Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: chrismas

Free Practice Questions for the Microsoft Certified: Information Security Administrator Associate SC-500 Exam (2026 Updated)

At Marks4sure, we are dedicated to providing IT professionals with the most accurate and reliable preparation materials for the Microsoft SC-500 exam. To support your certification journey, we have made a selection of our premium 2026 Microsoft Certified: Information Security Administrator Associate practice questions and answers available completely free. You can take this practice test as many times as you need. Every question includes a detailed, expertly verified explanation to ensure you fully grasp the core security concepts before test day.

Questions 4

You have a Microsoft Entra tenant that contains a group named Group1.

You plan to target Group1 to use the Microsoft Authenticator authentication method.

You need to ensure that the members in Group1 can use the Authenticator app as their primary authentication method.

What should you do?

Options:

A.

Enable one-time passcodes in Authenticator for Group1.

B.

Revoke the sessions for the Group1 members.

C.

Enable Authenticator push authentication mode for Group1.

D.

Enable the Authenticator passwordless authentication method for Group1.

Buy Now
Questions 5

You have an Azure virtual network named VNet1 that contains a subnet named Subnet! A network security group named NSG1 is associated with Subnet1.

Vou have a storage account named storage1.

You need to ensure that access from Subnet1 to storage! uses a private IP address in Subnet1 and ran be filtered by NSG1 Public network access to storage1 must be disabled.

What should you create?

Options:

A.

a user-defined route (UDR)

B.

a service endpoint

C.

a private endpoint

D.

an Azure Private link service

Buy Now
Questions 6

You have a Microsoft Sentinel workspace named Workspace1

You have 100 on-premises servers that run Linux and have the Azure Monitor Agent installed.

You need to collect Syslog events from the Linux servers. The solution must meet the following requirements:

•Ensure that filtering occurs before data is written to Workspace1

•Reduce ingestion costs by excluding low value Syslog messages.

What should you include in the solution?

Options:

A.

An Advanced Security Information Model (ASIM) parser

B.

A data collection rule (DCR)

C.

An analytics rule

D.

A table-level filter and split transformation

Buy Now
Questions 7

You have an Azure key vault named Vault1 that stores the resources shown in the following table.

SC-500 Question 7

Which resources support the creation of a rotation policy?

Options:

A.

Key1 only

B.

Cert1 only

C.

Key1 and Secret1 only

D.

Secre1 and Cert1 only

E.

Secret1 and Cert1 only

F.

Key1, Secre1, end Cert1

Buy Now
Questions 8

You have an Azure subscription that contains the following resources:

•An Azure SQL Database logical server named Server1 that contains a database named DB1

•An Azure SQL Managed Instance named Instance1 that contains a database named DB2

You need to configure database auditing. The solution must meet the following requirements:

•Ensure that audit data is centrally available in a location that supports for KQL queries.

•Minimize ongoing administrative effort as additional databases are added.

What should you configure? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

SC-500 Question 8

Options:

Buy Now
Questions 9

You have an Azure subscription that contains a resource group named RG1. RG1 contains a storage account named storage1. You have two custom Azure roles named Role1 and Role2 that are scoped to RG1. The permissions for Role1 are shown in the following JSON code.

SC-500 Question 9

SC-500 Question 9

Options:

Buy Now
Questions 10

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You add each virtual machine to a role on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 11

You have an Azure Storage account named storage1 that contains Azure Files shares.

You have an application named App1 that uses a system-assigned managed identity to access the shares.

Administrators access the shares by using storage account keys.

You need to ensure that App1 access the shares without using the storage account keys.

What should you do on storage1?

Options:

A.

Store the storage account access keys in Azure Key Vault and regenerate them periodically.

B.

Set Allow storage account key access to Disabled.

C.

Select Default to Microsoft Entra authorization in the Azure portal.

D.

Assign the Storage File Data Privileged Reader role to the managed identity of App1.

Buy Now
Questions 12

You plan to deploy Microsoft 365 Copilot

You discover that Copilot can access sensitive information in your Microsoft SharePoint Online libraries. You need to automatically identify which SharePoint Online content has be*»n shared between all internal users-What should you create?

Options:

A.

a Conditional Access policy that requires multifactor authentication (MFA) for SharePoint Online

B.

a Microsoft Purview Data Security Posture Management (DSPM) remediation action

C.

a Microsoft Purview data loss prevention IDLP) policy in audit mode for SharePoint Online

D.

a SharePoint Advanced Management (SAM) Data access governance report

Buy Now
Questions 13

You have an Azure virtual network that contains 100 virtual machines and an Azure Firewall instance named FW1.

All the traffic from the virtual machines is routed through FW1.

You need to ensure that FW1 allows access to only a URL of updates contoso.com and blocks all other outbound traffic.

What should you use?

Options:

A.

An inbound NAT rule

B.

An application rule

C.

An outbound NAT rule

D.

A network rule

Buy Now
Questions 14

You have an Azure key vault named KV1 that uses role-based access control (RBAC) for data plane authorization.

You have a user named User1 and an Azure App Service web app named App1 that has a system-assigned managed identity.

You need to configure authorization to meet the following requirements:

•App1 must be able to retrieve secrets from KV1.

•User1 must manage the KV1 settings without accessing secret values.

The solution must follow the principle of least privilege.

Which role should you assign to each identity for KV1? To answer, drag the appropriate roles to the correct identities. Each role may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

SC-500 Question 14

Options:

Buy Now
Questions 15

You have a Microsoft Entra tenant that contains the users shown in the following table.

SC-500 Question 15

The tenant contains a Conditional Access policy named CA1 that has the following settings:

Assignments:

o Users or agents:

- Include: Directory roles: Global Administrator

Target resources:

o Resources (formerly cloud apps):

- Include: All resources

Conditions:

o Locations:

- Configure: Yes

- Include: Any network or location

Access controls:

o Grant:

- Require multifactor authentication

o Grant:

- Require device to be marked as compliant

o For multiple controls:

- Require all the selected controls

The tenant contains a Conditional Access policy named CA2 that has the following settings:

Assignments:

o Users or agents:

- Include: Users and groups: Group1

Target resources:

o Resources (formerly cloud apps)

- Include: Select resources: Office 365

Conditions:

o Locations:

- Configure: Yes

- Include: Any network or location

Access controls:

o Grant:

- Require multifactor authentication

o Grant:

- Require app protection policy

o For multiple controls:

- Require one of the selected controls

The users perform the following tasks:

User1 signs in to Microsoft 365 from a home network by using Microsoft Outlook on a noncompliant device.

User2 signs in to Microsoft 365 without an app protection policy by using a noncompliant device.

User3 signs in to the Azure portal from a home network by using a compliant device.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

SC-500 Question 15

Options:

Buy Now
Questions 16

You have a Microsoft Sentinel-enabled Log Analytics workspace named Workspace1.

Your company receives JSON security events from a software as a service (SaaS) application.

You plan to create a custom Microsoft Sentinel data connector.

You need to prepare Workspace1 for the incoming JSON data.

What should you do first?

Options:

A.

Configure a diagnostic setting for the SaaS application.

B.

Install a built-in Microsoft Sentinel data connector.

C.

Create a custom log table in Workspace1.

D.

Create an analytics rule in Microsoft Sentinel.

Buy Now
Questions 17

You have Microsoft Security Copilot agents that authenticate by using Microsoft Entra service principals.

You receive a Microsoft Defender alert triggered by the anomalous OAuth authentication of an agent ' s Microsoft Entra service principal.

You need to assess the impact of the agent identity and identify which resources are affected if the identity is abused for lateral movement The solution must minimize administrative effort.

What should you do?

Options:

A.

From Advanced hunting, create a query against the IdentityLogonEvents table to list all the sign-ins performed by the identity.

B.

From Attack paths, select the identity and view the blast radius.

C.

From AI Observability in Microsoft Purview Data Security Posture Management (DSPM), review the agent activity.

D.

From Microsoft Purview Audit, query the audit logs for all the role assignments granted to the identity.

E.

From Incidents, review incidents related to OAuth events reported by Microsoft Defender for Cloud Apps.

Buy Now
Questions 18

You have a Microsoft Entra tenant that contains the users shown in the following table.

SC-500 Question 18

You have a Microsoft Security Copilot workspace.

From Microsoft Security Store, you plan to deploy a partner-built agent named Agent1 that requires access to Microsoft Intune.

When User1 selects Agent1, the Get agent option is unavailable.

You need to enable User1 to complete the agent setup. The solution must follow the principle of least privilege.

What should you do first?

Options:

A.

From Security Copilot, create an agent identity for Agent1.

B.

From Security Copilot, configure the required data source for Agent1.

C.

Assign User1 the AI Administrator role in Microsoft Entra.

D.

Assign User1 the Agent ID Administrator role in Microsoft Entra.

E.

Instruct User2 to approve the agent setup.

Buy Now
Questions 19

You use Azure Virtual Network Manager to manage multiple virtual networks organized into two network groups named Production and Development.

You need to configure Virtual Network Manager to meet the following requirements:

Allow traffic between all the virtual networks in Production.

Block traffic between Development and Production.

What should you use for each requirement? To answer, drag the components to the correct requirements. Each component may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

SC-500 Question 19

Options:

Buy Now
Questions 20

You have an Azure subscription.

You need to deploy an Azure virtual WAN to meet the following requirements:

•Create three secured virtual hubs located in the East US. West US, and North Europe Azure regions.

•Ensure that security rules sync between the regions.

What should you use?

Options:

A.

Azure Network Function Manager

B.

Azure Firewall Manager

C.

Azure Virtual Network Manager

D.

Azure Front Door

Buy Now
Questions 21

You have an Azure subscription that contains a blob container named cont1. Con1 ' has the access policies shown in the following exhibit.

SC-500 Question 21

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

SC-500 Question 21

Options:

Buy Now
Questions 22

You need to implement the planned change for SQLdb1

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point

Options:

A.

Create a compliance policy.

B.

Configure Microsoft Entra authentication for SQLServer1.

C.

Create a Conditional Access policy.

D.

Configure federated client identity for SQLdb1.

E.

Configure a user-assigned managed identity for SQLdb1.

Buy Now
Questions 23

You need to implement the planned change for storage2 The solution must meet the technical requirements for storage encryption.

What should you do?

Options:

A.

Enable purge protection for storage2.

B.

Create an encryption scope in storage2.

C.

Configure storage2 to use an account encryption key.

D.

Assign an Azure role-based access control (Azure RBAC) role to storage2.

Buy Now
Questions 24

Note. This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem

After you answer a question in this section, you will NOT be able to return. As a result these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution You create a hunting query.

Does this meet the goal’

Options:

A.

Yes

B.

No

Buy Now
Questions 25

You need to configure the AKS1 and ID 1 managed identities to meet the technical requirements. The solution must follow the principle of least privilege.

Which role should you assign to each identity? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

SC-500 Question 25

Options:

Buy Now
Questions 26

You need to protect the applications hosted on AKS1. The solution must meet the technical requirements.

Which Defender for Cloud plan should you enable?

Options:

A.

Microsoft Defender for Servers

B.

Microsoft Defender for App Service

C.

Microsoft Defender for Containers

D.

Microsoft Defender for Resource Manager

E.

Microsoft Defender for Storage

Buy Now
Questions 27

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You create a user-assigned managed identity, assign the identity to each virtual machine, and then add each managed identity to a role on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 28

User1 has requested to use the AI Administrator role.

Which approvers can approve the request, and how long will User1 be an AI administrator after the role is approved? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

SC-500 Question 28

Options:

Buy Now
Questions 29

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution: You create an analytics rule.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 30

You need to configure Server1 to meet the technical requirements.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

SC-500 Question 30

Options:

Buy Now
Questions 31

You need to implement the function apps to meet the technical requirements.

Which apps should you include in the implementation?

Options:

A.

Fa1 and Fa2 only

B.

Fa2 and Fa3 only

C.

Fa1 and Fa3 only

D.

Fa1, Fa2, and Fa3

Buy Now
Questions 32

You need to configure Microsoft Sentinel to meet the technical requirements.

To what should you set Analytics retention for DnsEvents?

Options:

A.

2 years

B.

12 years

C.

180 days

D.

1 year

E.

6 years

Buy Now
Questions 33

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You add each virtual machine to a security group, and then add the security group to a role on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 34

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution: You create a playbook

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 35

For each of the following statements, select Yes if the statement is true Otherwise, select No.

SC-500 Question 35

Options:

Buy Now
Questions 36

You need to implement the planned change for the AKS1 integration.

What should you configure for AKS1?

Options:

A.

application scaling

B.

a workload identity

C.

Secrets Store CSI Driver

D.

Kubernetes role-based access control (Kubernetes RBAC)

Buy Now
Questions 37

You need to delegate a user to implement the planned change for Defender for Cloud. The solution must follow the principle of least privilege.

Which user should you choose?

Options:

A.

Admin1

B.

Admin2

C.

Admin3

D.

Admin4

Buy Now
Questions 38

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution: You create an automation rule.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 39

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You create a private endpoint on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 40

For which storage accounts can you implement the planned changes for storage?

Options:

A.

storage1, storage2, storage3, and storage4

B.

storage1, storage2, and storage4 only

C.

storage2 and storage4 only

D.

storage1 and storage3 only

E.

storage2, storage3, and storage4 only

F.

storage1 only

Buy Now
Exam Code: SC-500
Exam Name: Microsoft Certified: Cloud and AI Security Engineer Associate
Last Update: Sep 19, 2026
Questions: 135

PDF + Testing Engine

$55.71   $185.69

Testing Engine

$42.85   $142.83

PDF (Q&A)

$47.13   $157.11