Weekend Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: w75best

Microsoft SC-500 Dumps

Page: 1 / 14
Total 135 questions

Microsoft Certified: Cloud and AI Security Engineer Associate Questions and Answers

Question 1

For each of the following statements, select Yes if the statement is true Otherwise, select No.

as

Options:

Question 2

You need to implement the planned change for storage2 The solution must meet the technical requirements for storage encryption.

What should you do?

Options:

A.

Enable purge protection for storage2.

B.

Create an encryption scope in storage2.

C.

Configure storage2 to use an account encryption key.

D.

Assign an Azure role-based access control (Azure RBAC) role to storage2.

Question 3

You need to implement the planned change for the AKS1 integration.

What should you configure for AKS1?

Options:

A.

application scaling

B.

a workload identity

C.

Secrets Store CSI Driver

D.

Kubernetes role-based access control (Kubernetes RBAC)

Question 4

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution: You create an automation rule.

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 5

You need to implement the function apps to meet the technical requirements.

Which apps should you include in the implementation?

Options:

A.

Fa1 and Fa2 only

B.

Fa2 and Fa3 only

C.

Fa1 and Fa3 only

D.

Fa1, Fa2, and Fa3

Question 6

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You add each virtual machine to a security group, and then add the security group to a role on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 7

You need to configure Microsoft Sentinel to meet the technical requirements.

To what should you set Analytics retention for DnsEvents?

Options:

A.

2 years

B.

12 years

C.

180 days

D.

1 year

E.

6 years

Question 8

You need to delegate a user to implement the planned change for Defender for Cloud. The solution must follow the principle of least privilege.

Which user should you choose?

Options:

A.

Admin1

B.

Admin2

C.

Admin3

D.

Admin4

Question 9

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You create a user-assigned managed identity, assign the identity to each virtual machine, and then add each managed identity to a role on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 10

User1 has requested to use the AI Administrator role.

Which approvers can approve the request, and how long will User1 be an AI administrator after the role is approved? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

as

Options:

Question 11

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You add each virtual machine to a role on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 12

You need to configure the AKS1 and ID 1 managed identities to meet the technical requirements. The solution must follow the principle of least privilege.

Which role should you assign to each identity? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

as

Options:

Question 13

You need to protect the applications hosted on AKS1. The solution must meet the technical requirements.

Which Defender for Cloud plan should you enable?

Options:

A.

Microsoft Defender for Servers

B.

Microsoft Defender for App Service

C.

Microsoft Defender for Containers

D.

Microsoft Defender for Resource Manager

E.

Microsoft Defender for Storage

Question 14

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution: You create an analytics rule.

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 15

You need to implement the planned change for SQLdb1

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point

Options:

A.

Create a compliance policy.

B.

Configure Microsoft Entra authentication for SQLServer1.

C.

Create a Conditional Access policy.

D.

Configure federated client identity for SQLdb1.

E.

Configure a user-assigned managed identity for SQLdb1.

Question 16

You need to configure Server1 to meet the technical requirements.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

as

Options:

Question 17

Note. This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem

After you answer a question in this section, you will NOT be able to return. As a result these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution You create a hunting query.

Does this meet the goal’

Options:

A.

Yes

B.

No

Question 18

For which storage accounts can you implement the planned changes for storage?

Options:

A.

storage1, storage2, storage3, and storage4

B.

storage1, storage2, and storage4 only

C.

storage2 and storage4 only

D.

storage1 and storage3 only

E.

storage2, storage3, and storage4 only

F.

storage1 only

Question 19

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution: You create a playbook

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 20

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You create a private endpoint on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 21

You have a Microsoft Security Copilot workspace named Workspace1 that is used by Security Operations Center (SOC) analysts and security administrators.

The SOC analysts use only the Security Copilot standalone experience, and the security administrators access Security Copilot from the Microsoft Defender portal.

A new Security Copilot workspace named Workspace2 is created for the security administrators. Workspace2 is assigned a capacity of five security compute units.

You need to ensure that Security Copilot usage for the SOC analysts is allocated to Workspace1 and Security Copilot usage for the security administrators is allocated to Workspace2.

What should you do?

Options:

A.

Configure Workspace2 for embedded agent traffic.

B.

Increase the capacity of Workspace2.

C.

Assign the Workspace1 capacity to Workspace2.

D.

Configure Workspace1 for embedded agent traffic.

Question 22

You have an Azure Container Registry named Registry1-

You add role assignments for Registry! as shown in the following table.

as

as

Options:

Question 23

You have an Azure subscription named Sub1 that is linked to a Microsoft Entra tenant named contoso.com.

Sub1 contains a Recovery Services vault named RSVault1 that stores virtual machine backups.

Your company’s security team maintains a dedicated Microsoft Entra tenant named security.contoso.com.

You need to ensure that modifying the backup settings of RSVault1 requires approval from an approver in security.contoso.com.

What should you do in contoso.com?

Options:

A.

Enable immutability for RSVault1 and lock the immutability setting.

B.

Create a private endpoint for RSVault1 on the virtual network.

C.

Configure Privileged Identity Management (PIM) activation for the Backup Operator role.

D.

Enable Multi-user authorization (MUA) for RSVault1.

Question 24

You have a Microsoft 365 subscription. All users have Microsoft Exchange Online mailboxes.

You use Microsoft Entra Agent ID to register and manage AI agents.

The developers at your company create the following two agents:

•Agent 1: An interactive agent that helps users summarize their own Exchange Online email

•Agent2: An autonomous agent that sends nightly updates to a Microsoft Teams channel

You need to grant each agent access to Microsoft Graph. The solution must minimize the access scope, while meeting each agent ' s operating model.

Which type of permission should you assign to each agent? To answer, drag the appropriate permission types to the correct agents. Each permission type may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

as

Options:

Question 25

You have a Microsoft Entra tenant.

You need to implement password less authentication. The solution must meet the following requirements:

•Users can sign in without a password by using a mobile device.

•New users that sign in for the first time must use a helpdesk issued sign in method that expires.

Which authentication method should you enable for each requirement? To answer, drag the appropriate methods to the correct requirements. Each method may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

as

Options:

Question 26

You have an Azure virtual network named VNet1 that contains a subnet named Subnet! A network security group named NSG1 is associated with Subnet1.

Vou have a storage account named storage1.

You need to ensure that access from Subnet1 to storage! uses a private IP address in Subnet1 and ran be filtered by NSG1 Public network access to storage1 must be disabled.

What should you create?

Options:

A.

a user-defined route (UDR)

B.

a service endpoint

C.

a private endpoint

D.

an Azure Private link service

Question 27

You have an Azure subscription named Sub1 that contains multiple virtual machines. Sub1 has the Microsoft Defender Cloud Security Posture Management (CSPM) plan enabled.

You discover that Defender for Cloud falls to identify plaintext connection strings and SSH keys stored on the virtual machines.

You need to ensure that secrets can be identified on the virtual machines.

What should you do?

Options:

A.

Configure the Defender for Cloud data connector in Microsoft Sentinel.

B.

Enable agentless machine scanning.

C.

Deploy the Azure Monitor Agent to all the virtual machines.

D.

Enable Microsoft Defender for Key Vault.

Question 28

You have an Azure subscription that contains the following servers:

•200 virtual machines that run either Windows Server or Ubuntu Server

•50 Azure Arc enabled servers

You use Azure Policy to manage compliance across all the servers.

You need to enforce an organization-specific security baseline. The solution must meet the following requirements:

•Customize a built-in security baseline.

•Ensure that configuration changes to the servers are enforced automatically after the security baseline is deployed.

♦Minimize administrative effort.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

as

Options:

Question 29

You have the Azure key vaults shown in the following table.

as

KV1 stores a secret named Secret1 and a key for a managed storage account named Key1.

You back up Secret1 and Key1.

To which key vaults can you restore each backup? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

as

Options:

Question 30

You have a Microsoft Entra tenant named contoso.com that contains the users shown in the following table.

as

Microsoft Entra Privileged Identity Management (PIM) is used in contoso.com.

In PIM, the Password Administrator role has the following settings:

as

Options:

Question 31

You have a virtual network named VNet1 that contains a subnet named Subnet1 and a virtual machine named VM1. VM1 uses only dynamic IP addresses from Subnet1.

You have an Azure key vault named KV1.

You enable a firewall on KV1 and allow access to KV1 from only select virtual networks and IP addresses.

VM1 receives 403 errors when it attempts to access KV1.

You need to enable VM1 to access KV1, while maintaining the current restrictions on KV1.

What should you do?

Options:

A.

Create a routing rule on Subnet1.

B.

Allow trusted Microsoft services to bypass the firewall on KV1.

C.

Add a Microsoft.KeyVault service endpoint for Subnet1.

D.

Add the current IPv4 address of VM1 to the firewall allowlist of KV1.

Question 32

You have an Azure subscription named Sub1 that contains multiple virtual machines and an Azure key vault named KV1.

Each virtual machine has a system-assigned managed identity. Sub1 has Microsoft Defender for Servers enabled. Defender for Servers has agentless scanning enabled.

Some virtual machines use managed disks that are encrypted by using customer-managed keys stored in KV1.

You discover that the affected virtual machines fail to return agentless scanning results in Microsoft Defender for Cloud.

You need to ensure that agentless scanning can analyze the virtual machines.

What should you do?

Options:

A.

Assign each virtual machine managed identity the Key Vault Reader role for KV1.

B.

Assign the scanning service the Key Vault Secrets User role for KV1.

C.

Enable Microsoft Defender for Key Vault for Sub1.

D.

Enable just-in-time (JIT) VM access for the affected virtual machines.

E.

Assign the scanning service the Key Vault Crypto Service Encryption User role for KV1

Question 33

You use Microsoft Security Copilot.

Users are assigned either the Security Copilot Contributor role or the Security Copilot Owner role.

A contributor enables a custom plugin that is NOT approved, and some Security Copilot features in embedded experiences no longer function.

You need to ensure that plugins affecting all users can only be added by owners.

What should you do in the Plugin settings?

Options:

A.

Select Contributors and Owners to configure which users can add custom plugins at the user scope.

B.

Select Contributors and Owners to configure which users can add custom plugins at the workspace scope.

C.

Select Owners only to configure which users can add custom plugins at the workspace scope.

D.

Select Owners only to configure which users can add custom plugins at the user scope.

Question 34

You have a Microsoft Sentinel workspace named Workspace1

You have 100 on-premises servers that run Linux and have the Azure Monitor Agent installed.

You need to collect Syslog events from the Linux servers. The solution must meet the following requirements:

•Ensure that filtering occurs before data is written to Workspace1

•Reduce ingestion costs by excluding low value Syslog messages.

What should you include in the solution?

Options:

A.

An Advanced Security Information Model (ASIM) parser

B.

A data collection rule (DCR)

C.

An analytics rule

D.

A table-level filter and split transformation

Question 35

You have an Azure subscription named Sub1 that contains a storage account named storage1. Sub1 has Microsoft Defender for Storage enabled. Defender for Storage has malware scanning enabled.

You need to configure a solution that automates the remediation of malware detected in storage1.

What should you include in the solution?

Options:

A.

Azure Logic Apps

B.

a Log Analytics workspace

C.

an alert rule

D.

Azure Policy

Question 36

You have an Azure Subscription that contains the storage accounts shown in the following table.

as

You enable Microsoft Defender for Storage.

Which storage services of storage5 are monitored by Microsoft for Storage which storage accounts are protected by.

as

Options:

Question 37

You have an Azure key vault named KV1 that uses rale based access control (RBAC) for data plane authorization.

You have multiple Azure App Service web apps that retrieve a SQL connection string stored as a secret in KV1.

You need to ensure that the web apps can access KV1. the solution must minimize the number of required identities and follow the principle of least privilege.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

as

Options:

Question 38

You have a Microsoft Sentinel workspace named Workspace1.

You hire a security consultant. You provide the consultant with a guest account named User1 in your Microsoft Entra tenant.

You need to enable User1 to assign incidents in Workspace1.

Which roles should you assign to User1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

as

Options:

Question 39

You have a Microsoft Sentinel workspace

You need to collect Windows security events from 200 Azure virtual machines that run Windows Server. The solution must meet the following requirements:

•Use direct agent based data collection from each virtual machine.

•Use a supported agent for new virtual machine deployments

Which Microsoft Sentinel connector should you use?

Options:

A.

Windows Forwarded Events

B.

Windows Security Events via AMA

C.

Security Events via Legacy Agent

D.

Syslog via AMA

E.

Azure Resource Graph

Question 40

You have an Azure key vault named KV1 that uses role-based access control (RBAC) for data plane authorization.

You have a user named User1 and an Azure App Service web app named App1 that has a system-assigned managed identity.

You need to configure authorization to meet the following requirements:

•App1 must be able to retrieve secrets from KV1.

•User1 must manage the KV1 settings without accessing secret values.

The solution must follow the principle of least privilege.

Which role should you assign to each identity for KV1? To answer, drag the appropriate roles to the correct identities. Each role may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

as

Options:

Page: 1 / 14
Total 135 questions