Microsoft Implementing End-to-End Security Controls for Cloud and AI Workloads SC-500 Dumps in PDF

Free Microsoft SC-500 Real Questions (page: 7)

DRAG DROP (Drag and Drop is not supported)
You have a Microsoft Entra tenant.
You need to implement passwordless authentication. The solution must meet the following requirements:
-Users can sign in without a password by using a mobile device.
-New users that sign in for the first time must use a helpdesk-issued sign-in method that expires.
Which authentication method should you enable for each requirement? To answer, drag the appropriate methods to the correct requirements. Each method may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
Note: Each correct selection is worth one point.
Select and Place:

  1. See Explanation section for answer.

Answer(s): A

Explanation:




Passwordless sign-in: Microsoft Authenticator First-time sign-in for new users: Temporary Access Pass
Microsoft Authenticator supports passwordless phone sign-in, allowing users to authenticate from a registered mobile device without entering a password. Temporary Access Pass is a time-limited, helpdesk-issued passcode that enables new users to complete their initial sign-in and register passwordless authentication methods.


Reference:

https://learn.microsoft.com/en-us/entra/identity/authentication/howto-authentication-temporary-access-pass



You have a Microsoft Entra tenant that has user consent for applications disabled.
You register an application named App1 that requests the following Microsoft Graph delegated permissions:
-User.Read
-Mail.Read
You need to configure tenant permissions to meet the following requirements:
-Enable users to grant consent for low-risk permissions without administrator interaction.
-Ensure that applications requesting higher-privilege permissions require administrator approval.
What should you do?

  1. Grant tenant-wide admin consent to App1.
  2. Configure application assignments for App1.
  3. Configure Privileged Identity Management (PIM) role assignments.
  4. Create an app consent policy.

Answer(s): D

Explanation:

An app consent policy defines the conditions under which users can consent to delegated permissions, such as permitting approved low-risk permissions while withholding consent rights for higher-privilege permissions. Permissions outside the allowed policy conditions require administrator consent or approval.


Reference:

https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/manage-app-consent-policies? pivots=ms-powershell https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/configure-user-consent?pivots=portal



You have an Azure management group named MG1 that contains two subscriptions named Sub1 and Sub2. Both subscriptions are linked to a Microsoft Entra tenant that contains a security group named Group1.
You need to ensure that the members of Group1 can assign roles to the resources in Sub1 and Sub2. The solution must follow the principle of least privilege.
Which role should you assign to Group1?

  1. Contributor at the MG1 scope
  2. Contributor at the Sub1 and Sub2 scopes
  3. User Access Administrator at the MG1 scope
  4. Owner at the MG1 scope

Answer(s): C

Explanation:

The User Access Administrator role permits members of Group1 to manage role assignments without granting them permission to modify the underlying Azure resources. Assigning the role at the MG1 scope causes the permission to be inherited by both Sub1 and Sub2 and their resources, providing centralized least-privilege access management.


Reference:

https://learn.microsoft.com/en-us/azure/role-based-access-control/role-definitions https://learn.microsoft.com/en-us/azure/role-based-access-control/elevate-access-global-admin?tabs=azure-portal%2Centra-audit-logs https://learn.microsoft.com/en-us/azure/role-based-access-control/scope-overview



HOTSPOT (Drag and Drop is not supported)
You have an Azure key vault named KV1 that uses role-based access control (RBAC) for data plane authorization.
You have a user named User1 and an Azure App Service web app named App1 that has a system-assigned managed identity.
You need to configure authorization to meet the following requirements:
-App1 must be able to retrieve secrets from KV1.
-User1 must manage the KV1 settings without accessing secret values.
The solution must follow the principle of least privilege.
Which role should you assign to each identity for KV1? To answer, drag the appropriate roles to the correct identities. Each role may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
Note: Each correct selection is worth one point.
Select and Place:

  1. See Explanation section for answer.

Answer(s): A

Explanation:



User1: Key Vault Contributor App1: Key Vault Secrets User
The Key Vault Contributor role allows User1 to manage the key vault resource and its configuration but does not grant access to secret values. The Key Vault Secrets User role grants App1’s managed identity permission to read secret contents from KV1 without allowing it to manage secrets or the vault, satisfying least privilege.


Reference:

https://learn.microsoft.com/en-us/azure/key-vault/general/rbac-guide?tabs=azure-cli



HOTSPOT (Drag and Drop is not supported)
You have an Azure subscription named Sub1 that contains 50 virtual machines. Sub1 has Microsoft Defender for Cloud enabled.
Sub1 contains an Azure key vault named KV1 and an Azure policy that enforces storing all secrets in KV1.
Occasionally, the developers at your company store plaintext tokens and SSH private keys on the virtual machines.
You need to configure Defender for Cloud to detect plaintext secrets on the virtual machines. The solution must minimize administrative changes to the virtual machines.
How should you configure Defender for Cloud? To answer, select the appropriate options in the answer area.
Note: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:




Plan to enable: Defender Cloud Security Posture Management (CSPM) Feature to enable: Agentless machine scanning
Defender CSPM supports agentless secrets scanning for Azure virtual machines. Enabling agentless machine scanning allows Defender for Cloud to analyze VM disk snapshots for exposed plaintext tokens and SSH private keys without requiring agents or configuration changes on the virtual machines.


Reference:

https://learn.microsoft.com/en-us/azure/defender-for-cloud/secrets-scanning-servers https://learn.microsoft.com/en-us/azure/defender-for-cloud/concept-agentless-data-collection



HOTSPOT (Drag and Drop is not supported)
You have an Azure subscription.
You need to create and deploy an Azure policy that meets the following requirements:
-When a new virtual machine is deployed, automatically install a custom security extension.
-Trigger an autogenerated remediation task for non-compliant virtual machines to install the extension.
What should you include in the policy? To answer, select the appropriate options in the answer area.
Note: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:



Definition effect: DeployIfNotExists For remediation, define: A managed identity that has the Contributor role
The DeployIfNotExists effect deploys the custom security extension when a virtual machine does not already have the required extension. Remediation tasks use the deployment template in this policy effect to correct existing non-compliant virtual machines. The policy assignment requires a managed identity with the permissions needed to deploy the extension; the Contributor role provides the required resource deployment permissions.


Reference:

https://learn.microsoft.com/en-us/azure/governance/policy/concepts/effect-deploy-if-not-exists https://learn.microsoft.com/en-us/azure/governance/policy/how-to/remediate-resources?tabs=azure-portal https://learn.microsoft.com/en-us/azure/governance/policy/overview




Overview
Fabrikam, Inc. is a consulting company. The company has a main office in New York City and branch offices in Amsterdam and Singapore.
Existing Environment. Network environment
The on-premises network contains a datacenter in each office.
Existing Environment. Cloud environment
Fabrikam has two Azure subscriptions named Sub1 and Sub2 and a Microsoft 365 subscription that includes Microsoft 365 E5 licenses.
All the subscriptions are linked to a Microsoft Entra tenant named fabrikam.com that contains the identities shown in the following table.

The tenant contains the groups shown in the following table.

All devices are enrolled in Microsoft Intune.
Existing Environment. Sub1 Resources
Sub1 contains a resource group named RG1 that contains the resources shown in the following table.

SQLServer1 uses Microsoft SQL Server authentication.
Sub1 has an Azure Web Application Firewall (WAF) named WAF1 that has the following types of rule sets:
• Bot Manager 1.1
• Azure-managed Default Rule Set (DRS)
Sub1 has the following compliance standards assigned in Microsoft Defender for Cloud:
• NIST SP 800-53 Rev. 4
• Microsoft cloud security benchmark (MCSB)
• System and Organization Controls (SOC) 2 Type 2
Existing Environment. Sub2 Resources
Sub2 contains a resource group named RG2.
Planned Changes and Requirements. Planned Changes
Fabrikam plans to implement the following changes:
• Deploy the following key vaults to RG1:
o AKV2 in the West Europe Azure region
o AKV3 in the Central US Azure region
o AKV4 in the East US Azure region
• Deploy the following key vaults to RG2:
o AKV5 in the East US region
• Configure VM1 to read data from storage1.
• Create function apps that have the following hosting plans:
o Fa1: Flex Consumption hosting plan
o Fa2: Consumption hosting plan
o Fa3: Dedicated hosting plan
• For WAF1, implement rate limiting rules based on the request location.
• Enable the NIST SP 800-53 Rev. 5 compliance standard in Defender for Cloud.
• Create a new storage account named storage2 that supports Azure Table storage.
• Enforce multifactor authentication (MFA) when database administrators access SQLdb1.
• Implement ExpressRoute circuits to the on-premises network as shown in the following table.

• For RG1, create a new Privileged Identity Management (PIM) eligible role assignment that assigns the Contributor role to supported groups.

Planned Changes and Requirements. Technical Requirements

Fabrikam has the following technical requirements:

• If VM1 is deleted, the permissions for VM1 must be removed automatically.
• The AKS1 managed identity must only be able to pull images from Registry1.
• The ID1 managed identity must be able to push images to and pull images from Registry1.
• All the data in the storage accounts must be encrypted by using Fabrikam-managed keys.
• All outbound traffic from the function apps to the on-premises network must use ExpressRoute circuits.
• ExpressRoute connectivity between the on-premises network and the Azure environment must be encrypted by using Layer 2 or Layer 3 encryption.

You need to implement the planned change for SQLdb1.
Which two actions should you perform? Each correct answer presents part of the solution.
Note: Each correct selection is worth one point.

  1. Create a compliance policy.
  2. Configure Microsoft Entra authentication for SQLServer1.
  3. Create a Conditional Access policy.
  4. Configure Federated client identity for SQLdb1.
  5. Configure a user-assigned managed identity for SQLdb1

Answer(s): B,C

Explanation:

Microsoft Entra authentication must be configured for SQLServer1 so database administrators can authenticate to Azure SQL Database by using Microsoft Entra identities. A Conditional Access policy can then target Azure SQL Database and require multifactor authentication when administrators connect to SQLdb1.


Reference:

https://learn.microsoft.com/en-us/azure/azure-sql/database/authentication-aad-configure? view=azuresql&tabs=azure-portal https://learn.microsoft.com/en-us/azure/azure-sql/database/conditional-access-configure?view=azuresql




Overview
Fabrikam, Inc. is a consulting company. The company has a main office in New York City and branch offices in Amsterdam and Singapore.
Existing Environment. Network environment
The on-premises network contains a datacenter in each office.
Existing Environment. Cloud environment
Fabrikam has two Azure subscriptions named Sub1 and Sub2 and a Microsoft 365 subscription that includes Microsoft 365 E5 licenses.
All the subscriptions are linked to a Microsoft Entra tenant named fabrikam.com that contains the identities shown in the following table.

The tenant contains the groups shown in the following table.

All devices are enrolled in Microsoft Intune.
Existing Environment. Sub1 Resources
Sub1 contains a resource group named RG1 that contains the resources shown in the following table.

SQLServer1 uses Microsoft SQL Server authentication.
Sub1 has an Azure Web Application Firewall (WAF) named WAF1 that has the following types of rule sets:
• Bot Manager 1.1
• Azure-managed Default Rule Set (DRS)
Sub1 has the following compliance standards assigned in Microsoft Defender for Cloud:
• NIST SP 800-53 Rev. 4
• Microsoft cloud security benchmark (MCSB)
• System and Organization Controls (SOC) 2 Type 2
Existing Environment. Sub2 Resources
Sub2 contains a resource group named RG2.
Planned Changes and Requirements. Planned Changes
Fabrikam plans to implement the following changes:
• Deploy the following key vaults to RG1:
o AKV2 in the West Europe Azure region
o AKV3 in the Central US Azure region
o AKV4 in the East US Azure region
• Deploy the following key vaults to RG2:
o AKV5 in the East US region
• Configure VM1 to read data from storage1.
• Create function apps that have the following hosting plans:
o Fa1: Flex Consumption hosting plan
o Fa2: Consumption hosting plan
o Fa3: Dedicated hosting plan
• For WAF1, implement rate limiting rules based on the request location.
• Enable the NIST SP 800-53 Rev. 5 compliance standard in Defender for Cloud.
• Create a new storage account named storage2 that supports Azure Table storage.
• Enforce multifactor authentication (MFA) when database administrators access SQLdb1.
• Implement ExpressRoute circuits to the on-premises network as shown in the following table.

• For RG1, create a new Privileged Identity Management (PIM) eligible role assignment that assigns the Contributor role to supported groups.

Planned Changes and Requirements. Technical Requirements

Fabrikam has the following technical requirements:

• If VM1 is deleted, the permissions for VM1 must be removed automatically.
• The AKS1 managed identity must only be able to pull images from Registry1.
• The ID1 managed identity must be able to push images to and pull images from Registry1.
• All the data in the storage accounts must be encrypted by using Fabrikam-managed keys.
• All outbound traffic from the function apps to the on-premises network must use ExpressRoute circuits.
• ExpressRoute connectivity between the on-premises network and the Azure environment must be encrypted by using Layer 2 or Layer 3 encryption.

You need to implement the planned change for storage2. The solution must meet the technical requirements for storage encryption.
What should you do?

  1. Enable purge protection for storage2.
  2. Create an encryption scope in storage2.
  3. Configure storage2 to use an account encryption key.
  4. Assign an Azure role-based access control (Azure RBAC) role to storage2.

Answer(s): C

Explanation:

Because storage2 must support Azure Table storage, it must be created to use an encryption key scoped to the storage account. Azure Table storage can then be encrypted by using a Fabrikam-managed customer-managed key. Encryption scopes apply to Blob storage and do not meet the requirement for Table storage encryption.


Reference:

https://learn.microsoft.com/en-us/azure/storage/common/account-encryption-key-create? tabs=portal https://learn.microsoft.com/en-us/azure/storage/blobs/encryption-scope-overview



Share your comments for Microsoft SC-500 exam with other users:

A
Anonymous User
4/15/2026 4:42:07 AM

Question 528:

  • Correct answer: NSG flow logs for NSG1 (Option B)

  • Why:
- Traffic Analytics uses NSG flow logs to analyze traffic patterns. You must have NSG flow logs enabled for the NSGs you want to monitor. - An Azure Log Analytics workspace is also required to store and query the traffic data. - Network Watcher must be available in the subscription for traffic analytics to function.
  • What to configure (brief steps):
- Ensure Network Watcher is enabled in the East US region (for the subscription/region). - Enable NSG flow logs on NSG1. - Ensure a Log Analytics workspace exists and is accessible (read/write) so Traffic Analytics can store and query logs.
  • Why other options aren’t correct:
- “Diagnostic settings for VM1” or “Diagnostic settings for NSG1” alone don’t guarantee flow logs are captured and sent to Log Analytics, which Traffic Analytics relies on. - “Insights for VM1” is not how Traffic Analytics collects traffic data.

A
Anonymous User
4/15/2026 2:43:53 AM

Question 23:
The correct answer is Domain admin (option B), not Fabric admin.

  • Domain admin provides domain-level management: create domains/subdomains and assign workspaces within those domains, which matches the tasks while following least privilege.
  • Fabric admin is global-level access and is more privileges than needed for this scenario (it would grant broader control across the Fabric environment).

A
Anonymous User
4/14/2026 12:31:34 PM

Question 2:
For question 2, the key concept is the Longest Prefix Match. Routers pick the route whose subnet mask is the most specific (largest prefix length) that still matches the destination IP.
From the options:

  • A) 10.10.10.0/28 ? 10.10.10.0–10.10.10.15
  • B) 10.10.13.0/25 ? 10.10.13.0–10.10.13.127
  • C) 10.10.13.144/28 ? 10.10.13.144–10.10.13.159
  • D) 10.10.13.208/29 ? 10.10.13.208–10.10.13.215

The destination Host A’s IP must fall within 10.10.13.208–10.10.13.215 for the /29 to be the best match. Since /29 is the longest prefix among the matching options, Router1 will use 10.10.13.208/29.
Thus, the correct answer is D.

S
srameh
4/14/2026 10:09:29 AM

Question 3:

  • Correct answer: Phase 4, Post Accreditation

  • Explanation:
- In DITSCAP, the four phases are: - Phase 1: Definition (concept and requirements) - Phase 2: Verification (design and testing) - Phase 3: Validation (fielding and evaluation) - Phase 4: Post Accreditation (ongoing operations and lifecycle management) - The description—continuing operation of an accredited IT system and addressing changing threats throughout its life cycle—fits the Post Accreditation phase, which covers operations, maintenance, monitoring, and reauthorization as threats and environment evolve.

O
onibokun10
4/13/2026 7:50:14 PM

Question 129:
Correct answer: CNAME

  • A CNAME record creates an alias for a domain, so newapplication.comptia.org will resolve to whatever IP address www.comptia.org resolves to. This ensures both names point to the same resource without duplicating the IP.
  • Why not the others:
- SOA defines authoritative information for a zone. - MX specifies mail exchange servers. - NS designates name servers for a zone.
  • Notes: The alias name (newapplication.comptia.org) should not have other records if you use a CNAME for it, and CNAMEs aren’t used for the zone apex (root) domain. This scenario uses a subdomain, so a CNAME is appropriate.

A
Anonymous User
4/13/2026 6:29:58 PM

Question 1:

  • Correct answer: C

  • Why this is best:
- Uses OS Login with IAM, so SSH access is granted via Google accounts rather than distributing per-user SSH keys. - Granting the compute.osAdminLogin role to a Google group gives admin access to all team members in a centralized, auditable way. - Access is auditable: Cloud Audit Logs show who accessed which VM, satisfying the security requirement to determine who accessed a given instance.
  • How it works:
- Enable OS Login on the project/instances (enable-oslogin metadata). - Add the team’s

A
Anonymous User
4/13/2026 1:00:51 PM

Question 2:

  • Answer: D. Azure Advisor

  • Why: To view security-related recommendations for resources in the Compute and Apps area (including App Service Web Apps and Functions), you use Azure Advisor. Advisor surfaces personalized best-practice recommendations across resources, including security, and shows which resources are affected and the severity.

  • Why not the others:
- Azure Log Analytics is for ad-hoc querying of telemetry, not for viewing security recommendations. - Azure Event Hubs is for streaming telemetry data, not for security recommendations.
  • Quick tip: In the portal, navigate to Azure Advisor and check the Security recommendations for App Services to see actionable items and affe

D
Don
4/11/2026 5:36:42 AM

Recommend using AI for Solutions rather the Answer(s) submitted here

M
Mogae Malapela
4/8/2026 6:37:56 AM

This is very interesting

A
Anon
4/6/2026 5:22:54 PM

Are these the same questions you have to pay for in ExamTopics?

L
LRK
3/22/2026 2:38:08 PM

For Question 7 - while the answer description indicates the correct answer, the option no. mentioned is incorrect. Nice and Comprehensive. Thankyou

R
Rian
3/19/2026 9:12:10 AM

This is very good and accurate. Explanation is very helpful even thou some are not 100% right but good enough to pass.

G
Gerrard
3/18/2026 6:58:37 AM

The DP-900 exam can be tricky if you aren't familiar with Microsoft’s specific cloud terminology. I used the practice questions from free-braindumps.com and found them incredibly helpful. The site breaks down core data concepts and Azure services in a way that actually mirrors the real test. As a resutl I passed my exam.

V
Vineet Kumar
3/6/2026 5:26:16 AM

interesting

J
Joe
1/20/2026 8:25:24 AM

Passed this exam 2 days ago. These questions are in the exam. You are safe to use them.

N
NJ
12/24/2025 10:39:07 AM

Helpful to test your preparedness before giving exam

A
Ashwini
12/17/2025 8:24:45 AM

Really helped

J
Jagadesh
12/16/2025 9:57:10 AM

Good explanation

S
shobha
11/29/2025 2:19:59 AM

very helpful

P
Pandithurai
11/12/2025 12:16:21 PM

Question 1, Ans is - Developer,Standard,Professional Direct and Premier

E
Einstein
11/8/2025 4:13:37 AM

Passed this exam in first appointment. Great resource and valid exam dump.

D
David
10/31/2025 4:06:16 PM

Today I wrote this exam and passed, i totally relay on this practice exam. The questions were very tough, these questions are valid and I encounter the same.

T
Thor
10/21/2025 5:16:29 AM

Anyone used this dump recently?

V
Vladimir
9/25/2025 9:11:14 AM

173 question is A not D

K
khaos
9/21/2025 7:07:26 AM

nice questions

K
Katiso Lehasa
9/15/2025 11:21:52 PM

Thanks for the practice questions they helped me a lot.

E
Einstein
9/2/2025 7:42:00 PM

Passed this exam today. All questions are valid and this is not something you can find in ChatGPT.

V
vito
8/22/2025 4:16:51 AM

i need to pass exam for VMware 2V0-11.25

M
Matt
7/31/2025 11:44:40 PM

Great questions.

O
OLERATO
7/1/2025 5:44:14 AM

great dumps to practice for the exam

A
Adekunle willaims
6/9/2025 7:37:29 AM

How reliable and relevant are these questions?? also i can see the last update here was January and definitely new questions would have emerged.

A
Alex
5/24/2025 12:54:15 AM

Can I trust to this source?

S
SPriyak
3/17/2025 11:08:37 AM

can you please provide the CBDA latest test preparation

C
Chandra
11/28/2024 7:17:38 AM

This is the best and only way of passing this exam as it is extremely hard. Good questions and valid dump.

AI Tutor 👋 I’m here to help!