Pre-Winter Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free and Premium Microsoft SC-500 Dumps Questions Answers

Page: 1 / 10
Total 135 questions

Microsoft Certified: Cloud and AI Security Engineer Associate Questions and Answers

Question 1

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution: You create an analytics rule.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Question 2

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution: You create a playbook

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 3

You need to implement the function apps to meet the technical requirements.

Which apps should you include in the implementation?

Options:

A.

Fa1 and Fa2 only

B.

Fa2 and Fa3 only

C.

Fa1 and Fa3 only

D.

Fa1, Fa2, and Fa3

Question 4

You need to configure the AKS1 and ID 1 managed identities to meet the technical requirements. The solution must follow the principle of least privilege.

Which role should you assign to each identity? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Question 5

You need to configure Server1 to meet the technical requirements.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Question 6

You need to delegate a user to implement the planned change for Defender for Cloud. The solution must follow the principle of least privilege.

Which user should you choose?

Options:

A.

Admin1

B.

Admin2

C.

Admin3

D.

Admin4

Question 7

You need to implement the planned change for SQLdb1

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point

Options:

A.

Create a compliance policy.

B.

Configure Microsoft Entra authentication for SQLServer1.

C.

Create a Conditional Access policy.

D.

Configure federated client identity for SQLdb1.

E.

Configure a user-assigned managed identity for SQLdb1.

Question 8

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You create a user-assigned managed identity, assign the identity to each virtual machine, and then add each managed identity to a role on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 9

You need to implement the planned change for storage2 The solution must meet the technical requirements for storage encryption.

What should you do?

Options:

A.

Enable purge protection for storage2.

B.

Create an encryption scope in storage2.

C.

Configure storage2 to use an account encryption key.

D.

Assign an Azure role-based access control (Azure RBAC) role to storage2.

Question 10

Note. This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem

After you answer a question in this section, you will NOT be able to return. As a result these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution You create a hunting query.

Does this meet the goal’

Options:

A.

Yes

B.

No

Question 11

For which storage accounts can you implement the planned changes for storage?

Options:

A.

storage1, storage2, storage3, and storage4

B.

storage1, storage2, and storage4 only

C.

storage2 and storage4 only

D.

storage1 and storage3 only

E.

storage2, storage3, and storage4 only

F.

storage1 only

Question 12

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have a Microsoft Sentinel workspace

You have a multi-tier Security Operations Center (SOC) team.

You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.

Solution: You create an automation rule.

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 13

You need to protect the applications hosted on AKS1. The solution must meet the technical requirements.

Which Defender for Cloud plan should you enable?

Options:

A.

Microsoft Defender for Servers

B.

Microsoft Defender for App Service

C.

Microsoft Defender for Containers

D.

Microsoft Defender for Resource Manager

E.

Microsoft Defender for Storage

Question 14

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You create a private endpoint on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 15

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You add each virtual machine to a security group, and then add the security group to a role on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 16

You need to implement the planned change for the AKS1 integration.

What should you configure for AKS1?

Options:

A.

application scaling

B.

a workload identity

C.

Secrets Store CSI Driver

D.

Kubernetes role-based access control (Kubernetes RBAC)

Question 17

User1 has requested to use the AI Administrator role.

Which approvers can approve the request, and how long will User1 be an AI administrator after the role is approved? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Question 18

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You add each virtual machine to a role on storage1.

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 19

You need to configure Microsoft Sentinel to meet the technical requirements.

To what should you set Analytics retention for DnsEvents?

Options:

A.

2 years

B.

12 years

C.

180 days

D.

1 year

E.

6 years

Question 20

For each of the following statements, select Yes if the statement is true Otherwise, select No.

Options:

Question 21

You have an Azure subscription that contains the resources shown in the following table.

VM1 contains an application that accesses storage1. Another application accesses storage1 from a public IP address of 131.107.10.20.

For storage1, you set Public network access to Enabled from selected virtual networks and IP addresses. You add an IP network rule for 131.107.10.20.

After the configuration, only connections from 131.107.10.20 succeed.

You need to ensure that both VM1 and 131.107.10.20 can access storage1 over the public endpoint, while preventing all other access.

What should you do?

Options:

A.

Add a public IP address to VM1.

B.

Set Public network access to Enabled from all networks.

C.

Enable the Microsoft.Storage service endpoint for Subnet1.

Question 22

You have a hybrid Microsoft entra tenant named contoso.com that contains a user named Userl and the servers shown in the following table.

The tenant Is linked to an Azure subscription that contains a storage account named storage 1- The storage! account contains a file

share named Share1

User1 is assigned the Storage File Data SMB Share Contributor role for storage1.

The security protocol settings for the file shares for storage1 are configured as shown in the following exhibit.

Options:

Question 23

Vou have a Microsoft Entra tenant that uses Microsoft Entra Agent ID. You have multiple Microsoft Foundry agents that have agent identities assigned. Vou dm OW that one of the identities is flagged as high risk duf in unusual sign-in activity. Vou need to ensure that agent access to resources is restricted automatically based on risk. What should you create?

Options:

A.

a Privileged Identity Management (PIM) activation policy

B.

a Microsoft Entra role assignment policy

C.

a Conditional Access policy for the identities

D.

an Access review for the identities

Question 24

You have an Azure subscription named Sub1 that contains a storage account named storage1. Sub1 has Microsoft Defender for Storage enabled. Defender for Storage has malware scanning enabled.

You need to configure a solution that automates the remediation of malware detected in storage1.

What should you include in the solution?

Options:

A.

Application Insights

B.

Azure Event Hubs

C.

Azure Event Grid

D.

Azure Policy

Question 25

You have an Azure management group named MG1 that contains two subscriptions named Sub1 and Sub? Both subscriptions are linked to a Microsoft Entra tenant that contains a security group named Group!

You need to ensure that the members of Group1 can assign roles to the resources in Sub1 and Sub2. The solution must follow the principle of least privilege.

Which role should you assign to Group1?

Options:

A.

Contributor at the MG1 scope

B.

Contributor at the Sub1 and Sub2 scopes

C.

User Access Administrator at the MG1 scope

D.

Owner at the MG1 scope

Question 26

You use Microsoft Security Copilot.

You need to update Plugin settings. the solution must meet the following requirements:

• Allow contributors to use custom plug-ins without affecting either UMTS

• Limit publishing of custom plug-ins for other users to Owners only.

Which Plugin settings option should you configure for each requirement? To answer, drag the appropriate settings lo the correct requirements. Each setting may be used once, more than once., or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Options:

Question 27

You have an Azure subscription that has the Microsoft Defender for Cloud Foundational Cloud Security Posture Management (CSPM) plan enabled.

You have an Amazon Web Services (AWS) account connected to Defender for Cloud for posture management.

In Defender for Cloud, security recommendations for the resources in Azure and AWS have a risk level of Not evaluated.

You need to ensure that Defender for Cloud assigns a risk level to the recommendations.

What should you do?

Options:

A.

Onboard all the virtual machines in the AWS account to Azure Arc.

B.

Enable Microsoft Defender for Servers Plan 2.

C.

Assign the CIS AWS Foundations v3.0.0 standard to the AWS account.

D.

Enable the Defender CSPM plan.

Question 28

You have an Azure subscription that contains the following resources:

•An Azure SQL Database logical server named Server1 that contains a database named DB1

•An Azure SQL Managed Instance named Instance1 that contains a database named DB2

You need to configure database auditing. The solution must meet the following requirements:

•Ensure that audit data is centrally available in a location that supports for KQL queries.

•Minimize ongoing administrative effort as additional databases are added.

What should you configure? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Question 29

You have an Azure subscription named Sub1 that contains multiple virtual machines. Sub1 has the Microsoft Defender Cloud Security Posture Management (CSPM) plan enabled.

You discover that Defender for Cloud fails to identify plaintext connection strings and SSH keys stored on the virtual machines.

You need to ensure that secrets can be identified on the virtual machines.

What should you do?

Options:

A.

Configure the Defender for Cloud data connector in Microsoft Sentinel.

B.

Enable agentless machine scanning.

C.

Deploy the Azure Monitor Agent to all the virtual machines.

D.

Enable Microsoft Defender for Key Vault.

Question 30

You have an Azure subscription that contains three storage accounts, an Azure SQL managed instance named SQL1, and three Azure SQL databases.

The storage accounts are configured as shown in the following table.

Options:

Question 31

You have a Microsoft Defender External Attack Surface Management (Defender EASM) resource that discovers internet-facing assets for a company named Contoso, Ltd.

You need to classify the assets lo meet the following requirements.

• Third-party infrastructure assets must be tracked separately from assets owned by Contoso.

• Assets with unconfirmed ownership must remain outside the owned inventory until ownership is verified.

How should you classify the assets? To answer, drag the appropriate asset states to the correct assets. Each state may be used once, more than once or not at all. You may need to drag the split bar between panes or scroll to view content.

Options:

Question 32

You have a Microsoft Defender XDR environment.

You have a Microsoft Power Platform environment where makers publish custom Microsoft Copilot Studio agents.

You need to enable real-time protection so that suspicious tool invocations are blocked before an agent runs actions, and related alerts appear in the Microsoft Defender portal.

What should you do? To answer, drag the appropriate actions to the correct services. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Options:

Question 33

You have an Azure virtual network that contains 100 virtual machines and an Azure Firewall instance named FW1.

All the traffic from the virtual machines is routed through FW1.

You need to ensure that FW1 allows access to only a URL of updates contoso.com and blocks all other outbound traffic.

What should you use?

Options:

A.

An inbound NAT rule

B.

An application rule

C.

An outbound NAT rule

D.

A network rule

Question 34

You use Azure Virtual Network Manager to manage multiple virtual networks in a network group named Group1

You discover that the virtual machines in Group1 are accessible from the internet by using TCP port 3389.

You need to block inbound TCP 3389 from the internet across all the virtual networks in Group1 The solution must minimize administrative effort.

What should you use?

Options:

A.

A connectivity configuration

B.

A security admin configuration

C.

A user-defined route (UDR)

D.

A network security group (NSG)

Question 35

You have a Microsoft Entra tenant.

You need to implement password less authentication. The solution must meet the following requirements:

•Users can sign in without a password by using a mobile device.

•New users that sign in for the first time must use a helpdesk issued sign in method that expires.

Which authentication method should you enable for each requirement? To answer, drag the appropriate methods to the correct requirements. Each method may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Options:

Question 36

You have an Azure Logic Apps Consumption workflow that uses a Request trigger. All supported authentication methods are enabled on the Request trigger

You need to ensure that the endpoint accepts only OAuth-based requests. The solution must minimize costs.

What should you do?

Options:

A.

Use OAuth 2.0 authorization.

B.

Enable Secure Inputs and enable Secure Outputs for the Request trigger.

C.

Disable shared access signature (SAS) authentication for the Request trigger.

D.

Deploy Azure API Management.

Question 37

You have an Azure subscription named Sub1 that contains an Azure Kubernetes Service (AKS) cluster named cluster1 and an Azure container registry named ACR1 Sub1 has Microsoft Defender for Containers enabled, and runtime protection is active on cluster!

The developers at your company deploy pods that have elevated privileges, and the deployments are created in cluster1

You need to prevent pods with elevated privileges from being accepted by cluster!

What should you do?

Options:

A.

Create an Azure Policy for cluster1.

B.

Enable agentless discovery for Kubernetes in Defender for Containers.

C.

Configure runtime threat protection alerts for privileged container activity.

D.

Enable vulnerability assessment for images in ACR1.

Question 38

You have an Azure Storage account named storage1 that hosts a blob container named container1.

You have an Azure Functions app named app1 that uses a managed identity.

You need to configure app1 to read, write, and delete blobs in container1. The solution must follow the principle of least privilege.

What should you do?

Options:

A.

Assign the Storage Account Contributor role to the managed identity of app1 at the scope of storage1.

B.

Assign the Storage Blob Delegator role to the managed identity of app1 at the scope of container1.

C.

Assign the Owner role to the managed identity of app1 at the scope of container1.

D.

Assign the Storage Blob Data Contributor role to the managed identity of app1 at the scope of container1.

Question 39

You have a Microsoft Entra tenant.

On January 1, you configure a Multifactor authentication registration policy that has the following settings

• Assignments: All users

• Require Microsoft Entra ID multifactor authentication registration: Enabled

• Enforce policy: On

On January 3, you create two new users named User1 and User2.

On January 5, User1 authenticates to Microsoft Entra ID for the first time. On January 7, User2 authenticates to Microsoft Entra ID for the first time.

On which date will User1 and User2 be forced to register for MFA? To answer, drag the appropriate dates to the correct users. Each date may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Options:

Question 40

You have an Azure subscription named Sub1 that contains an Azure Database for PostgreSQL instance Sub1 has Microsoft Defender for Cloud enabled.

You need to configure Microsoft Defender for Databases to minimize costs.

Which Defender plan should you enable?

Options:

A.

Microsoft Defender for Servers

B.

Microsoft Defender for Open-Source Relational Databases

C.

Microsoft Defender for SQL Servers on Machines

D.

Microsoft Defender for Azure SQL Databases

E.

Microsoft Defender for Storage

Page: 1 / 10
Total 135 questions