Month End Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: newyear

Microsoft SC-500 - Microsoft Certified: Cloud and AI Security Engineer Associate

Page: 2 / 4
Total 135 questions

You need to delegate a user to implement the planned change for Defender for Cloud. The solution must follow the principle of least privilege.

Which user should you choose?

A.

Admin1

B.

Admin2

C.

Admin3

D.

Admin4

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You create a user-assigned managed identity, assign the identity to each virtual machine, and then add each managed identity to a role on storage1.

Does this meet the goal?

A.

Yes

B.

No

You use Microsoft Security Copilot.

Users are assigned either the Security Copilot Contributor role or the Security Copilot Owner role.

A contributor enables a custom plugin that is NOT approved, and some Security Copilot features in embedded experiences no longer function.

You need to ensure that plugins affecting all users can only be added by owners.

What should you do in the Plugin settings?

A.

Select Contributors and Owners to configure which users can add custom plugins at the user scope.

B.

Select Contributors and Owners to configure which users can add custom plugins at the workspace scope.

C.

Select Owners only to configure which users can add custom plugins at the workspace scope.

D.

Select Owners only to configure which users can add custom plugins at the user scope.

You have an Azure subscription named Sub1. Sub1 contains 20 virtual machines that run Windows Server.

Sub1 has the Microsoft Defender for Cloud Defender Cloud Security Posture Management (CSPM) plan enabled.

You need to ensure that all the virtual machines are scanned automatically for known security flaws and misconfigurations.

What should you use?

A.

Attack path analysis

B.

Microsoft Cloud Security Benchmark (MCSB)

C.

Cloud security explorer

D.

Just-in-time (JIT) VM access

E.

Vulnerability assessment on the virtual machines

You have an Azure Storage account named storage1 that hosts a blob container named container1.

You have an Azure Functions app named app1 that uses a managed identity.

You need to configure app1 to read, write, and delete blobs in container1. The solution must follow the principle of least privilege.

What should you do?

A.

Assign the Storage Account Contributor role to the managed identity of app1 at the scope of storage1.

B.

Assign the Storage Blob Delegator role to the managed identity of app1 at the scope of container1.

C.

Assign the Owner role to the managed identity of app1 at the scope of container1.

D.

Assign the Storage Blob Data Contributor role to the managed identity of app1 at the scope of container1.

You have an Azure subscription named Sub1 that contains multiple virtual machines. Sub1 has the Microsoft Defender Cloud Security Posture Management (CSPM) plan enabled.

You discover that Defender for Cloud fails to identify plaintext connection strings and SSH keys stored on the virtual machines.

You need to ensure that secrets can be identified on the virtual machines.

What should you do?

A.

Configure the Defender for Cloud data connector in Microsoft Sentinel.

B.

Enable agentless machine scanning.

C.

Deploy the Azure Monitor Agent to all the virtual machines.

D.

Enable Microsoft Defender for Key Vault.

You have an Azure subscription.

You have the following custom role-based access control (RBAC) role definition

You need to implement the planned change for SQLdb1

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point

A.

Create a compliance policy.

B.

Configure Microsoft Entra authentication for SQLServer1.

C.

Create a Conditional Access policy.

D.

Configure federated client identity for SQLdb1.

E.

Configure a user-assigned managed identity for SQLdb1.

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.

After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.

You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.

You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.

You need to ensure that VM1 and VM2 can access storage1.

Solution: You add each virtual machine to a role on storage1.

Does this meet the goal?

A.

Yes

B.

No

For which storage accounts can you implement the planned changes for storage?

A.

storage1, storage2, storage3, and storage4

B.

storage1, storage2, and storage4 only

C.

storage2 and storage4 only

D.

storage1 and storage3 only

E.

storage2, storage3, and storage4 only

F.

storage1 only