, or automation requirement stated in the question. The result is a direct exam-style implementation choice: it changes the required security behavior without relying on unrelated monitoring, manual cleanup, or excessive privilege. Official Microsoft source/topic: SC-500 Study Guide > Secure Azure Virtual WAN; Microsoft Learn > Azure Firewall Manager secured virtual hubs and policies.

==============================================================


Page:    1 / 14   
Total 135 questions