Pre-Winter Sale Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Microsoft SC-500 Microsoft Certified: Cloud and AI Security Engineer Associate Exam Practice Test

Page: 1 / 14
Total 135 questions

Microsoft Certified: Cloud and AI Security Engineer Associate Questions and Answers

Question 1

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution: You create an automation rule.

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 2

You need to implement the planned change for storage2 The solution must meet the technical requirements for storage encryption.

What should you do?

Options:

A.

Enable purge protection for storage2.

B.

Create an encryption scope in storage2.

C.

Configure storage2 to use an account encryption key.

D.

Assign an Azure role-based access control (Azure RBAC) role to storage2.

Question 3

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You create a private endpoint on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 4

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You add each virtual machine to a role on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 5

User1 has requested to use the AI Administrator role.

Which approvers can approve the request, and how long will User1 be an AI administrator after the role is approved? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 5

Options:

Question 6

You need to delegate a user to implement the planned change for Defender for Cloud. The solution must follow the principle of least privilege.

Which user should you choose?

Options:

A.

Admin1

B.

Admin2

C.

Admin3

D.

Admin4

Question 7

You need to configure the AKS1 and ID 1 managed identities to meet the technical requirements. The solution must follow the principle of least privilege.

Which role should you assign to each identity? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 7

Options:

Question 8

You need to configure Microsoft Sentinel to meet the technical requirements.

To what should you set Analytics retention for DnsEvents?

Options:

A.

2 years

B.

12 years

C.

180 days

D.

1 year

E.

6 years

Question 9

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution: You create a playbook

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 10

Note. This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem

After you answer a question in this section, you will NOT be able to return. As a result these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution You create a hunting query.

Does this meet the goal’

Options:

A.

Yes

B.

No

Question 11

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution: You create an analytics rule.

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 12

For which storage accounts can you implement the planned changes for storage?

Options:

A.

storage1, storage2, storage3, and storage4

B.

storage1, storage2, and storage4 only

C.

storage2 and storage4 only

D.

storage1 and storage3 only

E.

storage2, storage3, and storage4 only

F.

storage1 only

Question 13

You need to protect the applications hosted on AKS1. The solution must meet the technical requirements.

Which Defender for Cloud plan should you enable?

Options:

A.

Microsoft Defender for Servers

B.

Microsoft Defender for App Service

C.

Microsoft Defender for Containers

D.

Microsoft Defender for Resource Manager

E.

Microsoft Defender for Storage

Question 14

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You add each virtual machine to a security group, and then add the security group to a role on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 15

You need to implement the function apps to meet the technical requirements.

Which apps should you include in the implementation?

Options:

A.

Fa1 and Fa2 only

B.

Fa2 and Fa3 only

C.

Fa1 and Fa3 only

D.

Fa1, Fa2, and Fa3

Question 16

You need to implement the planned change for the AKS1 integration.

What should you configure for AKS1?

Options:

A.

application scaling

B.

a workload identity

C.

Secrets Store CSI Driver

D.

Kubernetes role-based access control (Kubernetes RBAC)

Question 17

You need to configure Server1 to meet the technical requirements.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 17

Options:

Question 18

You need to implement the planned change for SQLdb1

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point

Options:

A.

Create a compliance policy.

B.

Configure Microsoft Entra authentication for SQLServer1.

C.

Create a Conditional Access policy.

D.

Configure federated client identity for SQLdb1.

E.

Configure a user-assigned managed identity for SQLdb1.

Question 19

For each of the following statements, select Yes if the statement is true Otherwise, select No.

Question # 19

Options:

Question 20

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You create a user-assigned managed identity, assign the identity to each virtual machine, and then add each managed identity to a role on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 21

You have a Microsoft Security Copilot workspace named Workspace1 that is used by Security Operations Center (SOC) analysts and security administrators.

The SOC analysts use only the Security Copilot standalone experience, and the security administrators access Security Copilot from the Microsoft Defender portal.

A new Security Copilot workspace named Workspace2 is created for the security administrators. Workspace2 is assigned a capacity of five security compute units.

You need to ensure that Security Copilot usage for the SOC analysts is allocated to Workspace1 and Security Copilot usage for the security administrators is allocated to Workspace2.

What should you do?

Options:

A.

Configure Workspace2 for embedded agent traffic.

B.

Increase the capacity of Workspace2.

C.

Assign the Workspace1 capacity to Workspace2.

D.

Configure Workspace1 for embedded agent traffic.

Question 22

You have an Azure subscription named Sub1 that contains multiple virtual machines. Sub1 has the Microsoft Defender Cloud Security Posture Management (CSPM) plan enabled.

You discover that Defender for Cloud falls to identify plaintext connection strings and SSH keys stored on the virtual machines.

You need to ensure that secrets can be identified on the virtual machines.

What should you do?

Options:

A.

Configure the Defender for Cloud data connector in Microsoft Sentinel.

B.

Enable agentless machine scanning.

C.

Deploy the Azure Monitor Agent to all the virtual machines.

D.

Enable Microsoft Defender for Key Vault.

Question 23

You have an Azure subscription.

You need to create and deploy an Azure policy that meets the following requirements:

•When a new virtual machine is deployed, automatically install a custom security extension.

•Trigger an autogenerated remediation task for non-compliant virtual machines to install the extension.

What should you include in the policy? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 23

Options:

Question 24

You have an Azure subscription that contains the virtual networks shown in the following table.

Question # 24

NSG1 and NSG2 both have default rules only.

The subscription contains the virtual machines shown in the following table.

Question # 24

Options:

Question 25

You have a Microsoft Foundry project that contains a model deployment named Deployment1.

Deployment1 contains an agent named Agent1 that uses an existing default guardrail configuration.

You discover that Agent1 generates tool calls that contain harmful language.

You need to ensure that Agent1 responses containing harmful content are prevented from running. The solution must prevent changes to the configuration of Deployment1.

What should you do?

Options:

A.

Create an automatic evaluation of the dataset of Agent1.

B.

Create a custom guardrail and assign it directly to Agent1.

C.

Fine-tune the model of Deployment1.

D.

Create a red teaming run for Agent1.

Question 26

You use Microsoft Security Copilot.

Security Copilot contributors currently create custom plugins for their own sessions and manage organization-wide custom plugins.

You need to prevent the contributors from managing the organization-wide custom plugins. The solution must NOT affect the contributors ' ability to create custom plugins for their own sessions.

What should you select in the Plugin settings?

Options:

A.

Contributors and Owners at the tenant scope

B.

Owners only at the user scope

C.

Contributors and Owners at the user scope

D.

Owners only at the tenant scope

Question 27

You have a Microsoft 365 tenant that uses Microsoft Security Copilot and Microsoft Defender XDR.

Access to Microsoft Defender XDR is managed by using Microsoft entra global roles.

The Phishing triage Agent is available in Microsoft Defender. The required agent prerequisites and approvals are complete

Two users will perform the following tasks:

• User1 will enable and manage the Phishing Triage Agent settings.

• User2 will use Security Copilot in Microsoft Defender XDR to manage phishing incidents identified by the agent.

You need to assign the least-privileged built in Microsoft Entra role and Security Copilot role combination to each us Which roles should you assign to each user? To answer, select the appropriate options in the answer area.

Question # 27

Options:

Question 28

You have an Azure subscription that contains an Azure SQL Database logical server named SQL1 and an Azure virtual machine named VM1. VM1 uses a private IP address only. The Firewall and virtual networks settings for SQL1 are shown in the following exhibit.

Question # 28

You need to ensure that VM1 can connect to SQL1. The solution must use the principle of least privilege.

What should you do on the SQL1 Firewall and virtual network settings?

Options:

A.

Create a new firewall rule.

B.

Set Allow Azure services and resources to access this server to Yes.

C.

Add an existing virtual network.

D.

Set Connection Policy to Proxy.

Question 29

You use Azure Virtual Network Manager to manage multiple virtual networks in a network group named Group1

You discover that the virtual machines in Group1 are accessible from the internet by using TCP port 3389.

You need to block inbound TCP 3389 from the internet across all the virtual networks in Group1 The solution must minimize administrative effort.

What should you use?

Options:

A.

A connectivity configuration

B.

A security admin configuration

C.

A user-defined route (UDR)

D.

A network security group (NSG)

Question 30

You have an Azure Storage account that contains a blob container named container 1 and a client application named App1. You need to enable App1 access to container1 by using Microsoft Entra authentication. What should you do ' To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Question # 30

Options:

Question 31

You have a Microsoft Entra tenant that has the following configurations:

•User consent for applications is disabled.

•Only administrators can grant permissions to applications.

You register an application named App1 that uses delegated Microsoft Graph permissions.

You need to configure App1 to meet the following requirements:

•Enable user sign-ins without interactive consent prompts.

•Enable App1 to access Microsoft Graph on behalf of the signed-in user.

What should you do?

Options:

A.

Configure enterprise applications to require user assignment and assign users to App1.

B.

Modify the app registration to use application permissions instead of delegated permissions.

C.

Add the required delegated Microsoft Graph permissions to the app registration and rely on user consent during sign-in.

D.

Grant admin consent to App1 for the required delegated permissions.

Question 32

You have a Microsoft Entra tenant that contains the users shown in the following table.

Question # 32

The tenant contains a Conditional Access policy named CA1 that has the following settings:

Assignments:

o Users or agents:

- Include: Directory roles: Global Administrator

Target resources:

o Resources (formerly cloud apps):

- Include: All resources

Conditions:

o Locations:

- Configure: Yes

- Include: Any network or location

Access controls:

o Grant:

- Require multifactor authentication

o Grant:

- Require device to be marked as compliant

o For multiple controls:

- Require all the selected controls

The tenant contains a Conditional Access policy named CA2 that has the following settings:

Assignments:

o Users or agents:

- Include: Users and groups: Group1

Target resources:

o Resources (formerly cloud apps)

- Include: Select resources: Office 365

Conditions:

o Locations:

- Configure: Yes

- Include: Any network or location

Access controls:

o Grant:

- Require multifactor authentication

o Grant:

- Require app protection policy

o For multiple controls:

- Require one of the selected controls

The users perform the following tasks:

User1 signs in to Microsoft 365 from a home network by using Microsoft Outlook on a noncompliant device.

User2 signs in to Microsoft 365 without an app protection policy by using a noncompliant device.

User3 signs in to the Azure portal from a home network by using a compliant device.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Question # 32

Options:

Question 33

You have an Azure virtual network named VNet1 that contains an Azure Bastion Subnet. VNet1 contains a subnet named Subnet1 Subnet1 contains multiple virtual machines.

You plan to deploy Azure Bastion to provide secure RDP access to the virtual machines on Subnet1. You associate a network security group (NSG) named NSG1 to Azure Bastion Subnet.

You need to configure rules for NSG1. The solution must meet the following requirements:

•Allow required inbound access to Azure Bastion from the internet.

•Allow user access to the virtual machines by using Azure Bastion.

Which TCP ports should you allow for the NSG1 rules? To answer, drag the appropriate ports to the correct rules. Each port may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Question # 33

Options:

Question 34

You have an Azure key vault named KV1 that uses role-based access control (RBAC) authorization KV1 stores database connection strings for an Azure App Service web app named App1.

You enable a firewall on KV1 and allow access to KV1 from only the virtual network that contains App1.

You need to ensure that App1 can retrieve secrets from KV1 without using credentials stored in the application configuration.

What should you create?

Options:

A.

An access policy for KV1

B.

An app registration for App1

C.

A private endpoint for KV1

D.

A managed identity for App1

Question 35

You are configuring a new Microsoft Sentinel workspace named Workspace1.

You have an external IT Service Management (ITSM) system that is NOT supported by any Microsoft Sentinel solutions in Azure Marketplace.

You need to ensure that Workspace1 creates service tickets in the ITSM system for all new security incidents.

What should you create?

Options:

A.

A playbook

B.

A workbook

C.

A watchlist

D.

An analytics rule

Question 36

You have an Azure subscription named Sub1. Sub1 contains 20 virtual machines that run Windows Server.

Sub1 has the Microsoft Defender for Cloud Defender Cloud Security Posture Management (CSPM) plan enabled.

You need to ensure that all the virtual machines are scanned automatically for known security flaws and misconfigurations.

What should you use?

Options:

A.

Attack path analysis

B.

Microsoft Cloud Security Benchmark (MCSB)

C.

Cloud security explorer

D.

Just-in-time (JIT) VM access

E.

Vulnerability assessment on the virtual machines

Question 37

You have a Microsoft Entra tenant that contains a group named Group1.

You plan to target Group1 to use the Microsoft Authenticator authentication method.

You need to ensure that the members in Group1 can use the Authenticator app as their primary authentication method.

What should you do?

Options:

A.

Enable one-time passcodes in Authenticator for Group1.

B.

Revoke the sessions for the Group1 members.

C.

Enable Authenticator push authentication mode for Group1.

D.

Enable the Authenticator passwordless authentication method for Group1.

Question 38

You have three on-premises apps named App1, App2, and App3 that are configured in Microsoft Entra Private Access as shown in the following table.

Question # 38

You have the users shown in the following table.

Question # 38

The Global Secure Access client is deployed to all user devices.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Question # 38

Options:

Question 39

You have an Azure subscription that contains the custom roles shown in the following table.

Question # 39

In the Azure portal, you plan to create new custom roles by cloning existing roles Ihe new roles will be configured as shown in following table.

Question # 39

Options:

Question 40

You have an Azure subscription named Sub1 that contains an Azure Kubernetes Service (AKS) cluster named cluster1 and an Azure container registry named ACR1 Sub1 has Microsoft Defender for Containers enabled, and runtime protection is active on cluster!

The developers at your company deploy pods that have elevated privileges, and the deployments are created in cluster1

You need to prevent pods with elevated privileges from being accepted by cluster!

What should you do?

Options:

A.

Create an Azure Policy for cluster1.

B.

Enable agentless discovery for Kubernetes in Defender for Containers.

C.

Configure runtime threat protection alerts for privileged container activity.

D.

Enable vulnerability assessment for images in ACR1.

Page: 1 / 14
Total 135 questions