This is the free Microsoft SC-500 practice question bank —
50 of 100 total questions, each with a full explanation, free to
read with no signup required. Updated 2026-10-03.
Every answer is verified against official Microsoft documentation —
see our methodology.
Question 1
Overview
Contoso, Ltd. is a consulting company that has a main office in San Francisco and a branch office in Dallas.
Contoso has a hybrid environment that contains on-premises servers connected to Azure, a Microsoft 365 E5 subscription, and an Azure subscription named Sub1.
Existing Environment. Microsoft Entra tenant
Contoso has a Microsoft Entra tenant named contoso.com that contains the users shown in the following table.
Existing Environment. On-premises environment
The on-premises network contains an Active Directory Domain Services (AD DS) forest that syncs with contoso.com. The forest contains a server named Server1 that runs Windows Server.
Existing Environment. Azure subscription
Sub1 contains the storage accounts shown in the following table.
Sub1 contains the virtual networks shown in the following table.
Sub1 contains the virtual machines shown in the following table.
The network interface of VM1 is associated with an application security group named ASG1.
Sub1 contains the resources shown in the following table.
Vault1 stores the objects shown in the following table.
Existing Environment. Privileged Identity Management (PIM) configuration
You manage privileged roles by using Privileged Identity Management (PIM). The PIM role settings are configured as shown in the following table.
Existing Environment. Microsoft Sentinel configuration
Contoso has a Microsoft Sentinel workspace that contains the following tables.
Requirements. Planned changes
Contoso plans to implement the following changes:
• Integrate AKS1 with Vault1.
• Enable Microsoft Entra Kerberos authentication for all supported storage.
• Configure auditing for sql1 by using the Azure portal and store audit logs in a centralized location.
Requirements. Technical requirements
Contoso identifies the following technical requirements:
• Protect Server1 by using file integrity monitoring.
• Protect AKS1 by using Microsoft Defender for Cloud.
• Configure Microsoft Sentinel to retain data for the maximum supported duration without changing the tier.
• Store objects used for authentication and encryption in Vault1 and ensure that Vault1 regenerates the objects every 30 days, whenever possible.
You need to meet the technical requirements for Vault1.
Which object can you use?
A. Certificate2
B. Key1
C. Certificate1
D. Secret1
Show Answer
Correct Answer: A
Explanation: Use Certificate2. A Key Vault certificate can be used for authentication and encryption, and Key Vault supports automatic certificate renewal when its lifetime policy is configured. Secret1 can store authentication data but does not provide native automatic rotation in the same way; the disabled objects are not usable as configured.
Question 2
Overview
Contoso, Ltd. is a consulting company that has a main office in San Francisco and a branch office in Dallas.
Contoso has a hybrid environment that contains on-premises servers connected to Azure, a Microsoft 365 E5 subscription, and an Azure subscription named Sub1.
Existing Environment. Microsoft Entra tenant
Contoso has a Microsoft Entra tenant named contoso.com that contains the users shown in the following table.
Existing Environment. On-premises environment
The on-premises network contains an Active Directory Domain Services (AD DS) forest that syncs with contoso.com. The forest contains a server named Server1 that runs Windows Server.
Existing Environment. Azure subscription
Sub1 contains the storage accounts shown in the following table.
Sub1 contains the virtual networks shown in the following table.
Sub1 contains the virtual machines shown in the following table.
The network interface of VM1 is associated with an application security group named ASG1.
Sub1 contains the resources shown in the following table.
Vault1 stores the objects shown in the following table.
Existing Environment. Privileged Identity Management (PIM) configuration
You manage privileged roles by using Privileged Identity Management (PIM). The PIM role settings are configured as shown in the following table.
Existing Environment. Microsoft Sentinel configuration
Contoso has a Microsoft Sentinel workspace that contains the following tables.
Requirements. Planned changes
Contoso plans to implement the following changes:
• Integrate AKS1 with Vault1.
• Enable Microsoft Entra Kerberos authentication for all supported storage.
• Configure auditing for sql1 by using the Azure portal and store audit logs in a centralized location.
Requirements. Technical requirements
Contoso identifies the following technical requirements:
• Protect Server1 by using file integrity monitoring.
• Protect AKS1 by using Microsoft Defender for Cloud.
• Configure Microsoft Sentinel to retain data for the maximum supported duration without changing the tier.
• Store objects used for authentication and encryption in Vault1 and ensure that Vault1 regenerates the objects every 30 days, whenever possible.
You need to implement the planned change for the AKS1 integration.
What should you configure for AKS1?
A. application scaling
B. a workload identity
C. Secrets Store CSI Driver
D. Kubernetes role-based access control (Kubernetes RBAC)
Show Answer
Correct Answer: C
Explanation: Configure the Secrets Store CSI Driver to integrate AKS with Azure Key Vault. It lets pods access secrets, keys, and certificates stored in Vault1. A workload identity can provide authentication, but it is not the integration mechanism itself.
Question 3
Overview
Contoso, Ltd. is a consulting company that has a main office in San Francisco and a branch office in Dallas.
Contoso has a hybrid environment that contains on-premises servers connected to Azure, a Microsoft 365 E5 subscription, and an Azure subscription named Sub1.
Existing Environment. Microsoft Entra tenant
Contoso has a Microsoft Entra tenant named contoso.com that contains the users shown in the following table.
Existing Environment. On-premises environment
The on-premises network contains an Active Directory Domain Services (AD DS) forest that syncs with contoso.com. The forest contains a server named Server1 that runs Windows Server.
Existing Environment. Azure subscription
Sub1 contains the storage accounts shown in the following table.
Sub1 contains the virtual networks shown in the following table.
Sub1 contains the virtual machines shown in the following table.
The network interface of VM1 is associated with an application security group named ASG1.
Sub1 contains the resources shown in the following table.
Vault1 stores the objects shown in the following table.
Existing Environment. Privileged Identity Management (PIM) configuration
You manage privileged roles by using Privileged Identity Management (PIM). The PIM role settings are configured as shown in the following table.
Existing Environment. Microsoft Sentinel configuration
Contoso has a Microsoft Sentinel workspace that contains the following tables.
Requirements. Planned changes
Contoso plans to implement the following changes:
• Integrate AKS1 with Vault1.
• Enable Microsoft Entra Kerberos authentication for all supported storage.
• Configure auditing for sql1 by using the Azure portal and store audit logs in a centralized location.
Requirements. Technical requirements
Contoso identifies the following technical requirements:
• Protect Server1 by using file integrity monitoring.
• Protect AKS1 by using Microsoft Defender for Cloud.
• Configure Microsoft Sentinel to retain data for the maximum supported duration without changing the tier.
• Store objects used for authentication and encryption in Vault1 and ensure that Vault1 regenerates the objects every 30 days, whenever possible.
You need to configure Microsoft Sentinel to meet the technical requirements.
To what should you set Analytics retention for DnsEvents?
A. 2 years
B. 12 years
C. 180 days
D. 1 year
E. 6 years
Show Answer
Correct Answer: A
Explanation: Set Analytics retention for DnsEvents to 2 years. This is the maximum supported retention period while keeping the data in the Analytics tier.
Question 4
Overview
Contoso, Ltd. is a consulting company that has a main office in San Francisco and a branch office in Dallas.
Contoso has a hybrid environment that contains on-premises servers connected to Azure, a Microsoft 365 E5 subscription, and an Azure subscription named Sub1.
Existing Environment. Microsoft Entra tenant
Contoso has a Microsoft Entra tenant named contoso.com that contains the users shown in the following table.
Existing Environment. On-premises environment
The on-premises network contains an Active Directory Domain Services (AD DS) forest that syncs with contoso.com. The forest contains a server named Server1 that runs Windows Server.
Existing Environment. Azure subscription
Sub1 contains the storage accounts shown in the following table.
Sub1 contains the virtual networks shown in the following table.
Sub1 contains the virtual machines shown in the following table.
The network interface of VM1 is associated with an application security group named ASG1.
Sub1 contains the resources shown in the following table.
Vault1 stores the objects shown in the following table.
Existing Environment. Privileged Identity Management (PIM) configuration
You manage privileged roles by using Privileged Identity Management (PIM). The PIM role settings are configured as shown in the following table.
Existing Environment. Microsoft Sentinel configuration
Contoso has a Microsoft Sentinel workspace that contains the following tables.
Requirements. Planned changes
Contoso plans to implement the following changes:
• Integrate AKS1 with Vault1.
• Enable Microsoft Entra Kerberos authentication for all supported storage.
• Configure auditing for sql1 by using the Azure portal and store audit logs in a centralized location.
Requirements. Technical requirements
Contoso identifies the following technical requirements:
• Protect Server1 by using file integrity monitoring.
• Protect AKS1 by using Microsoft Defender for Cloud.
• Configure Microsoft Sentinel to retain data for the maximum supported duration without changing the tier.
• Store objects used for authentication and encryption in Vault1 and ensure that Vault1 regenerates the objects every 30 days, whenever possible.
For which storage accounts can you implement the planned changes for storage?
A. storage1, storage2, storage3, and storage4
B. storage1, storage2, and storage4 only
C. storage2 and storage4 only
D. storage1 and storage3 only
E. storage2, storage3, and storage4 only
F. storage1 only
Show Answer
Correct Answer: D
Explanation: Microsoft Entra Kerberos authentication applies to supported Azure Files SMB storage. Of the listed accounts, storage1 and storage3 meet the requirements; the other accounts do not support the planned storage change.
Question 5
Overview
Fabrikam, Inc. is a consulting company. The company has a main office in New York City and branch offices in Amsterdam and Singapore.
Existing Environment. Network environment
The on-premises network contains a datacenter in each office.
Existing Environment. Cloud environment
Fabrikam has two Azure subscriptions named Sub1 and Sub2 and a Microsoft 365 subscription that includes Microsoft 365 E5 licenses.
All the subscriptions are linked to a Microsoft Entra tenant named fabrikam.com that contains the identities shown in the following table.
The tenant contains the groups shown in the following table.
All devices are enrolled in Microsoft Intune.
Existing Environment. Sub1 Resources
Sub1 contains a resource group named RG1 that contains the resources shown in the following table.
SQLServer1 uses Microsoft SQL Server authentication.
Sub1 has an Azure Web Application Firewall (WAF) named WAF1 that has the following types of rule sets:
• Bot Manager 1.1
• Azure-managed Default Rule Set (DRS)
Sub1 has the following compliance standards assigned in Microsoft Defender for Cloud:
• NIST SP 800-53 Rev. 4
• Microsoft cloud security benchmark (MCSB)
• System and Organization Controls (SOC) 2 Type 2
Existing Environment. Sub2 Resources
Sub2 contains a resource group named RG2.
Planned Changes and Requirements. Planned Changes
Fabrikam plans to implement the following changes:
• Deploy the following key vaults to RG1:
o AKV2 in the West Europe Azure region
o AKV3 in the Central US Azure region
o AKV4 in the East US Azure region
• Deploy the following key vaults to RG2:
o AKV5 in the East US region
• Configure VM1 to read data from storage1.
• Create function apps that have the following hosting plans:
o Fa1: Flex Consumption hosting plan
o Fa2: Consumption hosting plan
o Fa3: Dedicated hosting plan
• For WAF1, implement rate limiting rules based on the request location.
• Enable the NIST SP 800-53 Rev. 5 compliance standard in Defender for Cloud.
• Create a new storage account named storage2 that supports Azure Table storage.
• Enforce multifactor authentication (MFA) when database administrators access SQLdb1.
• Implement ExpressRoute circuits to the on-premises network as shown in the following table.
• For RG1, create a new Privileged Identity Management (PIM) eligible role assignment that assigns the Contributor role to supported groups.
Planned Changes and Requirements. Technical Requirements
Fabrikam has the following technical requirements:
• If VM1 is deleted, the permissions for VM1 must be removed automatically.
• The AKS1 managed identity must only be able to pull images from Registry1.
• The ID1 managed identity must be able to push images to and pull images from Registry1.
• All the data in the storage accounts must be encrypted by using Fabrikam-managed keys.
• All outbound traffic from the function apps to the on-premises network must use ExpressRoute circuits.
• ExpressRoute connectivity between the on-premises network and the Azure environment must be encrypted by using Layer 2 or Layer 3 encryption.
You need to implement the planned change for WAF1. The solution must minimize administrative effort.
What should you do?
A. Create an Azure policy.
B. Modify the Bot Manager 1.1 rule set.
C. Add a custom rule.
D. Modify the Azure-managed DRS.
Show Answer
Correct Answer: C
Explanation: Add a custom WAF rule that applies rate limiting based on the request’s geographic location. Custom rules support combining rate limiting with geo-location match conditions, while the managed Bot Manager and DRS rule sets aren’t where you configure this behavior.
Question 6
Overview
Fabrikam, Inc. is a consulting company. The company has a main office in New York City and branch offices in Amsterdam and Singapore.
Existing Environment. Network environment
The on-premises network contains a datacenter in each office.
Existing Environment. Cloud environment
Fabrikam has two Azure subscriptions named Sub1 and Sub2 and a Microsoft 365 subscription that includes Microsoft 365 E5 licenses.
All the subscriptions are linked to a Microsoft Entra tenant named fabrikam.com that contains the identities shown in the following table.
The tenant contains the groups shown in the following table.
All devices are enrolled in Microsoft Intune.
Existing Environment. Sub1 Resources
Sub1 contains a resource group named RG1 that contains the resources shown in the following table.
SQLServer1 uses Microsoft SQL Server authentication.
Sub1 has an Azure Web Application Firewall (WAF) named WAF1 that has the following types of rule sets:
• Bot Manager 1.1
• Azure-managed Default Rule Set (DRS)
Sub1 has the following compliance standards assigned in Microsoft Defender for Cloud:
• NIST SP 800-53 Rev. 4
• Microsoft cloud security benchmark (MCSB)
• System and Organization Controls (SOC) 2 Type 2
Existing Environment. Sub2 Resources
Sub2 contains a resource group named RG2.
Planned Changes and Requirements. Planned Changes
Fabrikam plans to implement the following changes:
• Deploy the following key vaults to RG1:
o AKV2 in the West Europe Azure region
o AKV3 in the Central US Azure region
o AKV4 in the East US Azure region
• Deploy the following key vaults to RG2:
o AKV5 in the East US region
• Configure VM1 to read data from storage1.
• Create function apps that have the following hosting plans:
o Fa1: Flex Consumption hosting plan
o Fa2: Consumption hosting plan
o Fa3: Dedicated hosting plan
• For WAF1, implement rate limiting rules based on the request location.
• Enable the NIST SP 800-53 Rev. 5 compliance standard in Defender for Cloud.
• Create a new storage account named storage2 that supports Azure Table storage.
• Enforce multifactor authentication (MFA) when database administrators access SQLdb1.
• Implement ExpressRoute circuits to the on-premises network as shown in the following table.
• For RG1, create a new Privileged Identity Management (PIM) eligible role assignment that assigns the Contributor role to supported groups.
Planned Changes and Requirements. Technical Requirements
Fabrikam has the following technical requirements:
• If VM1 is deleted, the permissions for VM1 must be removed automatically.
• The AKS1 managed identity must only be able to pull images from Registry1.
• The ID1 managed identity must be able to push images to and pull images from Registry1.
• All the data in the storage accounts must be encrypted by using Fabrikam-managed keys.
• All outbound traffic from the function apps to the on-premises network must use ExpressRoute circuits.
• ExpressRoute connectivity between the on-premises network and the Azure environment must be encrypted by using Layer 2 or Layer 3 encryption.
You implement the planned changes for the key vaults.
To which key vaults can you restore AKV1 backups?
A. AKV4 only
B. AKV3 and AKV4 only
C. AKV4 and AKV5 only
D. AKV2, AKV3, and AKV4 only
E. AKV2, AKV3, AKV4, and AKV5
Show Answer
Correct Answer: B
Explanation: A Key Vault backup can be restored only to a vault in the same Azure subscription and Azure geography as the source. AKV3 (Central US) and AKV4 (East US) are in Sub1 and the same US geography as AKV1. AKV2 is in a different geography, and AKV5 is in a different subscription.
Question 7
HOTSPOT
You have an Azure subscription that contains an Azure Database for PostgreSQL instance named DB1.
You plan to protect DB1 by using Microsoft Defender for Cloud.
You need to configure Defender for Cloud to detect anomalous activities and database exploitations for DB1. The solution must NOT affect any other databases.
What should you enable? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Protection: At the individual database level
Defender plan: Microsoft Defender for Open-Source Relational Databases
Explanation: Enable the open-source relational database plan for DB1 specifically to detect anomalous activity and exploitation without extending protection to other databases.
Question 8
You have an Azure API Management instance named APIM1.
You have a partner company that accesses an API in APIM1 by using subscription keys.
A backend API key is stored in a named value in APIM1.
Microsoft Defender for Cloud generates the following recommendation: “API Management secret named values should be stored in Azure Key Vault.”
You need to address the recommendation.
What should you do first?
A. Enable the Microsoft Defender for APIs plan.
B. Enable a managed identity for APIM1.
C. Mark the existing named value as a secret.
D. Replace the backend API key with a subscription key.
Show Answer
Correct Answer: B
Explanation: Enable a managed identity for APIM1 first. APIM needs an identity to authenticate to Azure Key Vault before a named value can reference a secret stored there.
Question 9
You have an Azure subscription named Sub1 that contains multiple virtual machines and an Azure key vault named KV1.
Each virtual machine has a system-assigned managed identity. Sub1 has Microsoft Defender for Servers enabled. Defender for Servers has agentless scanning enabled.
Some virtual machines use managed disks that are encrypted by using customer-managed keys stored in KV1.
You discover that the affected virtual machines fail to return agentless scanning results in Microsoft Defender for Cloud.
You need to ensure that agentless scanning can analyze the virtual machines.
What should you do?
A. Assign each virtual machine managed identity the Key Vault Reader role for KV1.
B. Enable Microsoft Defender for Key Vault for Sub1.
C. Assign the scanning service the Key Vault Crypto Service Encryption User role for KV1.
D. Enable just-in-time (JIT) VM access for the affected virtual machines.
E. Assign the scanning service the Key Vault Secrets User role for KV1.
Show Answer
Correct Answer: C
Explanation: Agentless scanning needs access to the customer-managed encryption keys to analyze disks encrypted with those keys. Assign the Defender for Cloud scanning service the Key Vault Crypto Service Encryption User role on KV1. The VM identities do not need Key Vault access for this scanning scenario.
Question 10
You have a Microsoft Entra tenant that uses Microsoft Entra Agent ID.
You have multiple Microsoft Foundry agents that have agent identities assigned.
You discover that one of the identities is flagged as high risk due to unusual sign-in activity.
You need to ensure that agent access to resources is restricted automatically based on risk.
What should you create?
A. a Privileged Identity Management (PIM) activation policy
B. an Access review for the identities
C. a Conditional Access policy for the identities
D. a Microsoft Entra role assignment policy
Show Answer
Correct Answer: C
Explanation: Create a Conditional Access policy targeting the agent identities and use risk conditions to automatically block or restrict access when an identity is high risk.
$19
Get all 100 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.