Month End Special Sale - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 75first

Page: 1 / 4
Total 40 questions
Exam Code: SC-500                Update: Sep 29, 2026
Exam Name: Microsoft Certified: Cloud and AI Security Engineer Associate

Microsoft Microsoft Certified: Cloud and AI Security Engineer Associate SC-500 Exam Dumps: Updated Questions & Answers (September 2026)

Question # 1

For each of the following statements, select Yes if the statement is true Otherwise, select No.

Question # 2

You need to configure the AKS1 and ID 1 managed identities to meet the technical requirements. The solution must follow the principle of least privilege.

Which role should you assign to each identity? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 3

You need to implement the planned change for SQLdb1

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point

A.

Create a compliance policy.

B.

Configure Microsoft Entra authentication for SQLServer1.

C.

Create a Conditional Access policy.

D.

Configure federated client identity for SQLdb1.

E.

Configure a user-assigned managed identity for SQLdb1.

Question # 4

You have an Azure subscription that has the Microsoft Defender for Cloud Foundational Cloud Security Posture Management (CSPM) plan enabled.

You have an Amazon Web Services (AWS) account connected to Defender for Cloud for posture management.

In Defender for Cloud, security recommendations for the resources in Azure and AWS have a risk level of Not evaluated.

You need to ensure that Defender for Cloud assigns a risk level to the recommendations.

What should you do?

A.

Onboard all the virtual machines in the AWS account to Azure Arc.

B.

Enable Microsoft Defender for Servers Plan 2.

C.

Assign the CIS AWS Foundations v3.0.0 standard to the AWS account.

D.

Enable the Defender CSPM plan.

Question # 5

You have an Azure subscription.

You need to deploy an Azure virtual WAN to meet the following requirements:

•Create three secured virtual hubs located in the East US. West US, and North Europe Azure regions.

•Ensure that security rules sync between the regions.

What should you use?

A.

Azure Network Function Manager

B.

Azure Firewall Manager

C.

Azure Virtual Network Manager

D.

Azure Front Door

Question # 6

The subscription contains the virtual machines shown in the following table.

On Nl1I, you configure an application security group named ASG1.

On which other network interfaces can you configure ASG1?

A.

NIC2 only

B.

NIC2 and NlC3 only

C.

NIC2, NIC3, and NIC4 only

D.

NIC2, N1C3, NIC4, and NIC5

Question # 7

You have an Azure Functions app named App1 that uses an HTTP trigger, runs on an Elastic Premium plan, and uses virtual network integration.

A partner application sends requests to App1 from a public IP address of xxx.xxx.xxx.xx.

You need to ensure that the requests are accepted from only xxx.xxx.xxx.xx.

What should you do?

A.

Deploy an Azure Bastion host.

B.

Create a private endpoint for App1 and disable public network access.

C.

Apply a network security group (NSG) to a dedicated subnet for virtual network integration.

D.

Configure an inbound access restriction on App1.

E.

Deploy an Azure NAT Gateway.

Question # 8

You have an Azure subscription that has Microsoft Defender for Cloud enabled.

You have an Amazon Web Services (AWS) account connected to Defender for Cloud that has the Defender Cloud Security Posture Management (CSPM) plan enabled.

You need to identify the potential impact of security incidents that exploit multiple risks reported by Defender CSPM.

What should you use?

A.

Regulatory compliance

B.

Cloud security explorer

C.

Security recommendations

D.

Attack path analysis

Question # 9

You have an Azure subscription.

You need to create and deploy an Azure policy that meets the following requirements:

•When a new virtual machine is deployed, automatically install a custom security extension.

•Trigger an autogenerated remediation task for non-compliant virtual machines to install the extension.

What should you include in the policy? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 10

You have an Azure subscription named Sub1 that contains an Azure Kubernetes Service (AKS) cluster named cluster1 and an Azure container registry named ACR1 Sub1 has Microsoft Defender for Containers enabled, and runtime protection is active on cluster!

The developers at your company deploy pods that have elevated privileges, and the deployments are created in cluster1

You need to prevent pods with elevated privileges from being accepted by cluster!

What should you do?

A.

Create an Azure Policy for cluster1.

B.

Enable agentless discovery for Kubernetes in Defender for Containers.

C.

Configure runtime threat protection alerts for privileged container activity.

D.

Enable vulnerability assessment for images in ACR1.

Page: 1 / 4
Total 40 questions

Most Popular Certification Exams

Payment

       

Contact us

Site Secure

mcafee secure

TESTED 29 Sep 2026