Microsoft

SC-500 Free Practice Questions — Page 5

Question 41

You have an Azure key vault named KV1. You have an Azure App Service web app named App1. App1 is integrated with a virtual network named VNet1 that is linked to an Azure Private DNS zone. App1 accesses secrets stored in KV1. You need to configure KV1 to meet the following requirements: • App1 must access the secrets by using a private IP address on VNet1. • Requests from outside VNet1 must be denied. Which two actions should you perform for KV1? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

A. Create a private endpoint.
B. Add the IP addresses of App1.
C. Disable public access.
D. Create an access policy.
Show Answer
Correct Answer: A, C
Explanation:
Create a private endpoint for KV1 so it can be reached through a private IP address on VNet1. Disable public network access to deny requests that come from outside the private network.

Question 42

You have an Azure subscription named Sub1 that is linked to a Microsoft Entra tenant named contoso.com. Sub1 contains a Recovery Services vault named RSVault1 that stores virtual machines backups. Your company’s security team maintains a dedicated Microsoft Entra tenant named security.contoso.com. You need to ensure that modifying the backup settings of RSVault1 requires approval from an approver in security.contoso.com. What should you do in contoso.com?

A. Enable immutability for RSVault1 and lock the immutability setting.
B. Create a private endpoint for RSVault1 on the virtual network.
C. Configure Privileged Identity Management (PIM) activation for the Backup Operator role.
D. Enable Multi-user authorization (MUA) for RSVault1.
Show Answer
Correct Answer: D
Explanation:
Enable Multi-user authorization (MUA) for RSVault1 and configure it to use a Resource Guard in the security.contoso.com tenant. MUA requires approval from an authorized approver for protected backup operations, including changes to backup settings.

Question 43

You have an Azure subscription named Sub1 that contains a resource group named RG1. RG1 contains a virtual network named VNet1 and a storage account named storage1. Several engineers are assigned the Owner role for Sub1. You need to prevent updates to and deletions from VNet1. The solution must ensure that engineers can continue updating other resources in RG1. Which lock should you apply?

A. a Read-only resource lock at the RG1 scope
B. a Delete resource lock at the RG1 scope
C. a Read-only resource lock at the VNet1 scope
D. a Delete resource lock at the VNet1 scope
Show Answer
Correct Answer: C
Explanation:
Apply a Read-only lock directly to VNet1. A Read-only lock prevents updates and deletions, while the VNet1 scope leaves other resources in RG1 available for engineers to update.

Question 44

You have a Microsoft Entra tenant that contains a user named User1. You have an Azure Arc-enabled server named SRV1 that runs Windows Server. SRV1 is configured for Microsoft Entra sign-in. User1 reports that when they use their Microsoft Entra credentials to sign in to SRV1 over RDP, they receive the following message: “Your account is configured to prevent you from using this device.” You need to ensure that User1 can sign in to SRV1 over RDP. The solution must follow the principle of least privilege. What should you do?

A. Assign User1 the Virtual Machine Administrator Login role for SRV1.
B. Create a Conditional Access policy that requires multifactor authentication (MFA).
C. Add User to the local Remote Desktop Users group on SRV1.
D. Assign User1 the Virtual Machine User Login role for SRV1.
Show Answer
Correct Answer: D
Explanation:
Assign User1 the Virtual Machine User Login role at the scope of SRV1. This grants the least-privilege Azure RBAC permission to sign in to the Arc-enabled server with Microsoft Entra credentials. The Administrator Login role grants broader privileges, and adding the user to a local group alone does not provide the required Azure RBAC authorization.

Question 45

You have an Azure subscription named Sub1 that contains a storage account named storage1. Sub1 has Microsoft Defender for Storage enabled. Defender for Storage has malware scanning enabled. You need to configure a solution that automates the remediation of malware detected in storage1. What should you include in the solution?

A. Azure Logic Apps
B. a Log Analytics workspace
C. an alert rule
D. Azure Policy
Show Answer
Correct Answer: A
Explanation:
Azure Logic Apps can run an automated remediation workflow when malware is detected, for example by quarantining or deleting the infected blob. Defender for Storage can publish malware-scan results to Event Grid, which can trigger the workflow.

Question 46

HOTSPOT You have an Azure Container Instances container group named CGI that has a DNS name of cg1.contoso.com. CG1 has the following configurations: A Linux container named container1 that serves HTTPS over TCP port 443 and hosts an application named App1 A Linux container named contained that listens on TCP port 5000 and is accessed only by App1 A public IP address A security review finds that external clients can reach TCP port 5000 by using the public IP address of CG1. You need to meet the following requirements: Ensure that the external clients can access container1 only by using TCP port 443. Ensure that container1 can continue to access contained. What should you configure? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-500 question 46
Show Answer
Correct Answer: Exposed ports on the public IP address of CG1: 443 only Network endpoint for App1: localhost:5000
Explanation:
Containers in the same container group share a network interface. App1 can reach the other container through localhost on port 5000 without exposing that port publicly.

Question 47

DRAG DROP You have an Azure virtual network named VNet1 that contains an AzureBastionSubnet. VNet1 contains a subnet named Subnet1. Subnet1 contains multiple virtual machines. You plan to deploy Azure Bastion to provide secure RDP access to the virtual machines on Subnet1. You associate a network security group (NSG) named NSG1 to AzureBastionSubnet. You need to configure rules for NSG1. The solution must meet the following requirements: Allow required inbound access to Azure Bastion from the internet. Allow user access to the virtual machines by using Azure Bastion. Which TCP ports should you allow for the NSG1 rules? To answer, drag the appropriate ports to the correct rules. Each port may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.

Illustration for SC-500 question 47
Show Answer
Correct Answer: Inbound from the internet: TCP 443 Outbound to Subnet1: TCP 3389
Explanation:
Users connect to Azure Bastion over HTTPS (443). Bastion connects to the virtual machines over RDP (3389).

Question 48

You have a Microsoft Copilot Studio agent. A Microsoft Power Platform administrator configures external threat detection for the agent by using a Microsoft Entra application. You need to ensure that real-time protection is enabled during agent runtime. What should you do in the Microsoft Defender portal?

A. Configure Microsoft Defender for Cloud Apps session policies.
B. Connect the Microsoft 365 app connector.
C. Enable Global Secure Access for Agents.
D. From Microsoft Sentinel, configure the Microsoft Purview data connector.
Show Answer
Correct Answer: B
Explanation:
Connect the Microsoft 365 app connector in the Microsoft Defender portal. This enables the telemetry integration required for Defender to monitor Copilot Studio agent activity and provide real-time runtime protection. Defender for Cloud Apps session policies do not enable this agent-specific protection.

Question 49

Overview Fabrikam, Inc. is a consulting company. The company has a main office in New York City and branch offices in Amsterdam and Singapore. Existing Environment. Network environment The on-premises network contains a datacenter in each office. Existing Environment. Cloud environment Fabrikam has two Azure subscriptions named Sub1 and Sub2 and a Microsoft 365 subscription that includes Microsoft 365 E5 licenses. All the subscriptions are linked to a Microsoft Entra tenant named fabrikam.com that contains the identities shown in the following table. The tenant contains the groups shown in the following table. All devices are enrolled in Microsoft Intune. Existing Environment. Sub1 Resources Sub1 contains a resource group named RG1 that contains the resources shown in the following table. SQLServer1 uses Microsoft SQL Server authentication. Sub1 has an Azure Web Application Firewall (WAF) named WAF1 that has the following types of rule sets: Bot Manager 1.1 Azure-managed Default Rule Set (DRS) Sub1 has the following compliance standards assigned in Microsoft Defender for Cloud: NIST SP 800-53 Rev. 4 Microsoft cloud security benchmark (MCSB) System and Organization Controls (SOC) 2 Type 2 Existing Environment. Sub2 Resources Sub2 contains a resource group named RG2. Planned Changes and Requirements. Planned Changes Fabrikam plans to implement the following changes: Deploy the following key vaults to RG1: AKV2 in the West Europe Azure region AKV3 in the Central US Azure region AKV4 in the East US Azure region Deploy the following key vaults to RG2: AKV5 in the East US region Configure VM1 to read data from storage1. Create function apps that have the following hosting plans: Fa1: Flex Consumption hosting plan Fa2: Consumption hosting plan Fa3: Dedicated hosting plan For WAF1, implement rate limiting rules based on the request location. Enable the NIST SP 800-53 Rev. 5 compliance standard in Defender for Cloud. Create a new storage account named storage2 that supports Azure Table storage. Enforce multifactor authentication (MFA) when database administrators access SQLdb1. Implement ExpressRoute circuits to the on-premises network as shown in the following table. For RG1, create a new Privileged Identity Management (PIM) eligible role assignment that assigns the Contributor role to supported groups. Planned Changes and Requirements. Technical Requirements Fabrikam has the following technical requirements: If VM1 is deleted, the permissions for VM1 must be removed automatically. The AKS1 managed identity must only be able to pull images from Registry1. The ID1 managed identity must be able to push images to and pull images from Registry1. All the data in the storage accounts must be encrypted by using Fabrikam-managed keys. All outbound traffic from the function apps to the on-premises network must use ExpressRoute circuits. ExpressRoute connectivity between the on-premises network and the Azure environment must be encrypted by using Layer 2 or Layer 3 encryption. You need to delegate a user to implement the planned change for Defender for Cloud. The solution must follow the principle of least privilege. Which user should you choose?

A. Admin1
B. Admin2
C. Admin3
D. Admin4
Show Answer
Correct Answer: A
Explanation:
Choose Admin1. Enabling the NIST SP 800-53 Rev. 5 standard requires permission to assign policies at the subscription scope. Admin1 has that permission, so this meets the requirement without granting broader access than necessary.

Question 50

You have an Azure subscription named Sub1 that contains an Azure Kubernetes Service (AKS) cluster named cluster1 and an Azure container registry named ACR1. Sub1 has Microsoft Defender for Containers enabled, and runtime protection is active on cluster1. The developers at your company deploy pods that have elevated privileges, and the deployments are created in cluster1. You need to prevent pods with elevated privileges from being accepted by cluster1. What should you do?

A. Create an Azure policy for cluster1.
B. Enable agentless discovery for Kubernetes in Defender for Containers.
C. Configure runtime threat protection alerts for privileged container activity.
D. Enable vulnerability assessment for images in ACR1.
Show Answer
Correct Answer: A
Explanation:
Create an Azure Policy for the AKS cluster that denies pods configured with privileged access. Azure Policy can enforce admission-time controls, preventing noncompliant pods from being accepted. The other options provide discovery, alerts, or image vulnerability assessment rather than blocking deployments.

$19

Get all 100 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.