Free Microsoft SC-500 Practice Test Questions MCQs
Stop wondering if you're ready. Our Microsoft SC-500 practice test is designed to identify your exact knowledge gaps. Validate your skills with Microsoft Certified: Cloud and AI Security Engineer Associate questions that mirror the real exam's format and difficulty. Build a personalized study plan based on your free SC-500 exam questions mcqs performance, focusing your effort where it matters most.
Targeted practice like this helps candidates feel significantly more prepared for Microsoft Certified: Cloud and AI Security Engineer Associate exam day.
2600+ already prepared
Updated On : 31-Aug-202660 Questions
Microsoft Certified: Cloud and AI Security Engineer Associate
4.9/5.0
You are configuring a new Microsoft Sentinel workspace named Workspace1.
You have an external IT Service Management (ITSM) system that is NOT supported by any Microsoft Sentinel solutions in Azure Marketplace.
You need to ensure that Workspace1 creates service tickets in the ITSM system for all new
security incidents.
What should you create?
A. A playbook
B. A workbook
C. A watchlist
D. An analytics rule
You have an Azure virtual network named VNet1 that contains an Azure Bastion Subnet.
VNet1 contains a subnet named Subnet1 Subnet1 contains multiple virtual machines.
You plan to deploy Azure Bastion to provide secure RDP access to the virtual machines on
Subnet1. You associate a network security group (NSG) named NSG1 to Azure Bastion
Subnet.
You need to configure rules for NSG1. The solution must meet the following requirements:
•Allow required inbound access to Azure Bastion from the internet.
•Allow user access to the virtual machines by using Azure Bastion.
Which TCP ports should you allow for the NSG1 rules? To answer, drag the appropriate
ports to the correct rules. Each port may be used once, more than once, or not at all. You
may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
You have three internet-facing Azure App Service web apps named App1, App2, and App1
Each app uses built-in authentication.
App2 hosts a backend API.
Some corporate users can sign in to App2, even though they should NOT be able to use
the API.
You need to restrict App2 access to assigned Microsoft Entra users and groups.
What should you configure for App2? To answer, drag the appropriate configurations to the
correct methods. Each configuration may be used once, more than once, or not at all. You
may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
You have a Microsoft Entra tenant that has user consent for applications disabled.
You register an application named App1 that requests the following Microsoft Graph
delegated permissions:.
•user.Read.
•Mail.Read.
You need to configure tenant permissions to meet the following requirements:.
•Enable users to grant consent for low-risk permissions without administrator interaction..
•Ensure that applications requesting higher-privilege permissions require administrator
approval..
What should you do?
A. Grant tenant-wide admin consent to App1.
B. Configure application assignments for App1.
C. Configure Privileged Identity Management (PIM) role assignments.
D. Create an app consent policy.
You have multiple Microsoft Security Copilot workspaces.
A user named User1 accesses Security Copilot by using the default workspace.
You create a new workspace named Workspace 1 and assign a capacity to Workspace1.
You plan to route Security Copilot agent traffic to Workspace1.
You need to ensure that User1 can use embedded experiences without errors.
What should you do before switching to Workspace1?
A. Add User1 to Workspace1.
B. Assign User1 the Security Operator role in Microsoft Entra.
C. Disassociate the capacity from the default workspace.
D. Create a new capacity for Workspace1.
You have a Microsoft 365 subscription.
You use Microsoft Entra Agent ID to manage an agent identity.
You manage AI agents from the Microsoft 365 admin center.
An autonomous agent named Agent1 runs without a signed-in user. The agent must
access Microsoft Graph and read secrets from a single Azure key vault.
You need to grant Agent 1 access to Microsoft Graph and Key Vault without requiring user
interaction or consent at runtime.
What should you do for the agent identity? To answer, drag the appropriate actions to the
correct services. Each action may be used once, more than once, or not at all. You may
need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
You have a Microsoft Sentinel workspace named Workspace1
You have 100 on-premises servers that run Linux and have the Azure Monitor Agent
installed.
You need to collect Syslog events from the Linux servers. The solution must meet the following requirements:
•Ensure that filtering occurs before data is written to Workspace1
•Reduce ingestion costs by excluding low value Syslog messages.
What should you include in the solution?
A. An Advanced Security Information Model (ASIM) parser
B. A data collection rule (DCR)
C. An analytics rule
D. A table-level filter and split transformation
You have an Azure Logic Apps Consumption workflow that uses a Request trigger. All supported authentication methods are enabled on the Request trigger
You need to ensure that the endpoint accepts only OAuth-based requests. The solution
must minimize costs.
What should you do?
A. Use OAuth 2.0 authorization.
B. Enable Secure Inputs and enable Secure Outputs for the Request trigger.
C. Disable shared access signature (SAS) authentication for the Request trigger.
D. Deploy Azure API Management.
You have Microsoft Security Copilot agents that authenticate by using Microsoft Entra service principals.
You receive a Microsoft Defender alert triggered by the anomalous OAuth authentication of an agent's Microsoft Entra service principal.
You need to assess the impact of the agent identity and identify which resources are affected if the identity is abused for lateral movement The solution must minimize administrative effort.
What should you do?
A. From Advanced hunting, create a query against the IdentityLogonEvents table to list all the sign-ins performed by the identity.
B. From Attack paths, select the identity and view the blast radius.
C. From AI Observability in Microsoft Purview Data Security Posture Management (DSPM), review the agent activity.
D. From Microsoft Purview Audit, query the audit logs for all the role assignments granted to the identity.
E. From Incidents, review incidents related to OAuth events reported by Microsoft Defender for Cloud Apps.
You have a Microsoft 365 subscription. All users have Microsoft Exchange Online mailboxes.
You use Microsoft Entra Agent ID to register and manage AI agents.
The developers at your company create the following two agents:
•Agent 1: An interactive agent that helps users summarize their own Exchange Online email
•Agent2: An autonomous agent that sends nightly updates to a Microsoft Teams channel
You need to grant each agent access to Microsoft Graph. The solution must minimize the access scope, while meeting each agent's operating model.
Which type of permission should you assign to each agent? To answer, drag the appropriate permission types to the correct agents. Each permission type may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
| Page 1 out of 6 Pages |