Microsoft Implementing End-to-End Security Controls for Cloud and AI Workloads - SC-500 Exam Practice Test

You have an Azure subscription named Sub1 that is linked to a Microsoft Entra tenant named contoso.com.
Sub1 contains a Recovery Services vault named RSVault1 that stores virtual machines backups.
Your company's security team maintains a dedicated Microsoft Entra tenant named security.contoso.com.
You need to ensure that modifying the backup settings of RSVault1 requires approval from an approver in security.contoso.com.
What should you do in contoso.com?

Correct Answer: B Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
You have an Azure SQL Database logical server named Server1 that contains a database named DB1.
You need to configure authentication for Server1 to meet the following requirements:
- SQL authentication cannot be used for any databases on Server1.
- The solution must be enforced centrally at the server level.
What should you do?

Correct Answer: B Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
Hotspot Question
You have an Azure subscription that contains an Azure Database for PostgreSQL instance named DB1.
You plan to protect DB1 by using Microsoft Defender for Cloud.
You need to configure Defender for Cloud to detect anomalous activities and database exploitations for DB1. The solution must NOT affect any other databases.
What should you enable? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Correct Answer:

Explanation:
Box 1: At the individual database level
The database protection must be applied at the individual database level (specifically, at the individual database server level).
The requirement specifies that the configuration must not affect other databases.
Individual Database Level: Microsoft Defender for Cloud allows you to navigate directly to the specific Azure Database for PostgreSQL server, expand its Security menu, and enable Microsoft Defender for Cloud specifically for that single resource. This completely isolates the configuration to this instance.
Box 2: Microsoft Defender for Open-Source Relational Databases
The most appropriate plan is Microsoft Defender for Open-Source Relational Databases (which operates under the broader Microsoft Defender for Databases bundle).
Reference:
https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-sql-introduction
You have an Azure subscription named Sub1 that contains multiple virtual machines and an Azure key vault named KV1.
Each virtual machine has a system-assigned managed identity. Sub1 has Microsoft Defender for Servers enabled. Defender for Servers has agentless scanning enabled.
Some virtual machines use managed disks that are encrypted by using customer-managed keys stored in KV1.
You discover that the affected virtual machines fail to return agentless scanning results in Microsoft Defender for Cloud.
You need to ensure that agentless scanning can analyze the virtual machines.
What should you do?

Correct Answer: B Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
You have multiple Microsoft Security Copilot workspaces.
A user named User1 accesses Security Copilot by using the default workspace.
You create a new workspace named Workspace1 and assign a capacity to Workspace1.
You plan to route Security Copilot agent traffic to Workspace1.
You need to ensure that User1 can use embedded experiences without errors.
What should you do before switching to Workspace1?

Correct Answer: C Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
You have an Azure subscription that contains a resource group named RG1.
RG1 contains a Microsoft Security Copilot deployment that is integrated with a Microsoft Sentinel workspace named Workspace1.
Analysts use the Security Copilot standalone experience to retrieve incidents by using the Microsoft Sentinel plugin.
A user named User1 can sign in to Security Copilot but cannot retrieve incidents from Workspace1. You verify that User1 has only the Security Copilot Contributor role.
You need to ensure that User1 can retrieve the incidents. The solution must follow the principle of least privilege and NOT require any configuration changes to Security Copilot.
Which role should you assign to User1?

Correct Answer: B Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
You have an Azure API Management instance named APIM1.
You have a partner company that accesses an API in APIM1 by using subscription keys.
A backend API key is stored in a named value in APIM1.
Microsoft Defender for Cloud generates the following recommendation: "API Management secret named values should be stored in Azure Key Vault." You need to address the recommendation.
What should you do first?

Correct Answer: A Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
Hotspot Question
You have a Microsoft Entra tenant that contains the users shown in the following table.

The tenant contains a Conditional Access policy named CA1 that has the following settings:
Assignments:

- Users or agents:
-- Include: Directory roles: Global Administrator
Target resources:

- Resources (formerly cloud apps):
-- Include: All resources
Conditions:

- Locations:
-- Configure: Yes
-- Include: Any network or location
Access controls:

- Grant:
-- Require multifactor authentication
- Grant:
-- Require device to be marked as compliant
- For multiple controls:
-- Require all the selected controls
The tenant contains a Conditional Access policy named CA2 that has the following settings:
Assignments:

- Users or agents:
-- Include: Users and groups: Group1
Target resources:

- Resources (formerly cloud apps)
-- Include: Select resources: Office 365
Conditions:

- Locations:
-- Configure: Yes
-- Include: Any network or location
Access controls:

- Grant:
-- Require multifactor authentication
- Grant:
-- Require app protection policy
- For multiple controls:
-- Require one of the selected controls
The users perform the following tasks:
User1 signs in to Microsoft 365 from a home network by using Microsoft

Outlook on a noncompliant device.
User2 signs in to Microsoft 365 without an app protection policy by

using a noncompliant device.
User3 signs in to the Azure portal from a home network by using a

compliant device.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Correct Answer:

Explanation:
Box 1: No
No, User1 will be denied access to Microsoft 365.Even though User1 satisfies the requirements for policy CA2, they are blocked by policy CA1 because their device is noncompliant.
In Microsoft Entra ID, all applicable Conditional Access policies must be satisfied simultaneously for access to be granted.
Box 2: No
No, User2 will be blocked from accessing Microsoft 365 because they fail to meet the strict security requirements of Conditional Access policy CA2.
Box 3: Yes
Yes, User3 is granted access to the Azure portal after completing multifactor authentication.
CA1 Application: User3 is a Global Administrator, so CA1 applies to them.
Target Match: User3 is accessing the Azure portal, which falls under "All resources.
"CA1 Requirements: CA1 requires both Multifactor Authentication (MFA) and a compliant device.
User3 Status: User3 satisfies both conditions because they successfully completed MFA and are using a compliant device.
CA2 Exclusion: CA2 does not apply to User3 because User3 is not a member of Group1.
Reference:
https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-conditional-access-policies

Contact Us

If you have any question please leave me your email address, we will reply and send email to you in 12 hours.

Our Working Time: ( GMT 0:00-15:00 ) From Monday to Saturday

Support: Contact now 

日本語 Deutsch 繁体中文 한국어