Implementing End-to-End Security Controls for Cloud and AI Workloads Free Sample Questions

Create a free account to browse all 12 sample questions. The full practice test includes 150 questions. Use the simulator for timed and flashcard mode.

Try Simulator

SC-500 Sample Questions

  1. Question 1

    Q1

    A financial enterprise is experiencing an increase in consent phishing attacks where end users inadvertently grant OAuth 2.0 permissions to unvetted third-party multi-tenant applications. As a cloud security engineer, you must reconfigure the tenant-wide user consent settings in Microsoft Entra ID to allow users to consent only to applications from verified publishers requesting low-risk permissions, while ensuring an approval path exists for all other applications.

    Which configuration should you implement in the Microsoft Entra admin center?

    Show answer & explanation

    Correct answer: D

    Microsoft recommends configuring user consent to 'Allow user consent for apps from verified publishers, for selected permissions' to mitigate consent phishing while allowing legitimate low-risk application adoption. Pairing this setting with the admin consent request workflow ensures that when an application requires unselected permissions or is not from a verified publisher, users can submit a request directly to administrators for formal review and approval. Setting user consent to completely disabled blocks all self-service workflows without distinguishing publisher trustworthiness, whereas allowing all user consent leaves the tenant vulnerable.

  2. Question 2

    Q2

    An organization deploys an internal multi-tenant enterprise application integrated with Microsoft Entra ID. The enterprise application object has the property 'Assignment required?' set to 'Yes'. A team of data analysts who have not been assigned to the application attempt to access it and grant delegated user consent for basic profile read permissions. The tenant's global consent policy allows user consent for verified publishers.

    What occurs when the unassigned analysts attempt to consent and access the application?

    Show answer & explanation

    Correct answer: D

    When an enterprise application requires user assignment ('Assignment required?' set to 'Yes'), Microsoft Entra ID blocks standard user consent. In this state, an administrator must explicitly consent to the permissions on the application's behalf before assigned users can sign in. Standard user consent policies, even if configured to allow consent for verified publishers, cannot override the application's assignment requirement.

  3. Question 3

    Q3

    A lead security architect is designing an automated secrets discovery mechanism across 400 Azure virtual machines. The security team requires discovery of plaintext connection strings, unprotected SSH private keys, and cloud storage Shared Access Signature (SAS) tokens without installing software agents, impacting host VM CPU utilization, or degrading network throughput.

    Which Microsoft Defender for Cloud capability and tier combination satisfies these operational requirements?

    Show answer & explanation

    Correct answer: C

    Agentless secrets scanning for virtual machines is provided under Defender Cloud Security Posture Management (Defender CSPM) or Defender for Servers Plan 2. It inspects VM disk snapshots out-of-band in an isolated scanning environment without deploying in-guest agents or utilizing host VM compute and network resources. It detects exposed secrets such as plaintext connection strings, SSH private keys (PKCS#1, PKCS#8, OpenSSH, PuTTY), and Azure Storage SAS tokens.

  4. Question 4

    Q4Multiple answers

    You enable agentless secrets scanning across your production Azure subscriptions using Microsoft Defender CSPM. Discovered secrets are cataloged and ingested into the cloud security graph.

    In which TWO surfaces within the Microsoft Defender for Cloud portal can security engineers investigate these discovered secrets? (Select TWO)

    Show answer & explanation

    Correct answers: A, E

    Attack path analysis uses cloud security graph data to model lateral movement risks, evaluating whether discovered secrets on a VM expose an exploitable path to sensitive crown-jewel assets. It is one of the primary investigation surfaces for Defender CSPM secrets scanning.

    Cloud security explorer allows analysts to build custom queries and use pre-built templates against the cloud security graph to search specifically for compute resources containing exposed plaintext secrets.

  5. Question 5

    Q5

    Contoso Pharmaceuticals maintains critical clinical trial database backups in Azure Recovery Services vaults. A recent threat assessment revealed that rogue administrators or compromised credentials could delete backup data or disable security configurations to facilitate ransomware extortion.

    The enterprise requirements are:

    1. Prevent any operation that could cause loss of recovery points by enforcing WORM (write once, read many) storage in an irreversible state.
    2. Ensure critical backup management actions (such as disabling soft delete or modifying retention) mandate approval from an independent security team using a separate authorization object.
    3. Elevate the vault security posture to achieve the 'Excellent (Maximum)' vault security level in Azure Backup.

    Which combination of Azure Backup security features must you implement to fulfill these requirements?

    sequenceDiagram autonumber participant Admin as Backup Administrator participant RG as Resource Guard (Security Subscription) participant Vault as Recovery Services Vault participant Storage as Immutable WORM Storage Admin->>RG: Request authorization for critical operation RG-->>Admin: Approval granted via MUA Admin->>Vault: Submit modify/delete command with MUA token Vault->>Storage: Block deletion (Locked Immutability)
    Show answer & explanation

    Correct answer: A

    To achieve the 'Excellent (Maximum)' security level in Azure Backup, a vault must have Multi-User Authorization (MUA) enabled AND either immutability configured in an irreversible 'Locked' state or soft delete configured as irreversible ('always-on'). MUA uses an Azure Resource Guard deployed in a separate subscription with restricted RBAC, requiring secondary approval before executing destructive actions. Locking the immutable vault enforces WORM retention permanently, preventing even subscription owners from revoking immutability or pruning recovery points prematurely.

  6. Question 6

    Q6

    A security engineer is evaluating the soft delete capabilities of Azure Backup for a newly provisioned Recovery Services vault. The engineer must ensure that soft delete protection cannot be disabled by a compromised administrative identity, and that deleted backup items are retained beyond the default window.

    Which configuration achieves this protection?

    Show answer & explanation

    Correct answer: B

    Enhanced soft delete in Azure Backup permits administrators to customize the retention window (from 14 up to 180 days) and set the state to 'Always-On'. Once soft delete is set to 'Always-On', it becomes irreversible and cannot be turned off by any user or administrator, providing robust defense against ransomware attempting to purge backup data before encrypting production systems. Standard soft delete has a fixed 14-day window and can be disabled by a compromised user with Contributor rights on the vault unless protected by MUA or Always-On.

Register free to unlock 6 more sample questions

Create a free account to continue with the rest of the SC-500 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 150 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon