Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: merry71

Free Microsoft Certified: Cloud and AI Security Engineer Associate Practice Questions

Exams4sure Dumps

Exam style questions across every SC-500 domain

Last Update 4 days ago
Total Questions : 135

Start with our free SC-500 practice questions, carefully crafted to mirror the domains, phrasing, and difficulty of the real Microsoft Certified: Information Security Administrator Associate exam. Each SC-500 exam question comes with a detailed rationale that explains not just which answer is correct but why the others fall short. That's how concepts stick. Use the free set to benchmark yourself: identify your Microsoft weak domains, see where you're losing marks, and build a focused study plan in minutes.

SC-500 PDF

SC-500 PDF (Printable)
$46.5
$154.99

SC-500 Testing Engine

SC-500 PDF (Printable)
$51
$169.99

SC-500 PDF + Testing Engine

SC-500 PDF (Printable)
$63.9
$212.99
Question # 1

For which storage accounts can you implement the planned changes for storage?

Options:

A.  

storage1, storage2, storage3, and storage4

B.  

storage1, storage2, and storage4 only

C.  

storage2 and storage4 only

D.  

storage1 and storage3 only

E.  

storage2, storage3, and storage4 only

F.  

storage1 only

Discussion 0
Question # 2

You need to delegate a user to implement the planned change for Defender for Cloud. The solution must follow the principle of least privilege.

Which user should you choose?

Options:

A.  

Admin1

B.  

Admin2

C.  

Admin3

D.  

Admin4

Discussion 0
Question # 3

You have an Azure subscription that contains an Azure Key vault. The role assignments for the vault are shown in the following.

Question # 3

Options:

Discussion 0
Question # 4

You have an Azure subscription that contains the custom roles shown in the following table.

Question # 4

In the Azure portal, you plan to create new custom roles by cloning existing roles Ihe new roles will be configured as shown in following table.

Question # 4

Options:

Discussion 0
Question # 5

You have an Azure subscription that contains a resource group named RG1 and has Microsoft Defender tor Cloud enabled.

You connect an Amazon Web Services (AWS) account to Defender for Cloud by creating the AW5 connector in RG1.

You have a Microsoft Entra group named Group1 that contains the UMf accounts of (he security analysts at your company.

You need to ensure that the members of Group1 can view multicloud recommendations and security alerts ' or the connected AWS account. The solution must follow the principle of least privilege

Which role should you assign to Group1 for RG1?

Options:

A.  

Owner

B.  

Security Administrator

C.  

Security Reader

D.  

Reader

Discussion 0
Question # 6

You have a management group named MG1 that contains two subscriptions named Sub1 and Sub2

Sub1 contains a resource group named RG-Exception and a resource group named RG1 that hosts Microsoft Foundry resources.

You need to assign an Azure policy to force new Foundry deployments in MG1 to use private endpoints. The solution must NOT restrict deployments in RG-Exception.

How should you configure the policy?

Options:

A.  

Assign the policy to MG1 and exclude RG-Exception.

B.  

Assign the policy to Sub1 and RG-Exception.

C.  

Assign the policy to MG1 and RG-Exception.

D.  

Assign the policy to Sub1 and exclude RG-Exception.

Discussion 0
Question # 7

You have a Microsoft Defender External Attack Surface Management (Defender EASM) resource for a company named Contoso. Ltd.

You need to update the Defender EASM workflow to meet the following requirements:

•Assets from a business domain that Contoso no longer owns must be removed from inventory.

•Findings that do NOT apply to confirmed inventory must NOT affect reported counts.

What should you do for each requirement? To answer, drag the appropriate actions to the correct requirements. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Question # 7

Options:

Discussion 0
Question # 8

You have an Azure subscription.

You need to create and deploy an Azure policy that meets the following requirements:

•When a new virtual machine is deployed, automatically install a custom security extension.

•Trigger an autogenerated remediation task for non-compliant virtual machines to install the extension.

What should you include in the policy? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 8

Options:

Discussion 0
Question # 9

You have a Microsoft Entra tenant that contains a user named User1.

You have an Azure Arc-enabled server named SRV1 that runs Windows Server. SRV1 is configured for Microsoft Entra sign-in.

User1 reports that when they use their Microsoft Entra credentials to sign in to SRV1 over RDP, they receive the following message:

“Your account is configured to prevent you from using this device.”

You need to ensure that User1 can sign in to SRV1 over RDP. The solution must follow the principle of least privilege.

What should you do?

Options:

A.  

Assign User1 the Virtual Machine Administrator Login role for SRV1.

B.  

Create a Conditional Access policy that requires multifactor authentication (MFA).

C.  

Add User1 to the local Remote Desktop Users group on SRV1.

D.  

Assign User1 the Virtual Machine User Login role for SRV1.

Discussion 0
Question # 10

You have a Microsoft Entra tenant that uses Privileged Identity Management (PIM).

You need to modify the AI Administrator role settings to meet the following requirements:

•Elevated access must be evaluated by another administrator before it is granted

•Privileged access must be removed automatically after a fixed period.

Which two settings should you configure? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Options:

A.  

Expire active assignments after

B.  

Require approval to activate

C.  

Require justification on activation

D.  

Expire eligible assignments after

E.  

Activation maximum duration

Discussion 0

Free Exams Sample Questions