Summer Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Microsoft Certified: Cloud and AI Security Engineer Associate Question and Answers

Microsoft Certified: Cloud and AI Security Engineer Associate

Last Update Jul 25, 2026
Total Questions : 68

We are offering FREE SC-500 Microsoft exam questions. All you do is to just go and sign up. Give your details, prepare SC-500 free exam questions and then go for complete pool of Microsoft Certified: Cloud and AI Security Engineer Associate test questions that will help you more.

SC-500 pdf

SC-500 PDF

$40.25  $114.99
SC-500 Engine

SC-500 Testing Engine

$47.25  $134.99
SC-500 PDF + Engine

SC-500 PDF + Testing Engine

$61.25  $174.99
Questions 1

You have an Azure management group named MG1 that contains two subscriptions named Sub1 and Sub? Both subscriptions are linked to a Microsoft Entra tenant that contains a security group named Group!

You need to ensure that the members of Group1 can assign roles to the resources in Sub1 and Sub2. The solution must follow the principle of least privilege.

Which role should you assign to Group1?

Options:

A.  

Contributor at the MG1 scope

B.  

Contributor at the Sub1 and Sub2 scopes

C.  

User Access Administrator at the MG1 scope

D.  

Owner at the MG1 scope

Discussion 0
Questions 2

For each of the following statements, select Yes if the statement is true Otherwise, select No.

Options:

Discussion 0
Questions 3

You need to implement the function apps to meet the technical requirements.

Which apps should you include in the implementation?

Options:

A.  

Fa1 and Fa2 only

B.  

Fa2 and Fa3 only

C.  

Fa1 and Fa3 only

D.  

Fa1, Fa2, and Fa3

Discussion 0
Questions 4

Note. This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem

After you answer a question in this section, you will NOT be able to return. As a result these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution You create a hunting query.

Does this meet the goal’

Options:

A.  

Yes

B.  

No

Discussion 0
Questions 5

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution: You create an analytics rule.

Does this meet the goal?

Options:

A.  

Yes

B.  

No

Discussion 0
Questions 6

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You add each virtual machine to a security group, and then add the security group to a role on storage1.

Does this meet the goal?

Options:

A.  

Yes

B.  

No

Discussion 0
Questions 7

User1 has requested to use the AI Administrator role.

Which approvers can approve the request, and how long will User1 be an AI administrator after the role is approved? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 8

You need to configure Server1 to meet the technical requirements.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 9

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution: You create a playbook

Does this meet the goal?

Options:

A.  

Yes

B.  

No

Discussion 0
Questions 10

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You add each virtual machine to a role on storage1.

Does this meet the goal?

Options:

A.  

Yes

B.  

No

Discussion 0
Questions 11

You have an Azure Storage account named storage1 that hosts a blob container named container1.

You have an Azure Functions app named app1 that uses a managed identity.

You need to configure app1 to read, write, and delete blobs in container1. The solution must follow the principle of least privilege.

What should you do?

Options:

A.  

Assign the Storage Account Contributor role to the managed identity of app1 at the scope of storage1.

B.  

Assign the Storage Blob Delegator role to the managed identity of app1 at the scope of container1.

C.  

Assign the Owner role to the managed identity of app1 at the scope of container1.

D.  

Assign the Storage Blob Data Contributor role to the managed identity of app1 at the scope of container1.

Discussion 0
Questions 12

You need to protect the applications hosted on AKS1. The solution must meet the technical requirements.

Which Defender for Cloud plan should you enable?

Options:

A.  

Microsoft Defender for Servers

B.  

Microsoft Defender for App Service

C.  

Microsoft Defender for Containers

D.  

Microsoft Defender for Resource Manager

E.  

Microsoft Defender for Storage

Discussion 0
Questions 13

You have a Microsoft Sentinel workspace named Workspace1.

You hire a security consultant. You provide the consultant with a guest account named User1 in your Microsoft Entra tenant

You need to enable User1 to assign incidents in Workspace1.

Which roles should you assign to User1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 14

You have an Azure subscription that contains a resource group named RG1.

RG1 contains a Microsoft Security Copilot deployment that is integrated with a Microsoft Sentinel workspace named Workspace1.

Analysts use the Security Copilot standalone experience to retrieve incidents by using the Microsoft Sentinel plugin.

A user named User1 can sign in to Security Copilot but cannot retrieve incidents from Workspace1. You verify that User1 lias only the Security Copilot Contributor role.

You need to ensure that User1 can retrieve the incidents. The solution must follow the principle of least privilege and NOT require any configuration changes to Security Copilot.

Which role should you assign to User1?

Options:

A.  

The Security Reader role in Microsoft Entra

B.  

The Microsoft Sentinel Reader role for Workspace1

C.  

The Security Copilot Owner role

D.  

The Security Administrator role in Microsoft Entra

E.  

The Contributor role in Azure for RG1

Discussion 0
Questions 15

You have an Azure subscription.

You need to deploy an Azure virtual WAN to meet the following requirements:

•Create three secured virtual hubs located in the East US. West US, and North Europe Azure regions.

•Ensure that security rules sync between the regions.

What should you use?

Options:

A.  

Azure Network Function Manager

B.  

Azure Firewall Manager

C.  

Azure Virtual Network Manager

D.  

Azure Front Door

Discussion 0
Questions 16

You have a hybrid environment that contains the following servers:

•50 Azure virtual machines that run Windows Server 2019

•20 physical, on premises servers that run Windows Server 2019

All the servers use a third-party antivirus solution that must remain active during a phased security rollout

You need to onboard all the servers to Microsoft Defender for Endpoint by using a centralized deployment method. The solution must meet the following requirements:

•Endpoint detection and response (EDR) capabilities must be enabled.

•Antivirus conflicts must be prevented during onboarding.

What should you do on the servers?

Options:

A.  

Set the Microsoft Defender for Endpoint service to Disabled.

B.  

Disable Microsoft Defender Antivirus real-time protection by using Set-MpPreference.

C.  

Configure the ForceDefenderPassiveMode registry value.

D.  

Enable EDR in block mode.

Discussion 0
Questions 17

You have an Azure virtual network named VNet1 that contains three subnets named Subnet1, Subnet2 and Subnet3. A single network security group (NSG) named NSG1 is associated with all the subnets. You have the following virtual machines:

•VM1 on Subnet1

•VM2 on Subnet2

VM3 on Subnet3

You create two application security groups named ASG1 and ASG2. VM2 is a member of ASG1, and VM3 is a member of ASG2.

You need to ensure that only VM2 can connect to VM3. The solution must continue to work if the private IP address of VM2 changes.

How should you configure the inbound rule on NSG1 ? To answer, drag the settings to the correct configurations. Each setting may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 18

You have an Azure subscription named Sub1 that contains a storage account named storage1

Sub1 has Microsoft Defender for Storage enabled. Defender for Storage has on-upload malware scanning enabled.

The security team at your company requires that all malicious files be processed automatically by a serverless workflow for quarantine and notification.

You need to ensure that the malware scan results trigger an automated response. The solution must minimize operational effort.

What should you configure?

Options:

A.  

An Azure Event Grid subscription

B.  

Diagnostic settings to send logs to a Log Analytics workspace

C.  

Lifecycle management policies

D.  

An Azure Monitor alert rule

Discussion 0
Questions 19

You have a Microsoft Entra tenant.

You need to implement password less authentication. The solution must meet the following requirements:

•Users can sign in without a password by using a mobile device.

•New users that sign in for the first time must use a helpdesk issued sign in method that expires.

Which authentication method should you enable for each requirement? To answer, drag the appropriate methods to the correct requirements. Each method may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 20

You have an Azure subscription named Sub1 that contains a storage account named storage1. Sub1 has Microsoft Defender for Storage enabled. Defender for Storage has malware scanning enabled.

You need to configure a solution that automates the remediation of malware detected in storage1.

What should you include in the solution?

Options:

A.  

Application Insights

B.  

Azure Event Hubs

C.  

Azure Event Grid

D.  

Azure Policy

Discussion 0