Weekend Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: certbig75

SC-500 Exam Dumps - Microsoft Certified: Information Security Administrator Associate Questions and Answers

Question # 14

You use Microsoft Security Copilot.

Users are assigned either the Security Copilot Contributor role or the Security Copilot Owner role.

A contributor enables a custom plugin that is NOT approved, and some Security Copilot features in embedded experiences no longer function.

You need to ensure that plugins affecting all users can only be added by owners.

What should you do in the Plugin settings?

Options:

A.

Select Contributors and Owners to configure which users can add custom plugins at the user scope.

B.

Select Contributors and Owners to configure which users can add custom plugins at the workspace scope.

C.

Select Owners only to configure which users can add custom plugins at the workspace scope.

D.

Select Owners only to configure which users can add custom plugins at the user scope.

Buy Now
Question # 15

You have an Azure subscription named Sub1 that contains a storage account named storage1. Sub1 has Microsoft Defender for Storage enabled. Defender for Storage has malware scanning enabled.

You need to configure a solution that automates the remediation of malware detected in storage1.

What should you include in the solution?

Options:

A.

Azure Logic Apps

B.

a Log Analytics workspace

C.

an alert rule

D.

Azure Policy

Buy Now
Question # 16

You have a Microsoft Entra tenant.

You need to implement password less authentication. The solution must meet the following requirements:

•Users can sign in without a password by using a mobile device.

•New users that sign in for the first time must use a helpdesk issued sign in method that expires.

Which authentication method should you enable for each requirement? To answer, drag the appropriate methods to the correct requirements. Each method may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Question # 17

You have a virtual network named VNet1 that contains a subnet named Subnet1 and a virtual machine named VM1. VM1 uses only dynamic IP addresses from Subnet1.

You have an Azure key vault named KV1.

You enable a firewall on KV1 and allow access to KV1 from only select virtual networks and IP addresses.

VM1 receives 403 errors when it attempts to access KV1.

You need to enable VM1 to access KV1, while maintaining the current restrictions on KV1.

What should you do?

Options:

A.

Create a routing rule on Subnet1.

B.

Allow trusted Microsoft services to bypass the firewall on KV1.

C.

Add a Microsoft.KeyVault service endpoint for Subnet1.

D.

Add the current IPv4 address of VM1 to the firewall allowlist of KV1.

Buy Now
Question # 18

You have an Azure SQL Database logical server named Server1 that contains multiple databases.

The databases contain legacy SQL authentication logins that must no longer be usable for sign-in but must NOT be removed from the databases.

You need to ensure that SQL authentication is denied for connections.

What should you do?

Options:

A.

Run CREATE USER ... FROM EXTERNAL PROVIDER on each database.

B.

Create a Conditional Access policy.

C.

Enable Microsoft Entra-only authentication for Server1.

D.

Assign the SQL Server Contributor role to Server1.

Buy Now
Question # 19

You have an Azure subscription that contains a resource group named RG1.

RG1 contains a Microsoft Security Copilot deployment that is integrated with a Microsoft Sentinel workspace named Workspace1.

Analysts use the Security Copilot standalone experience to retrieve incidents by using the Microsoft Sentinel plugin.

A user named User1 can sign in to Security Copilot but cannot retrieve incidents from Workspace1. You verify that User1 lias only the Security Copilot Contributor role.

You need to ensure that User1 can retrieve the incidents. The solution must follow the principle of least privilege and NOT require any configuration changes to Security Copilot.

Which role should you assign to User1?

Options:

A.

The Security Reader role in Microsoft Entra

B.

The Microsoft Sentinel Reader role for Workspace1

C.

The Security Copilot Owner role

D.

The Security Administrator role in Microsoft Entra

E.

The Contributor role in Azure for RG1

Buy Now
Question # 20

You have an Azure subscription.

You need to deploy an Azure virtual WAN to meet the following requirements:

•Create three secured virtual hubs located in the East US. West US, and North Europe Azure regions.

•Ensure that security rules sync between the regions.

What should you use?

Options:

A.

Azure Network Function Manager

B.

Azure Firewall Manager

C.

Azure Virtual Network Manager

D.

Azure Front Door

Buy Now
Question # 21

You have an Azure subscription that contains a blob container named cont1. Con1 ' has the access policies shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Question # 22

You have three on-premises apps named App1, App2, and App3 that are configured in Microsoft Entra Private Access as shown in the following table.

You have the users shown in the following table.

The Global Secure Access client is deployed to all user devices.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Question # 23

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You add each virtual machine to a security group, and then add the security group to a role on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Exam Code: SC-500
Exam Name: Microsoft Certified: Cloud and AI Security Engineer Associate
Last Update: Sep 20, 2026
Questions: 135
SC-500 pdf

SC-500 PDF

$23.75  $94.99
SC-500 Engine

SC-500 Testing Engine

$27.5  $109.99
SC-500 PDF + Engine

SC-500 PDF + Testing Engine

$36.25  $144.99