Weekend Special Sale - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 75special

Practice Free SC-500 Microsoft Certified: Cloud and AI Security Engineer Associate Exam Questions Answers With Explanation

We at Crack4sure are committed to giving students who are preparing for the Microsoft SC-500 Exam the most current and reliable questions . To help people study, we've made some of our Microsoft Certified: Cloud and AI Security Engineer Associate exam materials available for free to everyone. You can take the Free SC-500 Practice Test as many times as you want. The answers to the practice questions are given, and each answer is explained.

Question # 6

You have a Microsoft Entra tenant.

On January 1, you configure a Multifactor authentication registration policy that has the following settings

• Assignments: All users

• Require Microsoft Entra ID multifactor authentication registration: Enabled

• Enforce policy: On

On January 3, you create two new users named User1 and User2.

On January 5, User1 authenticates to Microsoft Entra ID for the first time. On January 7, User2 authenticates to Microsoft Entra ID for the first time.

On which date will User1 and User2 be forced to register for MFA? To answer, drag the appropriate dates to the correct users. Each date may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

SC-500 question answer

Question # 7

You have three on-premises apps named App1, App2, and App3 that are configured in Microsoft Entra Private Access as shown in the following table.

SC-500 question answer

You have the users shown in the following table.

SC-500 question answer

The Global Secure Access client is deployed to all user devices.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

SC-500 question answer

Question # 8

You have a management group named MG1 that contains two subscriptions named Sub1 and Sub2

Sub1 contains a resource group named RG-Exception and a resource group named RG1 that hosts Microsoft Foundry resources.

You need to assign an Azure policy to force new Foundry deployments in MG1 to use private endpoints. The solution must NOT restrict deployments in RG-Exception.

How should you configure the policy?

A.

Assign the policy to MG1 and exclude RG-Exception.

B.

Assign the policy to Sub1 and RG-Exception.

C.

Assign the policy to MG1 and RG-Exception.

D.

Assign the policy to Sub1 and exclude RG-Exception.

Question # 9

You have a Microsoft Entra tenant that has the following configurations:

•User consent for applications is disabled.

•Only administrators can grant permissions to applications.

You register an application named App1 that uses delegated Microsoft Graph permissions.

You need to configure App1 to meet the following requirements:

•Enable user sign-ins without interactive consent prompts.

•Enable App1 to access Microsoft Graph on behalf of the signed-in user.

What should you do?

A.

Configure enterprise applications to require user assignment and assign users to App1.

B.

Modify the app registration to use application permissions instead of delegated permissions.

C.

Add the required delegated Microsoft Graph permissions to the app registration and rely on user consent during sign-in.

D.

Grant admin consent to App1 for the required delegated permissions.

Question # 10

Vou have a Microsoft Entra tenant that uses Microsoft Entra Agent ID. You have multiple Microsoft Foundry agents that have agent identities assigned. Vou dm OW that one of the identities is flagged as high risk duf in unusual sign-in activity. Vou need to ensure that agent access to resources is restricted automatically based on risk. What should you create?

A.

a Privileged Identity Management (PIM) activation policy

B.

a Microsoft Entra role assignment policy

C.

a Conditional Access policy for the identities

D.

an Access review for the identities

Question # 11

You have an Azure subscription.

You need to deploy an Azure virtual WAN to meet the following requirements:

•Create three secured virtual hubs located in the East US. West US, and North Europe Azure regions.

•Ensure that security rules sync between the regions.

What should you use?

A.

Azure Network Function Manager

B.

Azure Firewall Manager

C.

Azure Virtual Network Manager

D.

Azure Front Door

Question # 12

You have an Azure subscription that is linked to a Microsoft Entra tenant the tenant contains the groups shown in the following table.

SC-500 question answer

The tenant contains the users shown in the following table.

SC-500 question answer

The subscription contains the Azure SOL servers shown in the following table.

SC-500 question answer

The servers are configured for Microsoft Entra-only authentication.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

SC-500 question answer

Question # 13

You have an Azure SQL Database logical server named Server1 that contains multiple databases.

The databases contain legacy SQL authentication logins that must no longer be usable for sign-in but must NOT be removed from the databases.

You need to ensure that SQL authentication is denied for connections.

What should you do?

A.

Run CREATE USER ... FROM EXTERNAL PROVIDER on each database.

B.

Create a Conditional Access policy.

C.

Enable Microsoft Entra-only authentication for Server1.

D.

Assign the SQL Server Contributor role to Server1.

Question # 14

You have an Azure subscription that contains the following servers:

•200 virtual machines that run either Windows Server or Ubuntu Server

•50 Azure Arc enabled servers

You use Azure Policy to manage compliance across all the servers.

You need to enforce an organization-specific security baseline. The solution must meet the following requirements:

•Customize a built-in security baseline.

•Ensure that configuration changes to the servers are enforced automatically after the security baseline is deployed.

?Minimize administrative effort.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

SC-500 question answer

Question # 15

You have a Microsoft Entra tenant that contains a group named Group1.

You plan to target Group1 to use the Microsoft Authenticator authentication method.

You need to ensure that the members in Group1 can use the Authenticator app as their primary authentication method.

What should you do?

A.

Enable one-time passcodes in Authenticator for Group1.

B.

Revoke the sessions for the Group1 members.

C.

Enable Authenticator push authentication mode for Group1.

D.

Enable the Authenticator passwordless authentication method for Group1.

Question # 16

You have an Azure subscription named Sub1 that contains a resource group named RG1.

RG1 contains a virtual network named VNet1 and a storage account named storage1. Several engineers are assigned the Owner role for Sub1.

You need to prevent updates to and deletions from VNet1. The solution must ensure that engineers can continue updating other resources in RG1.

Which lock should you apply?

A.

a Read-only resource lock at the RG1 scope

B.

a Delete resource lock at the RG1 scope

C.

a Read-only resource lock at the VNet1 scope

D.

a Delete resource lock at the VNet1 scope

Question # 17

You have a Microsoft 365 tenant that uses Microsoft Security Copilot and Microsoft Defender XDR.

Access to Microsoft Defender XDR is managed by using Microsoft entra global roles.

The Phishing triage Agent is available in Microsoft Defender. The required agent prerequisites and approvals are complete

Two users will perform the following tasks:

• User1 will enable and manage the Phishing Triage Agent settings.

• User2 will use Security Copilot in Microsoft Defender XDR to manage phishing incidents identified by the agent.

You need to assign the least-privileged built in Microsoft Entra role and Security Copilot role combination to each us Which roles should you assign to each user? To answer, select the appropriate options in the answer area.

SC-500 question answer

Question # 18

You have an Azure subscription named Sub1 that contains a storage account named storage1

Sub1 has Microsoft Defender for Storage enabled. Defender for Storage has on-upload malware scanning enabled for a monthly cap of 10,000 GB per storage account.

You use a Microsoft Sentinel workspace to monitor security events on all Azure resources.

You need to configure storage1 to use a malware scanning cap of 2.000 GB per month.

What should you do?

A.

Enable Override Defender for Storage subscription-level settings for storage1.

B.

From Microsoft Sentinel, modify the data collection rule (DCR) to restrict log ingestion from storage1.

C.

Modify the malware scanning configuration of Sub1.

D.

From the Microsoft Sentinel workspace, modify the daily cap.

Question # 19

You have an Azure subscription that contains three storage accounts, an Azure SQL managed instance named SQL1, and three Azure SQL databases.

The storage accounts are configured as shown in the following table.

SC-500 question answer

SC-500 question answer

Question # 20

You have an Azure subscription that contains an Azure SQL Database logical server named SQL1 and an Azure virtual machine named VM1. VM1 uses a private IP address only. The Firewall and virtual networks settings for SQL1 are shown in the following exhibit.

SC-500 question answer

You need to ensure that VM1 can connect to SQL1. The solution must use the principle of least privilege.

What should you do on the SQL1 Firewall and virtual network settings?

A.

Create a new firewall rule.

B.

Set Allow Azure services and resources to access this server to Yes.

C.

Add an existing virtual network.

D.

Set Connection Policy to Proxy.

Question # 21

You have an Azure subscription that has the Microsoft Defender for Cloud Foundational Cloud Security Posture Management (CSPM) plan enabled.

You have an Amazon Web Services (AWS) account connected to Defender for Cloud for posture management.

In Defender for Cloud, security recommendations for the resources in Azure and AWS have a risk level of Not evaluated.

You need to ensure that Defender for Cloud assigns a risk level to the recommendations.

What should you do?

A.

Onboard all the virtual machines in the AWS account to Azure Arc.

B.

Enable Microsoft Defender for Servers Plan 2.

C.

Assign the CIS AWS Foundations v3.0.0 standard to the AWS account.

D.

Enable the Defender CSPM plan.

Question # 22

You have a Microsoft Entra tenant.

You need to implement password less authentication. The solution must meet the following requirements:

•Users can sign in without a password by using a mobile device.

•New users that sign in for the first time must use a helpdesk issued sign in method that expires.

Which authentication method should you enable for each requirement? To answer, drag the appropriate methods to the correct requirements. Each method may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

SC-500 question answer

Question # 23

You have an Azure subscription that contains the resources shown in the following table.

SC-500 question answer

VM1 contains an application that accesses storage1. Another application accesses storage1 from a public IP address of 131.107.10.20.

For storage1, you set Public network access to Enabled from selected virtual networks and IP addresses. You add an IP network rule for 131.107.10.20.

After the configuration, only connections from 131.107.10.20 succeed.

You need to ensure that both VM1 and 131.107.10.20 can access storage1 over the public endpoint, while preventing all other access.

What should you do?

A.

Add a public IP address to VM1.

B.

Set Public network access to Enabled from all networks.

C.

Enable the Microsoft.Storage service endpoint for Subnet1.

Question # 24

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution: You create a playbook

Does this meet the goal?

A.

Yes

B.

No

Question # 25

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You add each virtual machine to a role on storage1.

Does this meet the goal?

A.

Yes

B.

No

Question # 26

User1 has requested to use the AI Administrator role.

Which approvers can approve the request, and how long will User1 be an AI administrator after the role is approved? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

SC-500 question answer

Question # 27

You need to protect the applications hosted on AKS1. The solution must meet the technical requirements.

Which Defender for Cloud plan should you enable?

A.

Microsoft Defender for Servers

B.

Microsoft Defender for App Service

C.

Microsoft Defender for Containers

D.

Microsoft Defender for Resource Manager

E.

Microsoft Defender for Storage

Question # 28

You need to implement the planned change for the AKS1 integration.

What should you configure for AKS1?

A.

application scaling

B.

a workload identity

C.

Secrets Store CSI Driver

D.

Kubernetes role-based access control (Kubernetes RBAC)

Question # 29

You need to configure Microsoft Sentinel to meet the technical requirements.

To what should you set Analytics retention for DnsEvents?

A.

2 years

B.

12 years

C.

180 days

D.

1 year

E.

6 years

Question # 30

You need to configure Server1 to meet the technical requirements.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

SC-500 question answer

Question # 31

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution: You create an automation rule.

Does this meet the goal?

A.

Yes

B.

No

Question # 32

You need to implement the function apps to meet the technical requirements.

Which apps should you include in the implementation?

A.

Fa1 and Fa2 only

B.

Fa2 and Fa3 only

C.

Fa1 and Fa3 only

D.

Fa1, Fa2, and Fa3

Question # 33

You need to implement the planned change for SQLdb1

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point

A.

Create a compliance policy.

B.

Configure Microsoft Entra authentication for SQLServer1.

C.

Create a Conditional Access policy.

D.

Configure federated client identity for SQLdb1.

E.

Configure a user-assigned managed identity for SQLdb1.

Question # 34

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You create a private endpoint on storage1.

Does this meet the goal?

A.

Yes

B.

No

Question # 35

You need to implement the planned change for storage2 The solution must meet the technical requirements for storage encryption.

What should you do?

A.

Enable purge protection for storage2.

B.

Create an encryption scope in storage2.

C.

Configure storage2 to use an account encryption key.

D.

Assign an Azure role-based access control (Azure RBAC) role to storage2.

Question # 36

You need to delegate a user to implement the planned change for Defender for Cloud. The solution must follow the principle of least privilege.

Which user should you choose?

A.

Admin1

B.

Admin2

C.

Admin3

D.

Admin4

Question # 37

For each of the following statements, select Yes if the statement is true Otherwise, select No.

SC-500 question answer

Question # 38

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You add each virtual machine to a security group, and then add the security group to a role on storage1.

Does this meet the goal?

A.

Yes

B.

No

Question # 39

Note. This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem

After you answer a question in this section, you will NOT be able to return. As a result these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution You create a hunting query.

Does this meet the goal’

A.

Yes

B.

No

Question # 40

You need to configure the AKS1 and ID 1 managed identities to meet the technical requirements. The solution must follow the principle of least privilege.

Which role should you assign to each identity? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

SC-500 question answer

SC-500 PDF

$35

$139.99

3 Months Free Update

  • Printable Format
  • Value of Money
  • 100% Pass Assurance
  • Verified Answers
  • Researched by Industry Experts
  • Based on Real Exams Scenarios
  • 100% Real Questions

SC-500 PDF + Testing Engine

$47.5

$189.99

3 Months Free Update

  • Exam Name: Microsoft Certified: Cloud and AI Security Engineer Associate
  • Last Update: Sep 19, 2026
  • Questions and Answers: 135
  • Free Real Questions Demo
  • Recommended by Industry Experts
  • Best Economical Package
  • Immediate Access

SC-500 Engine

$40

$159.99

3 Months Free Update

  • Best Testing Engine
  • One Click installation
  • Recommended by Teachers
  • Easy to use
  • 3 Modes of Learning
  • State of Art Technology
  • 100% Real Questions included