SC-500 Implementing End-to-End Security Controls for Cloud and AI Workloads Practice Questions
Prepare for SC-500 with more than an answer.
- Exam fee
- $165 USD
- Time limit
- 120 minutes
- Passing score
- 700 (scale 1-1000)
- Level
- Associate (Intermediate)
- Valid for
- 1 year (renew annually for free via online assessment)
Domains covered on the exam 4
- Manage identity, access, and governance24%
- Secure storage, databases, and networking28%
- Secure compute24%
- Manage and monitor security posture24%
- 1
A software company requires near-real-time automated containment of malicious files uploaded to its public-facing Azure Blob Storage containers. When Defender for Storage detects a file containing malware, the malicious blob must be immediately moved to a quarantined container and tagged as infected, without manual security analyst intervention.
Which architectural integration fulfills this requirement with the lowest administrative complexity?
flowchart LR Upload[Client Blob Upload] --> Storage[(Azure Blob Storage)] Storage --> Scan{Defender for Storage Malware Scan} Scan -->|Malicious Verdict| EG[Azure Event Grid System Topic] EG --> Sub[Event Subscription] Sub --> Auto[Azure Function / Logic App] Auto --> Quarantine[(Quarantine Container)]Show answer details
Correct answer: D
Defender for Storage malware scanning publishes scan results directly to Azure Event Grid. By creating an Event Grid subscription targeting the Microsoft.Security.MalwareScanningResult event type, organizations can trigger automated serverless workloads (such as Azure Functions or Logic Apps) to delete, quarantine, or apply blob index tags to malicious files in near real time immediately after detection.
- 2
You are enabling Defender for Storage across multiple enterprise subscriptions hosting Azure Data Lake Storage Gen2 accounts. The security leadership requires continuous discovery of data sensitivity risks to identify potential data exfiltration threats involving credit card numbers and health records.
Which statement accurately describes the Sensitive Data Discovery capability in Defender for Storage?
Show answer details
Correct answer: D
Sensitive Data Discovery in Defender for Storage uses an agentless smart sampling engine to scan storage containers without impacting performance. It integrates directly with Microsoft Purview sensitive information types (SITs) and sensitivity classification labels to detect sensitive data exposure. Under the Defender for Storage plan, this discovery feature can be enabled at no additional charge (unlike malware scanning, which incurs a per-GB processing fee).
- 3
A database security administrator is configuring database auditing for an Azure SQL Database containing highly sensitive financial records. The audit logs must be written to an Azure Storage account protected behind a storage firewall and virtual network rules. Furthermore, compliance regulations mandate that audit log files be protected by an immutable time-based retention policy where log entries can be appended continuously but never overwritten or deleted prematurely.
Which configuration must the administrator implement to satisfy these technical requirements?
Show answer details
Correct answer: C
To audit an Azure SQL Database to a storage account protected behind a virtual network or firewall, a general-purpose v2 (or Premium BlockBlobStorage) account is required. The Azure SQL logical server must authenticate using its system-assigned managed identity granted the 'Storage Blob Data Contributor' RBAC role. Because SQL audit records are written to Append Blobs (.xel format), any time-based immutability policy applied to the target container must have 'Allow protected append writes' configured for 'Append blobs' (or 'Block and append blobs'). Furthermore, SQL auditing retention must be set to a duration greater than the storage immutability period (setting SQL retention to 0 is unsupported with storage immutability).
- 4
You are auditing the security telemetry generated by Azure SQL Database auditing across your production environments. During an incident investigation, an engineer observes discrepancies between anticipated operational activities and logged audit records.
Which TWO statements describe documented limitations or operational omissions of Azure SQL Database auditing? (Select TWO)
Show answer details
Correct answer: B, D
Azure SQL Database auditing explicitly truncates the 'statement' and 'data_sensitivity_information' log fields at 4,000 characters. Queries or schema metadata exceeding this boundary will not be fully captured in the audit logs.
Operations executed against temporary tables and objects residing in the tempdb database are not captured by Azure SQL Database auditing to prevent excessive log bloat and performance degradation.
- 5
A financial enterprise is experiencing an increase in consent phishing attacks where end users inadvertently grant OAuth 2.0 permissions to unvetted third-party multi-tenant applications. As a cloud security engineer, you must reconfigure the tenant-wide user consent settings in Microsoft Entra ID to allow users to consent only to applications from verified publishers requesting low-risk permissions, while ensuring an approval path exists for all other applications.
Which configuration should you implement in the Microsoft Entra admin center?
Show answer details
Correct answer: D
Microsoft recommends configuring user consent to 'Allow user consent for apps from verified publishers, for selected permissions' to mitigate consent phishing while allowing legitimate low-risk application adoption. Pairing this setting with the admin consent request workflow ensures that when an application requires unselected permissions or is not from a verified publisher, users can submit a request directly to administrators for formal review and approval. Setting user consent to completely disabled blocks all self-service workflows without distinguishing publisher trustworthiness, whereas allowing all user consent leaves the tenant vulnerable.
- 6
An organization deploys an internal multi-tenant enterprise application integrated with Microsoft Entra ID. The enterprise application object has the property 'Assignment required?' set to 'Yes'. A team of data analysts who have not been assigned to the application attempt to access it and grant delegated user consent for basic profile read permissions. The tenant's global consent policy allows user consent for verified publishers.
What occurs when the unassigned analysts attempt to consent and access the application?
Show answer details
Correct answer: D
When an enterprise application requires user assignment ('Assignment required?' set to 'Yes'), Microsoft Entra ID blocks standard user consent. In this state, an administrator must explicitly consent to the permissions on the application's behalf before assigned users can sign in. Standard user consent policies, even if configured to allow consent for verified publishers, cannot override the application's assignment requirement.
