Rate this post

[Sep 09, 2026] SC-500 Test Engine files, SC-500 Dumps PDF

Latest Microsoft SC-500 PDF and Dumps (2026) Free Exam Questions Answers

Q66. You have a Microsoft Defender External Attack Surface Management (Defender EASM) resource for a company named Contoso. Ltd.
You need to update the Defender EASM workflow to meet the following requirements:
*Assets from a business domain that Contoso no longer owns must be removed from inventory.
*Findings that do NOT apply to confirmed inventory must NOT affect reported counts.
What should you do for each requirement? To answer, drag the appropriate actions to the correct requirements. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

Q67. Drag and Drop Question
You have an Azure subscription named Sub1 that contains a storage account named storage1.
storage1 hosts a blob container named container1.
Sub1 is linked to a Microsoft Entra tenant that contains a security group named Group1.
You need to ensure that Group1 can use the Azure portal to view the blobs in container1. The solution must follow the principle of least privilege.
Which roles should you assign to Group1. To answer, drag the appropriate roles to the correct objects. Each role may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

Q68. You have an Azure subscription named Sub1 that contains multiple virtual machines and an Azure key vault named KV1.
Each virtual machine has a system-assigned managed identity. Sub1 has Microsoft Defender for Servers enabled. Defender for Servers has agentless scanning enabled.
Some virtual machines use managed disks that are encrypted by using customer-managed keys stored in KV1.
You discover that the affected virtual machines fail to return agentless scanning results in Microsoft Defender for Cloud.
You need to ensure that agentless scanning can analyze the virtual machines.
What should you do?

 
 
 
 
 

Q69. Case Study 1 – Contoso, Ltd.
Overview
Contoso, Ltd. is a consulting company that has a main office in San Francisco and a branch office in Dallas.
Contoso has a hybrid environment that contains on-premises servers connected to Azure, a Microsoft 365 E5 subscription, and an Azure subscription named Sub1.
Existing Environment. Microsoft Entra tenant
Contoso has a Microsoft Entra tenant named contoso.com that contains the users shown in the following table.

Existing Environment. On-premises environment
The on-premises network contains an Active Directory Domain Services (AD DS) forest that syncs with contoso.com. The forest contains a server named Server1 that runs Windows Server.
Existing Environment. Azure subscription
Sub1 contains the storage accounts shown in the following table.

Sub1 contains the virtual networks shown in the following table.

Sub1 contains the virtual machines shown in the following table.

The network interface of VM1 is associated with an application security group named ASG1.
Sub1 contains the resources shown in the following table.

Vault1 stores the objects shown in the following table.

Existing Environment. Privileged Identity Management (PIM) configuration You manage privileged roles by using Privileged Identity Management (PIM). The PIM role settings are configured as shown in the following table.

Existing Environment. Microsoft Sentinel configuration
Contoso has a Microsoft Sentinel workspace that contains the following tables.

Requirements. Planned changes
Contoso plans to implement the following changes:
– Integrate AKS1 with Vault1.
– Enable Microsoft Entra Kerberos authentication for all supported
storage.
– Configure auditing for sql1 by using the Azure portal and store audit logs in a centralized location.
Requirements. Technical requirements
Contoso identifies the following technical requirements:
– Protect Server1 by using file integrity monitoring.
– Protect AKS1 by using Microsoft Defender for Cloud.
– Configure Microsoft Sentinel to retain data for the maximum supported duration without changing the tier.
– Store objects used for authentication and encryption in Vault1 and
ensure that Vault1 regenerates the objects every 30 days, whenever
possible.
Hotspot Question
You need to configure Server1 to meet the technical requirements.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Q70. You have an Azure subscription named Sub1 that contains an Azure Kubernetes Service (AKS) cluster named cluster1 and an Azure container registry named ACR1 Sub1 has Microsoft Defender for Containers enabled, and runtime protection is active on cluster!
The developers at your company deploy pods that have elevated privileges, and the deployments are created in cluster1 You need to prevent pods with elevated privileges from being accepted by cluster!
What should you do?

 
 
 
 

Q71. You have an Azure virtual network named VNet1 that contains three subnets named Subnet1, Subnet2 and Subnet3. A single network security group (NSG) named NSG1 is associated with all the subnets. You have the following virtual machines:
*VM1 on Subnet1
*VM2 on Subnet2
VM3 on Subnet3
You create two application security groups named ASG1 and ASG2. VM2 is a member of ASG1, and VM3 is a member of ASG2.
You need to ensure that only VM2 can connect to VM3. The solution must continue to work if the private IP address of VM2 changes.
How should you configure the inbound rule on NSG1 ? To answer, drag the settings to the correct configurations. Each setting may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

Q72. You have an Azure subscription named Sub1. Sub1 contains 20 virtual machines that run Windows Server.
Sub1 has the Microsoft Defender for Cloud Defender Cloud Security Posture Management (CSPM) plan enabled.
You need to ensure that all the virtual machines are scanned automatically for known security flaws and misconfigurations.
What should you use?

 
 
 
 
 

Q73. Case Study 1 – Contoso, Ltd.
Overview
Contoso, Ltd. is a consulting company that has a main office in San Francisco and a branch office in Dallas.
Contoso has a hybrid environment that contains on-premises servers connected to Azure, a Microsoft 365 E5 subscription, and an Azure subscription named Sub1.
Existing Environment. Microsoft Entra tenant
Contoso has a Microsoft Entra tenant named contoso.com that contains the users shown in the following table.

Existing Environment. On-premises environment
The on-premises network contains an Active Directory Domain Services (AD DS) forest that syncs with contoso.com. The forest contains a server named Server1 that runs Windows Server.
Existing Environment. Azure subscription
Sub1 contains the storage accounts shown in the following table.

Sub1 contains the virtual networks shown in the following table.

Sub1 contains the virtual machines shown in the following table.

The network interface of VM1 is associated with an application security group named ASG1.
Sub1 contains the resources shown in the following table.

Vault1 stores the objects shown in the following table.

Existing Environment. Privileged Identity Management (PIM) configuration You manage privileged roles by using Privileged Identity Management (PIM). The PIM role settings are configured as shown in the following table.

Existing Environment. Microsoft Sentinel configuration
Contoso has a Microsoft Sentinel workspace that contains the following tables.

Requirements. Planned changes
Contoso plans to implement the following changes:
– Integrate AKS1 with Vault1.
– Enable Microsoft Entra Kerberos authentication for all supported
storage.
– Configure auditing for sql1 by using the Azure portal and store audit logs in a centralized location.
Requirements. Technical requirements
Contoso identifies the following technical requirements:
– Protect Server1 by using file integrity monitoring.
– Protect AKS1 by using Microsoft Defender for Cloud.
– Configure Microsoft Sentinel to retain data for the maximum supported duration without changing the tier.
– Store objects used for authentication and encryption in Vault1 and
ensure that Vault1 regenerates the objects every 30 days, whenever
possible.
You need to meet the technical requirements for Vault1.
Which object can you use?

 
 
 
 

Q74. Hotspot Question
You have a Microsoft Entra tenant that contains the users shown in the following table.

You have a location named HQ-Trusted that contains the IP address of the corporate network.
The tenant contains a Conditional Access policy named CA1 that has the following settings:
Assignments:

– Users or agents:
— Include: All users
— Exclude: Group1
Target resources:

– Resources (formerly cloud apps):
— Include: Office 365
Conditions:

– Client apps: Not configured
Access controls:

– Grant:
— Require multifactor authentication
– Grant:
— Require device to be marked as compliant
– For multiple controls:
— Require all the selected controls
The tenant contains a Conditional Access policy named CA2 that has the following settings:
Assignments:

– Users or agents:
— Include: All users
— Exclude: Group2
Target resources:

– Resources (formerly cloud apps):
— Include: All resources
Conditions:

– Locations:
— Configure: Yes
— Include: Any network or location
— Exclude: HQ-Trusted
Access controls:

– Grant:
— Block access
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Q75. Case Study 1 – Contoso, Ltd.
Overview
Contoso, Ltd. is a consulting company that has a main office in San Francisco and a branch office in Dallas.
Contoso has a hybrid environment that contains on-premises servers connected to Azure, a Microsoft 365 E5 subscription, and an Azure subscription named Sub1.
Existing Environment. Microsoft Entra tenant
Contoso has a Microsoft Entra tenant named contoso.com that contains the users shown in the following table.

Existing Environment. On-premises environment
The on-premises network contains an Active Directory Domain Services (AD DS) forest that syncs with contoso.com. The forest contains a server named Server1 that runs Windows Server.
Existing Environment. Azure subscription
Sub1 contains the storage accounts shown in the following table.

Sub1 contains the virtual networks shown in the following table.

Sub1 contains the virtual machines shown in the following table.

The network interface of VM1 is associated with an application security group named ASG1.
Sub1 contains the resources shown in the following table.

Vault1 stores the objects shown in the following table.

Existing Environment. Privileged Identity Management (PIM) configuration You manage privileged roles by using Privileged Identity Management (PIM). The PIM role settings are configured as shown in the following table.

Existing Environment. Microsoft Sentinel configuration
Contoso has a Microsoft Sentinel workspace that contains the following tables.

Requirements. Planned changes
Contoso plans to implement the following changes:
– Integrate AKS1 with Vault1.
– Enable Microsoft Entra Kerberos authentication for all supported
storage.
– Configure auditing for sql1 by using the Azure portal and store audit logs in a centralized location.
Requirements. Technical requirements
Contoso identifies the following technical requirements:
– Protect Server1 by using file integrity monitoring.
– Protect AKS1 by using Microsoft Defender for Cloud.
– Configure Microsoft Sentinel to retain data for the maximum supported duration without changing the tier.
– Store objects used for authentication and encryption in Vault1 and
ensure that Vault1 regenerates the objects every 30 days, whenever
possible.
You need to implement the planned change for the AKS1 integration.
What should you configure for AKS1?

 
 
 
 

Q76. You plan to deploy Microsoft 365 Copilot.
You discover that Copilot can access sensitive information in your Microsoft SharePoint Online libraries.
You need to automatically identify which SharePoint Online content has been shared between all internal users.
What should you create?

 
 
 
 

Q77. An organization is evaluating the security of AI-generated content before it is presented to end users. The goal is to detect harmful, unsafe, or policy-violating responses automatically. Which capability should be prioritized?

 
 
 
 

Q78. You have an Azure subscription named Sub1 that contains multiple virtual machines.
You have a Microsoft 365 E5 subscription that contains devices onboarded to Microsoft Defender for Endpoint.
You have an on-premises datacenter that contains multiple servers.
You plan to onboard all existing and future on-premises servers to Azure Arc.
You need to ensure that the Azure Arc-enabled servers are protected by using the same security features as the Microsoft 365 devices immediately after the servers are onboarded. The solution must minimize administrative effort.
What should you do?

 
 
 
 

Q79. You have an Azure subscription named Sub1 that contains an Azure Kubernetes Service (AKS) cluster named cluster1 and an Azure container registry named ACR1. Sub1 has Microsoft Defender for Containers enabled, and runtime protection is active on cluster1.
The developers at your company deploy pods that have elevated privileges, and the deployments are created in cluster1.
You need to prevent pods with elevated privileges from being accepted by cluster1.
What should you do?

 
 
 
 

Q80. Hotspot Question
You have an Azure subscription named Sub1 that contains 50 virtual machines. Sub1 has Microsoft Defender for Cloud enabled.
Sub1 contains an Azure key vault named KV1 and an Azure policy that enforces storing all secrets in KV1.
Occasionally, the developers at your company store plaintext tokens and SSH private keys on the virtual machines.
You need to configure Defender for Cloud to detect plaintext secrets on the virtual machines. The solution must minimize administrative changes to the virtual machines.
How should you configure Defender for Cloud? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Q81. Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals.
More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.
After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.
You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.
You have an Azure Storage account named storage. Public access from all networks is enabled for storage1.
You need to ensure that VM1 and VM2 can access storage1.
Solution: You create a private endpoint on storage1.
Does this meet the goal?

 
 

Q82. You have an Azure subscription named Sub1 that contains a storage account named storage1.
Sub1 has Microsoft Defender for Storage enabled. Defender for Storage has malware scanning enabled.
You need to configure a solution that automates the remediation of malware detected in storage1.
What should you include in the solution?

 
 
 
 

Q83. You have an Azure virtual network that contains 100 virtual machines and an Azure Firewall instance named FW1.
All the traffic from the virtual machines is routed through FW1.
You need to ensure that FW1 allows access to only a URL of updates contoso.com and blocks all other outbound traffic.
What should you use?

 
 
 
 

Q84. Case Study 2 – Fabrikam, Inc.
Overview
Fabrikam, Inc. is a consulting company. The company has a main office in New York City and branch offices in Amsterdam and Singapore.
Existing Environment. Network environment
The on-premises network contains a datacenter in each office.
Existing Environment. Cloud environment
Fabrikam has two Azure subscriptions named Sub1 and Sub2 and a Microsoft 365 subscription that includes Microsoft 365 E5 licenses.
All the subscriptions are linked to a Microsoft Entra tenant named fabrikam.com that contains the identities shown in the following table.

The tenant contains the groups shown in the following table.

All devices are enrolled in Microsoft Intune.
Existing Environment. Sub1 Resources
Sub1 contains a resource group named RG1 that contains the resources shown in the following table.

SQLServer1 uses Microsoft SQL Server authentication.
Sub1 has an Azure Web Application Firewall (WAF) named WAF1 that has the following types of rule sets:
– Bot Manager 1.1
– Azure-managed Default Rule Set (DRS)
Sub1 has the following compliance standards assigned in Microsoft Defender for Cloud:
– NIST SP 800-53 Rev. 4
– Microsoft cloud security benchmark (MCSB)
– System and Organization Controls (SOC) 2 Type 2
Existing Environment. Sub2 Resources
Sub2 contains a resource group named RG2.
Planned Changes and Requirements. Planned Changes
Fabrikam plans to implement the following changes:
– Deploy the following key vaults to RG1:
AKV2 in the West Europe Azure region

AKV3 in the Central US Azure region

AKV4 in the East US Azure region

– Deploy the following key vaults to RG2:
AKV5 in the East US region

– Configure VM1 to read data from storage1.
– Create function apps that have the following hosting plans:
Fa1: Flex Consumption hosting plan

Fa2: Consumption hosting plan

Fa3: Dedicated hosting plan

– For WAF1, implement rate limiting rules based on the request
location.
– Enable the NIST SP 800-53 Rev. 5 compliance standard in Defender for
Cloud.
– Create a new storage account named storage2 that supports Azure Table storage.
– Enforce multifactor authentication (MFA) when database administrators access SQLdb1.
– Implement ExpressRoute circuits to the on-premises network as shown
in the following table.

– For RG1, create a new Privileged Identity Management (PIM) eligible role assignment that assigns the Contributor role to supported groups.
Planned Changes and Requirements. Technical Requirements
Fabrikam has the following technical requirements:
– If VM1 is deleted, the permissions for VM1 must be removed
automatically.
– The AKS1 managed identity must only be able to pull images from
Registry1.
– The ID1 managed identity must be able to push images to and pull
images from Registry1.
– All the data in the storage accounts must be encrypted by using
Fabrikam-managed keys.
– All outbound traffic from the function apps to the on-premises
network must use ExpressRoute circuits.
– ExpressRoute connectivity between the on-premises network and the
Azure environment must be encrypted by using Layer 2 or Layer 3
encryption.
You need to implement the function apps to meet the technical requirements. Which apps should you include in the implementation?

 
 
 
 

Q85. Drag and Drop Question
You have a Microsoft Entra tenant.
You need to implement passwordless authentication. The solution must meet the following requirements:
– Users can sign in without a password by using a mobile device.
– New users that sign in for the first time must use a helpdesk-issued
sign-in method that expires.
Which authentication method should you enable for each requirement? To answer, drag the appropriate methods to the correct requirements. Each method may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.


Pass Your Microsoft Certified: Information Security Administrator Associate SC-500 Exam on Sep 09, 2026 with 136 Questions: https://www.braindumpstudy.com/SC-500_braindumps.html

         

Related Links: myportal.utt.edu.tt www.stes.tyc.edu.tw www.stes.tyc.edu.tw myportal.utt.edu.tt www.stes.tyc.edu.tw www.stes.tyc.edu.tw