Last Update 1 hour ago Total Questions : 135
The Microsoft Certified: Cloud and AI Security Engineer Associate content is now fully updated, with all current exam questions added 1 hour ago. Deciding to include SC-500 practice exam questions in your study plan goes far beyond basic test preparation.
You'll find that our SC-500 exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these SC-500 sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Microsoft Certified: Cloud and AI Security Engineer Associate practice test comfortably within the allotted time.
You have an Azure subscription named Sub1 that contains a storage account named storage1. Sub1 has Microsoft Defender for Storage enabled. Defender for Storage has malware scanning enabled.
You need to configure a solution that automates the remediation of malware detected in storage1.
What should you include in the solution?
You have an Azure subscription that contains an Azure Database for PostgreSQL instance named 081.
You plan to protect OBI by using Microsoft Defender for Cloud.
You need to configure Defender for Cloud to detect anomalous activities and database exploitations for 061. The solution must NOT affect any other databases.
What should you enable? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You have a Microsoft Entra tenant that contains a user named User1.
You have an Azure Arc-enabled server named SRV1 that runs Windows Server. SRV1 is configured for Microsoft Entra sign-in.
User1 reports that when they use their Microsoft Entra credentials to sign in to SRV1 over RDP, they receive the following message:
“Your account is configured to prevent you from using this device.”
You need to ensure that User1 can sign in to SRV1 over RDP. The solution must follow the principle of least privilege.
What should you do?
You have an Azure subscription named Sub1 that contains a storage account named storage1
Sub1 has Microsoft Defender for Storage enabled. Defender for Storage has on-upload malware scanning enabled.
The security team at your company requires that all malicious files be processed automatically by a serverless workflow for quarantine and notification.
You need to ensure that the malware scan results trigger an automated response. The solution must minimize operational effort.
What should you configure?
You create a new Microsoft Sentinel workspace named Workspace1.
Workspace1 ingests Azure Firewall logs that are used only occasionally during investigations.
You need to retain the logs for seven years at the lowest cost. The solution must ensure that investigators ran search the retained data when needed.
What should you do?
You have a Microsoft Sentinel workspace named Workspace1
You have 100 on-premises servers that run Linux and have the Azure Monitor Agent installed.
You need to collect Syslog events from the Linux servers. The solution must meet the following requirements:
•Ensure that filtering occurs before data is written to Workspace1
•Reduce ingestion costs by excluding low value Syslog messages.
What should you include in the solution?
You have an Azure subscription that contains a blob container named cont1. Con1 ' has the access policies shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.

You have an Azure subscription named Sub1 that contains an Azure Kubernetes Service (AKS) cluster named cluster1 and an Azure container registry named ACR1 Sub1 has Microsoft Defender for Containers enabled, and runtime protection is active on cluster!
The developers at your company deploy pods that have elevated privileges, and the deployments are created in cluster1
You need to prevent pods with elevated privileges from being accepted by cluster!
What should you do?
An application run2 on VM1 and VM2. The application is being migrated from storage account key authentication to Microsoft Entra authentication.
You review the current configuration and identify the following:
• VM1 and VM2 each have a system-assigned managed identity.
• Each application instance requests tokens by using only the local system-assigned managed identity.
• Network access to storage 1 from VMI and VM2 is allowed.
• No Azure RBAC data roles are assigned to the managed identities on storage1.
You need to enable the application on VM1 and VM2 to read and write blob data in storage1 by using Microsoft Entra authentication without changing how the application requests tokens.
Solution: You create a private endpoint for the blob service of storage1.
Does this meet the goal?
You have an Azure SQL Database logical server named Server1 that contains a database named DB1.
You need to configure authentication for Server1 to meet the following requirements;
•SQL authentication cannot be used for any databases on Server1.
•The solution must be enforced centrally at the server level.
What should you do?
