Exam style questions across every SC-500 domain
Last Update 4 days ago
Total Questions : 135
Start with our free SC-500 practice questions, carefully crafted to mirror the domains, phrasing, and difficulty of the real Microsoft Certified: Information Security Administrator Associate exam. Each SC-500 exam question comes with a detailed rationale that explains not just which answer is correct but why the others fall short. That's how concepts stick. Use the free set to benchmark yourself: identify your Microsoft weak domains, see where you're losing marks, and build a focused study plan in minutes.
For which storage accounts can you implement the planned changes for storage?
You need to delegate a user to implement the planned change for Defender for Cloud. The solution must follow the principle of least privilege.
Which user should you choose?
You have an Azure subscription that contains an Azure Key vault. The role assignments for the vault are shown in the following.

You have an Azure subscription that contains the custom roles shown in the following table.

In the Azure portal, you plan to create new custom roles by cloning existing roles Ihe new roles will be configured as shown in following table.

You have an Azure subscription that contains a resource group named RG1 and has Microsoft Defender tor Cloud enabled.
You connect an Amazon Web Services (AWS) account to Defender for Cloud by creating the AW5 connector in RG1.
You have a Microsoft Entra group named Group1 that contains the UMf accounts of (he security analysts at your company.
You need to ensure that the members of Group1 can view multicloud recommendations and security alerts ' or the connected AWS account. The solution must follow the principle of least privilege
Which role should you assign to Group1 for RG1?
You have a management group named MG1 that contains two subscriptions named Sub1 and Sub2
Sub1 contains a resource group named RG-Exception and a resource group named RG1 that hosts Microsoft Foundry resources.
You need to assign an Azure policy to force new Foundry deployments in MG1 to use private endpoints. The solution must NOT restrict deployments in RG-Exception.
How should you configure the policy?
You have a Microsoft Defender External Attack Surface Management (Defender EASM) resource for a company named Contoso. Ltd.
You need to update the Defender EASM workflow to meet the following requirements:
•Assets from a business domain that Contoso no longer owns must be removed from inventory.
•Findings that do NOT apply to confirmed inventory must NOT affect reported counts.
What should you do for each requirement? To answer, drag the appropriate actions to the correct requirements. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

You have an Azure subscription.
You need to create and deploy an Azure policy that meets the following requirements:
•When a new virtual machine is deployed, automatically install a custom security extension.
•Trigger an autogenerated remediation task for non-compliant virtual machines to install the extension.
What should you include in the policy? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You have a Microsoft Entra tenant that contains a user named User1.
You have an Azure Arc-enabled server named SRV1 that runs Windows Server. SRV1 is configured for Microsoft Entra sign-in.
User1 reports that when they use their Microsoft Entra credentials to sign in to SRV1 over RDP, they receive the following message:
“Your account is configured to prevent you from using this device.”
You need to ensure that User1 can sign in to SRV1 over RDP. The solution must follow the principle of least privilege.
What should you do?
You have a Microsoft Entra tenant that uses Privileged Identity Management (PIM).
You need to modify the AI Administrator role settings to meet the following requirements:
•Elevated access must be evaluated by another administrator before it is granted
•Privileged access must be removed automatically after a fixed period.
Which two settings should you configure? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.






