Microsoft

SC-500 Free Practice Questions — Page 2

Question 11

You have an Azure Functions app named App1 that uses an HTTP trigger, runs on an Elastic Premium plan, and uses virtual network integration. A partner application sends requests to App1 from a public IP address of xxx.xxx.xxx.xx. You need to ensure that the requests are accepted from only xxx.xxx.xxx.xx. What should you do?

A. Deploy an Azure Bastion host.
B. Create a private endpoint for App1 and disable public network access.
C. Apply a network security group (NSG) to a dedicated subnet for virtual network integration.
D. Configure an inbound access restriction on App1.
E. Deploy an Azure NAT Gateway.
Show Answer
Correct Answer: D
Explanation:
Configure an inbound access restriction on App1 that allows the partner’s public IP address. Access restrictions act as an inbound IP firewall; other unmatched public traffic is denied. VNet integration and an NSG on its subnet do not control inbound requests to the app.

Question 12

You have a Microsoft 365 tenant that has Microsoft 365 Copilot enabled for a pilot group. Users frequently generate responses based on Microsoft Teams chats and Microsoft SharePoint Online sites. You use Microsoft Purview Data Security Posture Management (DSPM) to identify oversharing risks and create policies based on the recommendations. You need to manage and edit the policies created by DSPM. Which Microsoft Purview solution should you use?

A. Communication Compliance
B. Data Loss Prevention
C. Insider Risk Management
D. Information Protection
Show Answer
Correct Answer: B
Explanation:
Use Microsoft Purview Data Loss Prevention (DLP) to manage and edit the DLP policies created from DSPM recommendations for oversharing risks in Teams and SharePoint.

Question 13

You have a Microsoft Foundry project that contains a model deployment named Deployment1. Deployment1 contains an agent named Agent1 that uses an existing default guardrail configuration. You discover that Agent1 generates tool calls that contain harmful language. You need to ensure that Agent1 responses containing harmful content are prevented from running. The solution must prevent changes to the configuration of Deployment1. What should you do?

A. Create an automatic evaluation of the dataset of Agent1.
B. Create a custom guardrail and assign it directly to Agent1.
C. Fine-tune the model of Deployment1.
D. Create a red teaming run for Agent1.
Show Answer
Correct Answer: B
Explanation:
Create a custom guardrail and assign it directly to Agent1. It can inspect proposed tool calls for harmful content and block them before they run, without changing Deployment1’s configuration. Evaluations and red teaming assess behavior, while fine-tuning changes the model rather than adding this runtime control.

Question 14

You have an Azure subscription that contains the virtual machines shown in the following table. All the virtual networks are peered. You deploy Azure Bastion to VNET2. Which virtual machines can be protected by the bastion host?

A. VM2 only
B. VM2 and VM4 only
C. VM1, VM2, and VM3 only
D. VM1, VM2, VM3, and VM4
Show Answer
Correct Answer: D
Explanation:
Azure Bastion can provide access to virtual machines in its own virtual network and in peered virtual networks. Since all the virtual networks are peered, the Bastion host in VNET2 can protect VM1, VM2, VM3, and VM4.

Question 15

You plan to deploy Microsoft 365 Copilot. You discover that Copilot can access sensitive information in your Microsoft SharePoint Online libraries. You need to automatically identify which SharePoint Online content has been shared between all internal users. What should you create?

A. a Microsoft Purview data loss prevention (DLP) policy in audit mode for SharePoint Online
B. a Microsoft Purview Data Security Posture Management (DSPM) remediation action
C. a Conditional Access policy that requires multifactor authentication (MFA) for SharePoint Online
D. a SharePoint Advanced Management (SAM) Data access governance report
Show Answer
Correct Answer: D
Explanation:
Create a SharePoint Advanced Management (SAM) Data access governance report. These reports help identify SharePoint sites and files shared broadly with internal users, such as through the “Everyone except external users” group, so you can assess oversharing that could expose content to Copilot.

Question 16

You use Microsoft Security Copilot. Users are assigned either the Security Copilot Contributor role or the Security Copilot Owner role. A contributor enables a custom plugin that is NOT approved, and some Security Copilot features in embedded experiences no longer function. You need to ensure that plugins affecting all users can only be added by owners. What should you do in the Plugin settings?

A. Select Contributors and Owners to configure which users can add custom plugins at the user scope.
B. Select Contributors and Owners to configure which users can add custom plugins at the workspace scope.
C. Select Owners only to configure which users can add custom plugins at the workspace scope.
D. Select Owners only to configure which users can add custom plugins at the user scope.
Show Answer
Correct Answer: C
Explanation:
Set custom plugin permissions to **Owners only** at the **workspace scope**. Workspace-scope plugins can affect all users, so limiting who can add them to owners prevents contributors from enabling organization-wide plugins.

Question 17

You have a Microsoft Entra tenant that contains the users shown in the following table. You have a Microsoft Security Copilot workspace. From Microsoft Security Store, you plan to deploy a partner-built agent named Agent1 that requires access to Microsoft Intune. When User1 selects Agent1, the Get agent option is unavailable. You need to enable User1 to complete the agent setup. The solution must follow the principle of least privilege. What should you do first?

A. From Security Copilot, create an agent identity for Agent1.
B. From Security Copilot, configure the required data source for Agent1.
C. Assign User1 the AI Administrator role in Microsoft Entra.
D. Assign User1 the Agent ID Administrator role in Microsoft Entra.
E. Instruct User2 to approve the agent setup.
Show Answer
Correct Answer: E
Explanation:
Have User2 approve the agent setup. This lets User1 proceed without granting User1 broader Entra administrative roles, following least privilege.

Question 18

You have an Azure subscription. You plan to map an online infrastructure and perform vulnerability scanning for the following: • ASNs • Hostnames • IP addresses • SSL certificates What should you use?

A. Microsoft Defender for Identity
B. Microsoft Defender External Attack Surface Management (Defender EASM)
C. Microsoft Defender for Endpoint
D. Microsoft Defender for Cloud
Show Answer
Correct Answer: B
Explanation:
Microsoft Defender External Attack Surface Management (Defender EASM) discovers and maps an organization’s internet-facing assets, including ASNs, hostnames, IP addresses, and SSL certificates, and helps assess their exposure.

Question 19

You have an Azure subscription that has the Microsoft Defender for Cloud Foundational Cloud Security Posture Management (CSPM) plan enabled. You have an Amazon Web Services (AWS) account connected to Defender for Cloud for posture management. In Defender for Cloud, security recommendations for the resources in Azure and AWS have a risk level of Not evaluated. You need to ensure that Defender for Cloud assigns a risk level to the recommendations. What should you do?

A. Onboard all the virtual machines in the AWS account to Azure Arc.
B. Enable Microsoft Defender for Servers Plan 2.
C. Assign the CIS AWS Foundations v3.0.0 standard to the AWS account.
D. Enable the Defender CSPM plan.
Show Answer
Correct Answer: D
Explanation:
Foundational CSPM provides posture recommendations, but recommendation risk prioritization requires the Defender CSPM plan. Enable Defender CSPM so Defender for Cloud can assign risk levels to recommendations across the connected Azure and AWS environments.

Question 20

DRAG DROP You have an Azure subscription named Sub1. Sub1 contains 60 virtual machines that run either Window Server or Linux. All the Windows Server virtual machines host line-of-business (LOB) applications and all the Linux virtual machines host backend databases. You need to enable malware protection for the virtual machines. Which Microsoft Defender for Cloud plan should you enable for each type of virtual machine? To answer, drag the appropriate plans to the correct virtual machine types. Each plan may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.

Illustration for SC-500 question 20
Show Answer
Correct Answer: Windows Server: Microsoft Defender for Servers Linux: Microsoft Defender for Servers
Explanation:
Defender for Servers provides malware protection for both Windows Server and Linux virtual machines, regardless of whether they host applications or databases.

$19

Get all 100 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.