Summer Sale Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Microsoft SC-500 Microsoft Certified: Cloud and AI Security Engineer Associate Exam Practice Test

Page: 1 / 7
Total 68 questions

Microsoft Certified: Cloud and AI Security Engineer Associate Questions and Answers

Question 1

You have a Microsoft Entra tenant that has the following configurations:

•User consent for applications is disabled.

•Only administrators can grant permissions to applications.

You register an application named App1 that uses delegated Microsoft Graph permissions.

You need to configure App1 to meet the following requirements:

•Enable user sign-ins without interactive consent prompts.

•Enable App1 to access Microsoft Graph on behalf of the signed-in user.

What should you do?

Options:

A.

Configure enterprise applications to require user assignment and assign users to App1.

B.

Modify the app registration to use application permissions instead of delegated permissions.

C.

Add the required delegated Microsoft Graph permissions to the app registration and rely on user consent during sign-in.

D.

Grant admin consent to App1 for the required delegated permissions.

Question 2

You have an Azure virtual network named VNet1 that contains an Azure Bastion Subnet. VNet1 contains a subnet named Subnet1 Subnet1 contains multiple virtual machines.

You plan to deploy Azure Bastion to provide secure RDP access to the virtual machines on Subnet1. You associate a network security group (NSG) named NSG1 to Azure Bastion Subnet.

You need to configure rules for NSG1. The solution must meet the following requirements:

•Allow required inbound access to Azure Bastion from the internet.

•Allow user access to the virtual machines by using Azure Bastion.

Which TCP ports should you allow for the NSG1 rules? To answer, drag the appropriate ports to the correct rules. Each port may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Question # 2

Options:

Question 3

You have three internet-facing Azure App Service web apps named App1, App2, and App1 Each app uses built-in authentication.

App2 hosts a backend API.

Some corporate users can sign in to App2, even though they should NOT be able to use the API.

You need to restrict App2 access to assigned Microsoft Entra users and groups.

What should you configure for App2? To answer, drag the appropriate configurations to the correct methods. Each configuration may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Question # 3

Options:

Question 4

You have a management group named MG1 that contains two subscriptions named Sub1 and Sub2

Sub1 contains a resource group named RG-Exception and a resource group named RG1 that hosts Microsoft Foundry resources.

You need to assign an Azure policy to force new Foundry deployments in MG1 to use private endpoints. The solution must NOT restrict deployments in RG-Exception.

How should you configure the policy?

Options:

A.

Assign the policy to MG1 and exclude RG-Exception.

B.

Assign the policy to Sub1 and RG-Exception.

C.

Assign the policy to MG1 and RG-Exception.

D.

Assign the policy to Sub1 and exclude RG-Exception.

Question 5

You have an Azure Storage account named storage1 that hosts a blob container named container1.

You have an Azure Functions app named app1 that uses a managed identity.

You need to configure app1 to read, write, and delete blobs in container1. The solution must follow the principle of least privilege.

What should you do?

Options:

A.

Assign the Storage Account Contributor role to the managed identity of app1 at the scope of storage1.

B.

Assign the Storage Blob Delegator role to the managed identity of app1 at the scope of container1.

C.

Assign the Owner role to the managed identity of app1 at the scope of container1.

D.

Assign the Storage Blob Data Contributor role to the managed identity of app1 at the scope of container1.

Question 6

You have an Azure Container Instances container group named CG1 that has a DNS name of cg1.contoso.com. CG1 has the following configurations:

•A Linux container named container1 that serves HTTPS over TCP port 443 and hosts an application named App1

•A Linux container named container2 that listens on TCP port 5000 and is accessed only by App1

•A public IP address

A security review finds that external clients can reach TCP port 5000 by using the public IP address of CG1.

You need to meet the following requirements:

•Ensure that the external clients can access container1 only by using TCP port 443.

•Ensure that container1 can continue to access container2

What should you configure? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 6

Options:

Question 7

You have a Microsoft Defender External Attack Surface Management (Defender EASM) resource for a company named Contoso. Ltd.

You need to update the Defender EASM workflow to meet the following requirements:

•Assets from a business domain that Contoso no longer owns must be removed from inventory.

•Findings that do NOT apply to confirmed inventory must NOT affect reported counts.

What should you do for each requirement? To answer, drag the appropriate actions to the correct requirements. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Question # 7

Options:

Question 8

You have an Azure subscription that contains the following servers:

•200 virtual machines that run either Windows Server or Ubuntu Server

•50 Azure Arc enabled servers

You use Azure Policy to manage compliance across all the servers.

You need to enforce an organization-specific security baseline. The solution must meet the following requirements:

•Customize a built-in security baseline.

•Ensure that configuration changes to the servers are enforced automatically after the security baseline is deployed.

♦Minimize administrative effort.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 8

Options:

Question 9

You have a Microsoft Sentinel workspace named Workspace1

You have 100 on-premises servers that run Linux and have the Azure Monitor Agent installed.

You need to collect Syslog events from the Linux servers. The solution must meet the following requirements:

•Ensure that filtering occurs before data is written to Workspace1

•Reduce ingestion costs by excluding low value Syslog messages.

What should you include in the solution?

Options:

A.

An Advanced Security Information Model (ASIM) parser

B.

A data collection rule (DCR)

C.

An analytics rule

D.

A table-level filter and split transformation

Question 10

You have Microsoft Security Copilot agents that authenticate by using Microsoft Entra service principals.

You receive a Microsoft Defender alert triggered by the anomalous OAuth authentication of an agent ' s Microsoft Entra service principal.

You need to assess the impact of the agent identity and identify which resources are affected if the identity is abused for lateral movement The solution must minimize administrative effort.

What should you do?

Options:

A.

From Advanced hunting, create a query against the IdentityLogonEvents table to list all the sign-ins performed by the identity.

B.

From Attack paths, select the identity and view the blast radius.

C.

From AI Observability in Microsoft Purview Data Security Posture Management (DSPM), review the agent activity.

D.

From Microsoft Purview Audit, query the audit logs for all the role assignments granted to the identity.

E.

From Incidents, review incidents related to OAuth events reported by Microsoft Defender for Cloud Apps.

Question 11

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution: You create an analytics rule.

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 12

You need to implement the function apps to meet the technical requirements.

Which apps should you include in the implementation?

Options:

A.

Fa1 and Fa2 only

B.

Fa2 and Fa3 only

C.

Fa1 and Fa3 only

D.

Fa1, Fa2, and Fa3

Question 13

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You create a private endpoint on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 14

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You create a user-assigned managed identity, assign the identity to each virtual machine, and then add each managed identity to a role on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 15

You need to protect the applications hosted on AKS1. The solution must meet the technical requirements.

Which Defender for Cloud plan should you enable?

Options:

A.

Microsoft Defender for Servers

B.

Microsoft Defender for App Service

C.

Microsoft Defender for Containers

D.

Microsoft Defender for Resource Manager

E.

Microsoft Defender for Storage

Question 16

For each of the following statements, select Yes if the statement is true Otherwise, select No.

Question # 16

Options:

Question 17

You need to delegate a user to implement the planned change for Defender for Cloud. The solution must follow the principle of least privilege.

Which user should you choose?

Options:

A.

Admin1

B.

Admin2

C.

Admin3

D.

Admin4

Question 18

User1 has requested to use the AI Administrator role.

Which approvers can approve the request, and how long will User1 be an AI administrator after the role is approved? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 18

Options:

Question 19

You need to configure the AKS1 and ID 1 managed identities to meet the technical requirements. The solution must follow the principle of least privilege.

Which role should you assign to each identity? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 19

Options:

Question 20

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You add each virtual machine to a role on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Page: 1 / 7
Total 68 questions