Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Microsoft Certified: Cloud and AI Security Engineer Associate

Last Update 1 hour ago Total Questions : 135

The Microsoft Certified: Cloud and AI Security Engineer Associate content is now fully updated, with all current exam questions added 1 hour ago. Deciding to include SC-500 practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our SC-500 exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these SC-500 sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Microsoft Certified: Cloud and AI Security Engineer Associate practice test comfortably within the allotted time.

Question # 31

You have an Azure subscription named Sub1 that contains a storage account named storage1. Sub1 has Microsoft Defender for Storage enabled. Defender for Storage has malware scanning enabled.

You need to configure a solution that automates the remediation of malware detected in storage1.

What should you include in the solution?

A.

Azure Logic Apps

B.

a Log Analytics workspace

C.

an alert rule

D.

Azure Policy

Question # 32

You have an Azure subscription that contains an Azure Database for PostgreSQL instance named 081.

You plan to protect OBI by using Microsoft Defender for Cloud.

You need to configure Defender for Cloud to detect anomalous activities and database exploitations for 061. The solution must NOT affect any other databases.

What should you enable? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 33

You have a Microsoft Entra tenant that contains a user named User1.

You have an Azure Arc-enabled server named SRV1 that runs Windows Server. SRV1 is configured for Microsoft Entra sign-in.

User1 reports that when they use their Microsoft Entra credentials to sign in to SRV1 over RDP, they receive the following message:

“Your account is configured to prevent you from using this device.”

You need to ensure that User1 can sign in to SRV1 over RDP. The solution must follow the principle of least privilege.

What should you do?

A.

Assign User1 the Virtual Machine Administrator Login role for SRV1.

B.

Create a Conditional Access policy that requires multifactor authentication (MFA).

C.

Add User1 to the local Remote Desktop Users group on SRV1.

D.

Assign User1 the Virtual Machine User Login role for SRV1.

Question # 34

You have an Azure subscription named Sub1 that contains a storage account named storage1

Sub1 has Microsoft Defender for Storage enabled. Defender for Storage has on-upload malware scanning enabled.

The security team at your company requires that all malicious files be processed automatically by a serverless workflow for quarantine and notification.

You need to ensure that the malware scan results trigger an automated response. The solution must minimize operational effort.

What should you configure?

A.

An Azure Event Grid subscription

B.

Diagnostic settings to send logs to a Log Analytics workspace

C.

Lifecycle management policies

D.

An Azure Monitor alert rule

Question # 35

You create a new Microsoft Sentinel workspace named Workspace1.

Workspace1 ingests Azure Firewall logs that are used only occasionally during investigations.

You need to retain the logs for seven years at the lowest cost. The solution must ensure that investigators ran search the retained data when needed.

What should you do?

A.

Configure the table in Workspace1 that stores the togs to use the analytics tier.

B.

Increase the analytics retention period of Workspace1 to seven years.

C.

Configure the table in Workspace1 that stores the logs to use the data lake tier.

D.

Archive the logs to an Azure Storage account.

Question # 36

You have a Microsoft Sentinel workspace named Workspace1

You have 100 on-premises servers that run Linux and have the Azure Monitor Agent installed.

You need to collect Syslog events from the Linux servers. The solution must meet the following requirements:

•Ensure that filtering occurs before data is written to Workspace1

•Reduce ingestion costs by excluding low value Syslog messages.

What should you include in the solution?

A.

An Advanced Security Information Model (ASIM) parser

B.

A data collection rule (DCR)

C.

An analytics rule

D.

A table-level filter and split transformation

Question # 37

You have an Azure subscription that contains a blob container named cont1. Con1 ' has the access policies shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

Question # 38

You have an Azure subscription named Sub1 that contains an Azure Kubernetes Service (AKS) cluster named cluster1 and an Azure container registry named ACR1 Sub1 has Microsoft Defender for Containers enabled, and runtime protection is active on cluster!

The developers at your company deploy pods that have elevated privileges, and the deployments are created in cluster1

You need to prevent pods with elevated privileges from being accepted by cluster!

What should you do?

A.

Create an Azure Policy for cluster1.

B.

Enable agentless discovery for Kubernetes in Defender for Containers.

C.

Configure runtime threat protection alerts for privileged container activity.

D.

Enable vulnerability assessment for images in ACR1.

Question # 39

An application run2 on VM1 and VM2. The application is being migrated from storage account key authentication to Microsoft Entra authentication.

You review the current configuration and identify the following:

• VM1 and VM2 each have a system-assigned managed identity.

• Each application instance requests tokens by using only the local system-assigned managed identity.

• Network access to storage 1 from VMI and VM2 is allowed.

• No Azure RBAC data roles are assigned to the managed identities on storage1.

You need to enable the application on VM1 and VM2 to read and write blob data in storage1 by using Microsoft Entra authentication without changing how the application requests tokens.

Solution: You create a private endpoint for the blob service of storage1.

Does this meet the goal?

A.

Yes

B.

No

Question # 40

You have an Azure SQL Database logical server named Server1 that contains a database named DB1.

You need to configure authentication for Server1 to meet the following requirements;

•SQL authentication cannot be used for any databases on Server1.

•The solution must be enforced centrally at the server level.

What should you do?

A.

Configure a Microsoft Entra administrator for Server1.

B.

Enable a managed identity for Server1.

C.

Enable Microsoft Entra-only authentication for Server1.

D.

Remove SQL logins from DB1.

Go to page: