Microsoft Implementing End-to-End Security Controls for Cloud and AI Workloads - SC-500 Exam Practice Test

Question 1
Hotspot Question
You have an Azure subscription.
You need to create and deploy an Azure policy that meets the following requirements:
- When a new virtual machine is deployed, automatically install a
custom security extension.
- Trigger an autogenerated remediation task for non-compliant virtual
machines to install the extension.
What should you include in the policy? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Correct Answer:
Question 2
You have an Azure key vault named KV1.
You have an Azure App Service web app named App1. App1 is integrated with a virtual network named VNet1 that is linked to an Azure Private DNS zone. App1 accesses secrets stored in KV1.
You need to configure KV1 to meet the following requirements:
- App1 must access the secrets by using a private IP address on VNet1.
- Requests from outside VNet1 must be denied.
Which two actions should you perform for KV1? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

Correct Answer: A,B
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 3
Hotspot Question
You need to deploy the Phishing Triage Agent in Microsoft Security Copilot to manage phishing incidents in Microsoft Defender XDR.
The solution must meet the following requirements:
- Manage the phishing incidents.
- Enable the Phishing Triage Agent.
- Follow the principle of least privilege.
Which roles should you assign? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Correct Answer:

Explanation:
Box 1: Security Operator in Microsoft Entra and Security Copilot Contributor To enable the Phishing Triage Agent in Microsoft Security Copilot while adhering strictly to the principle of least privilege, you should assign the following two roles:
Microsoft Entra Role: Security Operator
Microsoft Security Copilot Role: Security Copilot Contributor
Security Operator: This role provides the necessary permissions to manage operational security tasks and interact with incidents within Microsoft Defender XDR without granting excessive global administrative rights or broad data modification rights across other Microsoft portals.
Security Copilot Contributor: This role allows the agentic platform to utilize Copilot capabilities, run prompts, and manage agent behaviors without having full admin access to modify Security Copilot tenant configurations (which would require the Security Copilot Owner role).
Box 2: Security Operator in Microsoft Entra and Security Copilot Contributor To manage phishing incidents using the Phishing Triage Agent in Microsoft Defender XDR while strictly adhering to the principle of least privilege, you should assign the following two roles:
Entra Role: Security Operator
Copilot Role: Contributor
Security Operator vs. Security Administrator / Global Administrator: The Security Operator role provides the necessary permissions to read security data, manage alerts, and triage incidents without granting broad configuration or destructive management privileges inherent to a Security Administrator or Global Administrator.
Contributor vs. Owner: The Contributor role allows the agent to run prompts, access core Security Copilot capabilities, and interact with the data sources to execute investigations. It explicitly leaves out platform-level access management and billing configuration rights held by an Owner.
Reference:
https://github.com/MicrosoftDocs/defender-docs/blob/public/defender-xdr/phishing-triage-agent.md
Question 4
You have an Azure SQL Database logical server named Server1 that contains multiple databases.
The databases contain legacy SQL authentication logins that must no longer be usable for sign-in but must NOT be removed from the databases.
You need to ensure that SQL authentication is denied for connections.
What should you do?

Correct Answer: B
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 5
Hotspot Question
You have a Microsoft Sentinel workspace named Workspace1.
You hire a security consultant. You provide the consultant with a guest account named User1 in your Microsoft Entra tenant.
You need to enable User1 to assign incidents in Workspace1.
Which roles should you assign to User1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Correct Answer:
Question 6
You have an Azure subscription named Sub1. Sub1 contains 20 virtual machines that run Windows Server.
Sub1 has the Microsoft Defender for Cloud Defender Cloud Security Posture Management (CSPM) plan enabled.
You need to ensure that all the virtual machines are scanned automatically for known security flaws and misconfigurations.
What should you use?

Correct Answer: B
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).