Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Microsoft Certified: Cloud and AI Security Engineer Associate

Last Update 1 day ago Total Questions : 135

The Microsoft Certified: Cloud and AI Security Engineer Associate content is now fully updated, with all current exam questions added 1 day ago. Deciding to include SC-500 practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our SC-500 exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these SC-500 sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Microsoft Certified: Cloud and AI Security Engineer Associate practice test comfortably within the allotted time.

Question # 1

You have an Azure subscription that contains the following resources:

•An Azure SQL Database logical server named Server1 that contains a database named DB1

•An Azure SQL Managed Instance named Instance1 that contains a database named DB2

You need to configure database auditing. The solution must meet the following requirements:

•Ensure that audit data is centrally available in a location that supports for KQL queries.

•Minimize ongoing administrative effort as additional databases are added.

What should you configure? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 2

You have a Microsoft Entra tenant.

On January 1, you configure a Multifactor authentication registration policy that has the following settings

• Assignments: All users

• Require Microsoft Entra ID multifactor authentication registration: Enabled

• Enforce policy: On

On January 3, you create two new users named User1 and User2.

On January 5, User1 authenticates to Microsoft Entra ID for the first time. On January 7, User2 authenticates to Microsoft Entra ID for the first time.

On which date will User1 and User2 be forced to register for MFA? To answer, drag the appropriate dates to the correct users. Each date may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Question # 3

You have a virtual network named VNet1 that contains a subnet named Subnet1 and a virtual machine named VM1. VM1 uses only dynamic IP addresses from Subnet1.

You have an Azure key vault named KV1.

You enable a firewall on KV1 and allow access to KV1 from only select virtual networks and IP addresses.

VM1 receives 403 errors when it attempts to access KV1.

You need to enable VM1 to access KV1, while maintaining the current restrictions on KV1.

What should you do?

A.

Create a routing rule on Subnet1.

B.

Allow trusted Microsoft services to bypass the firewall on KV1.

C.

Add a Microsoft.KeyVault service endpoint for Subnet1.

D.

Add the current IPv4 address of VM1 to the firewall allowlist of KV1.

Question # 4

You have an Azure virtual network named VNet1 that contains a subnet named Subnet1.

You create a storage account named storage1.

You need to ensure that access to storage1 can be managed only by a network security group (NSG) linked to Subnet1.

What should you use?

A.

an Azure Private Link service

B.

a service endpoint

C.

a private endpoint

D.

a user-defined route (UDR)

Question # 5

You have an Azure Container Registry named Registry1-

You add role assignments for Registry! as shown in the following table.

Question # 6

You have multiple Microsoft Security Copilot workspaces.

A user named User1 accesses Security Copilot by using the default workspace.

You create a new workspace named Workspace 1 and assign a capacity to Workspace1.

You plan to route Security Copilot agent traffic to Workspace1.

You need to ensure that User1 can use embedded experiences without errors.

What should you do before switching to Workspace1?

A.

Add User1 to Workspace1.

B.

Assign User1 the Security Operator role in Microsoft Entra.

C.

Disassociate the capacity from the default workspace.

D.

Create a new capacity for Workspace1.

Question # 7

You need to configure the AKS1 and ID 1 managed identities to meet the technical requirements. The solution must follow the principle of least privilege.

Which role should you assign to each identity? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 8

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You add each virtual machine to a security group, and then add the security group to a role on storage1.

Does this meet the goal?

A.

Yes

B.

No

Question # 9

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You create a user-assigned managed identity, assign the identity to each virtual machine, and then add each managed identity to a role on storage1.

Does this meet the goal?

A.

Yes

B.

No

Question # 10

For each of the following statements, select Yes if the statement is true Otherwise, select No.

Go to page: