Microsoft SC-500 Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Topic 1: Manage identity, access, and governance | 20-25% | - Implement governance with Azure Policy and Defender for Cloud - Secure access to resources using Microsoft Entra ID - Secure secrets and keys using Azure Key Vault |
| Topic 2: Secure storage, databases, and networking | 25-30% | - Implement security for storage accounts - Implement security for databases - Implement security for Azure network services |
| Topic 3: Secure compute | 20-25% | - Implement security for AI workloads - Implement security for application platform services - Implement security for servers and virtual machines (VMs) |
| Topic 4: Manage and monitor security posture | 20-25% | - Implement activity and event collection in Microsoft Sentinel - Manage security posture using Microsoft Defender for Cloud - Implement Microsoft Security Copilot configuration |
Microsoft Implementing End-to-End Security Controls for Cloud and AI Workloads Sample Questions:
1. You have an Azure subscription named Sub1. Sub1 contains 20 virtual machines that run Windows Server.
Sub1 has the Microsoft Defender for Cloud Defender Cloud Security Posture Management (CSPM) plan enabled.
You need to ensure that all the virtual machines are scanned automatically for known security flaws and misconfigurations.
What should you use?
A) just-in-time (JIT) VM access
B) cloud security explorer
C) attack path analysis
D) vulnerability assessment on the virtual machines
E) Microsoft cloud security benchmark (MCSB)
2. Hotspot Question
You have an Azure key vault named KV1 that uses role-based access control (RBAC) for data plane authorization.
You have multiple Azure App Service web apps that retrieve a SQL connection string stored as a secret in KV1.
You need to ensure that the web apps can access KV1. The solution must minimize the number of required identities and follow the principle of least privilege.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
3. You have an Azure subscription named Sub1 that contains multiple virtual machines. Sub1 has the Microsoft Defender Cloud Security Posture Management (CSPM) plan enabled.
You discover that Defender for Cloud fails to identify plaintext connection strings and SSH keys stored on the virtual machines.
You need to ensure that secrets can be identified on the virtual machines.
What should you do?
A) Configure the Defender for Cloud data connector in Microsoft Sentinel.
B) Enable Microsoft Defender for Key Vault.
C) Deploy the Azure Monitor Agent to all the virtual machines.
D) Enable agentless machine scanning.
4. Drag and Drop Question
You have a Microsoft Entra tenant.
You need to implement passwordless authentication. The solution must meet the following requirements:
- Users can sign in without a password by using a mobile device.
- New users that sign in for the first time must use a helpdesk-issued
sign-in method that expires.
Which authentication method should you enable for each requirement? To answer, drag the appropriate methods to the correct requirements. Each method may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
5. You have an Azure subscription named Sub1 that contains a storage account named storage1.
Sub1 has Microsoft Defender for Storage enabled. Defender for Storage has malware scanning enabled.
You need to configure a solution that automates the remediation of malware detected in storage1.
What should you include in the solution?
A) a Log Analytics workspace
B) Azure Policy
C) Azure Logic Apps
D) an alert rule
Solutions:
| Question # 1 Answer: D | Question # 2 Answer: Only visible for members | Question # 3 Answer: D | Question # 4 Answer: Only visible for members | Question # 5 Answer: C |














1304 Customer Reviews
Quality and ValueITCertKing Practice Exams are written to the highest standards of technical accuracy, using only certified subject matter experts and published authors for development - no all study materials.
Tested and ApprovedWe are committed to the process of vendor and third party approvals. We believe professionals and executives alike deserve the confidence of quality coverage these authorizations provide.
Easy to PassIf you prepare for the exams using our ITCertKing testing engine, It is easy to succeed for all certifications in the first attempt. You don't have to deal with all dumps or any free torrent / rapidshare all stuff.
Try Before BuyITCertKing offers free demo of each product. You can check out the interface, question quality and usability of our practice exams before you decide to buy.
