Exit demo SC-500 Microsoft Certified: Cloud and AI Security Engineer Associate PDF format · free preview

Microsoft SC-500 - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/sc-500.html

Question 1
Single choice

You need to protect the applications hosted on AKS1. The solution must meet the technical requirements.

Which Defender for Cloud plan should you enable?

A.

Microsoft Defender for Servers

B.

Microsoft Defender for App Service

C.

Microsoft Defender for Containers

D.

Microsoft Defender for Resource Manager

E.

Microsoft Defender for Storage

Question 2
Hotspot

HOTSPOT

User1 has requested to use the AI Administrator role.

Which approvers can approve the request, and how long will User1 be an AI administrator after the role is approved? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question 3
Hotspot

HOTSPOT

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

stem image

Question 4
Hotspot

HOTSPOT

You need to configure Server1 to meet the technical requirements.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

stem image

Question 5
Single choice

You need to implement the planned change for storage2. The solution must meet the technical requirements for storage encryption.

What should you do?

A.

Enable purge protection for storage2.

B.

Create an encryption scope in storage2.

C.

Configure storage2 to use an account encryption key.

D.

Assign an Azure role-based access control (Azure RBAC) role to storage2.

Question 6
Single choice

You need to implement the function apps to meet the technical requirements.

Which apps should you include in the implementation?

A.

Fa1 and Fa2 only

B.

Fa2 and Fa3 only

C.

Fa1 and Fa3 only

D.

Fa1, Fa2, and Fa3

Question 7
Single choice

You need to delegate a user to implement the planned change for Defender for Cloud. The solution must follow the principle of least privilege.

Which user should you choose?

A.

Admin1

B.

Admin2

C.

Admin3

D.

Admin4

Question 8
Multiple choice

You need to implement the planned change for SQLdb1.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A.

Create a compliance policy.

B.

Configure Microsoft Entra authentication for SQLServer1.

C.

Create a Conditional Access policy.

D.

Configure Federated client identity for SQLdb1.

E.

Configure a user-assigned managed identity for SQLdb1

Question 9
Single choice

You have an Azure SQL Database logical server named Server1 that contains a database named DB1.

You need to configure authentication for Server1 to meet the following requirements:

SQL authentication cannot be used for any databases on Server1. The solution must be enforced centrally at the server level.

What should you do?

A.

Configure a Microsoft Entra administrator for Server1.

B.

Enable a managed identity for Server1.

C.

Enable Microsoft Entra-only authentication for Server1.

D.

Remove SQL logins from DB1.

Question 10
Single choice

You have a Microsoft Entra tenant that has the following configurations:

User consent for applications is disabled. Only administrators can grant permissions to applications.

You register an application named App1 that uses delegated Microsoft Graph permissions.

You need to configure App1 to meet the following requirements:

Enable user sign-ins without interactive consent prompts. Enable App1 to access Microsoft Graph on behalf of the signed-in user.

What should you do?

A.

Configure enterprise applications to require user assignment and assign users to App1.

B.

Modify the app registration to use application permissions instead of delegated permissions.

C.

Add the required delegated Microsoft Graph permissions to the app registration and rely on user consent during sign-in.

D.

Grant admin consent to App1 for the required delegated permissions.

Showing 10 of 93 questions · Unlock the full set