Microsoft SC-500 - Microsoft Certified: Cloud and AI Security Engineer Associate
You have a Microsoft Sentinel workspace named Workspace1
You have 100 on-premises servers that run Linux and have the Azure Monitor Agent installed.
You need to collect Syslog events from the Linux servers. The solution must meet the following requirements:
•Ensure that filtering occurs before data is written to Workspace1
•Reduce ingestion costs by excluding low value Syslog messages.
What should you include in the solution?
You have a Microsoft Defender External Attack Surface Management (Defender EASM) resource that discovers internet-facing assets for a company named Contoso, Ltd.
You need to classify the assets lo meet the following requirements.
• Third-party infrastructure assets must be tracked separately from assets owned by Contoso.
• Assets with unconfirmed ownership must remain outside the owned inventory until ownership is verified.
How should you classify the assets? To answer, drag the appropriate asset states to the correct assets. Each state may be used once, more than once or not at all. You may need to drag the split bar between panes or scroll to view content.

You have an Azure subscription named Sub1 that contains 50 virtual machines. Sub1 has Microsoft Defender for Cloud enabled.
Sub1 contains an Azure key vault named KV1 and an Azure policy that enforces storing all secrets in KV1.
Occasionally, the developers at your company store plaintext tokens and SSH private keys on the virtual machines.
You need to configure Defender for Cloud to detect plaintext secrets on the virtual machines. The solution must minimize administrative changes to the virtual machines.
How should you configure Defender for Cloud? To answer, select the appropriate options in the answer area
NOTE: Each correct selection is worth one point.

You have an Azure subscription that contains an Azure Database for PostgreSQL instance named 081.
You plan to protect OBI by using Microsoft Defender for Cloud.
You need to configure Defender for Cloud to detect anomalous activities and database exploitations for 061. The solution must NOT affect any other databases.
What should you enable? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You use Azure Virtual Network Manager to manage multiple virtual networks organized into two network groups named Production and Development.
You need to configure Virtual Network Manager to meet the following requirements:
Allow traffic between all the virtual networks in Production.
Block traffic between Development and Production.
What should you use for each requirement? To answer, drag the components to the correct requirements. Each component may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

You have an Azure subscription that contains the resources shown in the following table.

VM1 contains an application that accesses storage1. Another application accesses storage1 from a public IP address of 131.107.10.20.
For storage1, you set Public network access to Enabled from selected virtual networks and IP addresses. You add an IP network rule for 131.107.10.20.
After the configuration, only connections from 131.107.10.20 succeed.
You need to ensure that both VM1 and 131.107.10.20 can access storage1 over the public endpoint, while preventing all other access.
What should you do?
You have an Azure subscription named Sub1 that contains multiple virtual machines.
You have a Microsoft 365 E5 subscription that contains devices onboarded to Microsoft Defender for Endpoint.
You have an on-premises datacenter that contains multiple servers.
You plan to onboard all existing and future on-premises servers to Azure Arc.
You need to ensure that the Azure Arc-enabled servers are protected by using the same security features as the Microsoft 365 devices immediately after the servers are onboarded. The solution must minimize administrative effort.
What should you do?
You have a Microsoft Entra tenant that contains a user named User1.
You have an Azure Arc-enabled server named SRV1 that runs Windows Server. SRV1 is configured for Microsoft Entra sign-in.
User1 reports that when they use their Microsoft Entra credentials to sign in to SRV1 over RDP, they receive the following message:
“Your account is configured to prevent you from using this device.â€
You need to ensure that User1 can sign in to SRV1 over RDP. The solution must follow the principle of least privilege.
What should you do?
You have an Azure API Management instance named APIM1.
You have a partner company that accesses an API in APIM1 by using subscription keys.
A backend API key is stored in a named value in APIM1.
Microsoft Defender for Cloud generates the following recommendation: “API Management secret named values should be stored in Azure Key Vault.â€
You need to address the recommendation.
What should you do first?
You have an Azure subscription named Sub1 that contains a storage account named storage1. Sub1 has Microsoft Defender for Storage enabled. Defender for Storage has malware scanning enabled.
You need to configure a solution that automates the remediation of malware detected in storage1.
What should you include in the solution?





