Skip to content

SC-500 Implementing End-to-End Security Controls for Cloud and AI Workloads Practice Questions

Prepare for SC-500 with more than an answer.

150 questions in the full set12 sample questionsUpdated Oct 3, 2026
Exam fee
$165 USD
Time limit
120 minutes
Passing score
700 (scale 1-1000)
Level
Associate (Intermediate)
Valid for
1 year (renew annually for free via online assessment)
Domains covered on the exam 4
  1. Manage identity, access, and governance24%
  2. Secure storage, databases, and networking28%
  3. Secure compute24%
  4. Manage and monitor security posture24%
  1. 1

    You are enabling Defender for Storage across multiple enterprise subscriptions hosting Azure Data Lake Storage Gen2 accounts. The security leadership requires continuous discovery of data sensitivity risks to identify potential data exfiltration threats involving credit card numbers and health records.

    Which statement accurately describes the Sensitive Data Discovery capability in Defender for Storage?

    Show answer details

    Correct answer: D

    Sensitive Data Discovery in Defender for Storage uses an agentless smart sampling engine to scan storage containers without impacting performance. It integrates directly with Microsoft Purview sensitive information types (SITs) and sensitivity classification labels to detect sensitive data exposure. Under the Defender for Storage plan, this discovery feature can be enabled at no additional charge (unlike malware scanning, which incurs a per-GB processing fee).

  2. 2

    A database security administrator is configuring database auditing for an Azure SQL Database containing highly sensitive financial records. The audit logs must be written to an Azure Storage account protected behind a storage firewall and virtual network rules. Furthermore, compliance regulations mandate that audit log files be protected by an immutable time-based retention policy where log entries can be appended continuously but never overwritten or deleted prematurely.

    Which configuration must the administrator implement to satisfy these technical requirements?

    Show answer details

    Correct answer: C

    To audit an Azure SQL Database to a storage account protected behind a virtual network or firewall, a general-purpose v2 (or Premium BlockBlobStorage) account is required. The Azure SQL logical server must authenticate using its system-assigned managed identity granted the 'Storage Blob Data Contributor' RBAC role. Because SQL audit records are written to Append Blobs (.xel format), any time-based immutability policy applied to the target container must have 'Allow protected append writes' configured for 'Append blobs' (or 'Block and append blobs'). Furthermore, SQL auditing retention must be set to a duration greater than the storage immutability period (setting SQL retention to 0 is unsupported with storage immutability).

  3. 3

    You are auditing the security telemetry generated by Azure SQL Database auditing across your production environments. During an incident investigation, an engineer observes discrepancies between anticipated operational activities and logged audit records.

    Which TWO statements describe documented limitations or operational omissions of Azure SQL Database auditing? (Select TWO)

    Show answer details

    Correct answer: B, D

    Azure SQL Database auditing explicitly truncates the 'statement' and 'data_sensitivity_information' log fields at 4,000 characters. Queries or schema metadata exceeding this boundary will not be fully captured in the audit logs.

    Operations executed against temporary tables and objects residing in the tempdb database are not captured by Azure SQL Database auditing to prevent excessive log bloat and performance degradation.

  4. 4

    A financial enterprise is experiencing an increase in consent phishing attacks where end users inadvertently grant OAuth 2.0 permissions to unvetted third-party multi-tenant applications. As a cloud security engineer, you must reconfigure the tenant-wide user consent settings in Microsoft Entra ID to allow users to consent only to applications from verified publishers requesting low-risk permissions, while ensuring an approval path exists for all other applications.

    Which configuration should you implement in the Microsoft Entra admin center?

    Show answer details

    Correct answer: D

    Microsoft recommends configuring user consent to 'Allow user consent for apps from verified publishers, for selected permissions' to mitigate consent phishing while allowing legitimate low-risk application adoption. Pairing this setting with the admin consent request workflow ensures that when an application requires unselected permissions or is not from a verified publisher, users can submit a request directly to administrators for formal review and approval. Setting user consent to completely disabled blocks all self-service workflows without distinguishing publisher trustworthiness, whereas allowing all user consent leaves the tenant vulnerable.

  5. 5

    An organization deploys an internal multi-tenant enterprise application integrated with Microsoft Entra ID. The enterprise application object has the property 'Assignment required?' set to 'Yes'. A team of data analysts who have not been assigned to the application attempt to access it and grant delegated user consent for basic profile read permissions. The tenant's global consent policy allows user consent for verified publishers.

    What occurs when the unassigned analysts attempt to consent and access the application?

    Show answer details

    Correct answer: D

    When an enterprise application requires user assignment ('Assignment required?' set to 'Yes'), Microsoft Entra ID blocks standard user consent. In this state, an administrator must explicitly consent to the permissions on the application's behalf before assigned users can sign in. Standard user consent policies, even if configured to allow consent for verified publishers, cannot override the application's assignment requirement.

  6. 6

    A lead security architect is designing an automated secrets discovery mechanism across 400 Azure virtual machines. The security team requires discovery of plaintext connection strings, unprotected SSH private keys, and cloud storage Shared Access Signature (SAS) tokens without installing software agents, impacting host VM CPU utilization, or degrading network throughput.

    Which Microsoft Defender for Cloud capability and tier combination satisfies these operational requirements?

    Show answer details

    Correct answer: C

    Agentless secrets scanning for virtual machines is provided under Defender Cloud Security Posture Management (Defender CSPM) or Defender for Servers Plan 2. It inspects VM disk snapshots out-of-band in an isolated scanning environment without deploying in-guest agents or utilizing host VM compute and network resources. It detects exposed secrets such as plaintext connection strings, SSH private keys (PKCS#1, PKCS#8, OpenSSH, PuTTY), and Azure Storage SAS tokens.

Create an account to continue.