Weekend Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: certbig75

SC-500 Exam Dumps - Microsoft Certified: Information Security Administrator Associate Questions and Answers

Question # 4

You have an Azure subscription that has Microsoft Defender for Cloud enabled.

You have an Amazon Web Services (AWS) account connected to Defender for Cloud that has the Defender Cloud Security Posture Management (CSPM) plan enabled.

You need to identify the potential impact of security incidents that exploit multiple risks reported by Defender CSPM.

What should you use?

Options:

A.

Regulatory compliance

B.

Cloud security explorer

C.

Security recommendations

D.

Attack path analysis

Buy Now
Question # 5

You need to configure the AKS1 and ID 1 managed identities to meet the technical requirements. The solution must follow the principle of least privilege.

Which role should you assign to each identity? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Question # 6

You use Microsoft Security Copilot.

You need to update Plugin settings. the solution must meet the following requirements:

• Allow contributors to use custom plug-ins without affecting either UMTS

• Limit publishing of custom plug-ins for other users to Owners only.

Which Plugin settings option should you configure for each requirement? To answer, drag the appropriate settings lo the correct requirements. Each setting may be used once, more than once., or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Question # 7

You have an Azure subscription that contains the following servers:

•200 virtual machines that run either Windows Server or Ubuntu Server

•50 Azure Arc enabled servers

You use Azure Policy to manage compliance across all the servers.

You need to enforce an organization-specific security baseline. The solution must meet the following requirements:

•Customize a built-in security baseline.

•Ensure that configuration changes to the servers are enforced automatically after the security baseline is deployed.

♦Minimize administrative effort.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Question # 8

You have an Azure subscription named Sub1. Sub1 contains 20 virtual machines that run Windows Server.

Sub1 has the Microsoft Defender for Cloud Defender Cloud Security Posture Management (CSPM) plan enabled.

You need to ensure that all the virtual machines are scanned automatically for known security flaws and misconfigurations.

What should you use?

Options:

A.

Attack path analysis

B.

Microsoft Cloud Security Benchmark (MCSB)

C.

Cloud security explorer

D.

Just-in-time (JIT) VM access

E.

Vulnerability assessment on the virtual machines

Buy Now
Question # 9

You have an Azure subscription that contains the custom roles shown in the following table.

In the Azure portal, you plan to create new custom roles by cloning existing roles Ihe new roles will be configured as shown in following table.

Options:

Buy Now
Question # 10

You have an Azure subscription that contains a resource group named RG1 and has Microsoft Defender tor Cloud enabled.

You connect an Amazon Web Services (AWS) account to Defender for Cloud by creating the AW5 connector in RG1.

You have a Microsoft Entra group named Group1 that contains the UMf accounts of (he security analysts at your company.

You need to ensure that the members of Group1 can view multicloud recommendations and security alerts ' or the connected AWS account. The solution must follow the principle of least privilege

Which role should you assign to Group1 for RG1?

Options:

A.

Owner

B.

Security Administrator

C.

Security Reader

D.

Reader

Buy Now
Question # 11

You have an Azure subscription that contains the following resources:

•An Azure SQL Database logical server named Server1 that contains a database named DB1

•An Azure SQL Managed Instance named Instance1 that contains a database named DB2

You need to configure database auditing. The solution must meet the following requirements:

•Ensure that audit data is centrally available in a location that supports for KQL queries.

•Minimize ongoing administrative effort as additional databases are added.

What should you configure? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Question # 12

You have an Azure environment.

You need to identity any Azure configurations and workloads that are non-compliant with ISO 27001:2013 standards. What should you use?

Options:

A.

Microsoft Defender for Cloud

B.

Microsoft Defender for Identity

C.

Microsoft Entra ID Protection

D.

Microsoft Sentinel

Buy Now
Question # 13

You have an Azure subscription named Sub1 that contains a resource group named RG1.

RG1 contains a virtual network named VNet1 and a storage account named storage1. Several engineers are assigned the Owner role for Sub1.

You need to prevent updates to and deletions from VNet1. The solution must ensure that engineers can continue updating other resources in RG1.

Which lock should you apply?

Options:

A.

a Read-only resource lock at the RG1 scope

B.

a Delete resource lock at the RG1 scope

C.

a Read-only resource lock at the VNet1 scope

D.

a Delete resource lock at the VNet1 scope

Buy Now
Exam Code: SC-500
Exam Name: Microsoft Certified: Cloud and AI Security Engineer Associate
Last Update: Sep 20, 2026
Questions: 135
SC-500 pdf

SC-500 PDF

$23.75  $94.99
SC-500 Engine

SC-500 Testing Engine

$27.5  $109.99
SC-500 PDF + Engine

SC-500 PDF + Testing Engine

$36.25  $144.99