Perhaps now you are one of the candidates of the SC-500 exam, perhaps now you are worried about not passing the exam smoothly. Now we have good news for you: our SC-500 study materials will solve all your worries and help you successfully pass it. With the high pass rate as 98% to 100%, you will find that we have the best SC-500 learning braindumps which contain the most accurate real exam questions.
| Section | Weight | Objectives |
|---|---|---|
| Topic 1: Secure storage, databases, and networking | 25–30% | - Network security
|
| Topic 2: Manage identity, access, and governance | 20–25% | - Secure secrets and keys using Azure Key Vault
|
| Topic 3: Secure compute | 20–25% | - Servers and virtual machines
|
| Topic 4: Manage and monitor security posture | 20–25% | - Microsoft Sentinel
|
iPassleader has built customizable Microsoft SC-500 practice exams (desktop software & web-based) for our customers. Users can customize the time and Implementing End-to-End Security Controls for Cloud and AI Workloads (SC-500) questions of Microsoft SC-500 Practice Tests according to their needs. You can give more than one test and track the progress of your previous attempts to improve your marks on the next try.
NEW QUESTION # 124
You have an Azure subscription named Sub1. Sub1 contains 60 virtual machines that run either Window Server or Linux.
All the Windows Server virtual machines host line-of-business (LOB) applications and all the Linux virtual machines host backend databases.
You need to enable malware protection for the virtual machines.
Which Microsoft Defender for Cloud plan should you enable for each type of virtual machine? To answer, drag the appropriate plans to the correct virtual machine types. Each plan may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
Virtual machine type
Plan
Windows Server
Microsoft Defender for Servers
Linux
Microsoft Defender for Servers
Microsoft Defender for Servers is the correct plan for both the Windows Server and Linux virtual machines because the requirement is to provide malware protection at the virtual-machine operating-system level .
Defender for Servers protects both Windows and Linux VMs and integrates with Microsoft Defender for Endpoint to provide endpoint protection, including antimalware capabilities. Microsoft states that Defender for Servers supports Windows and Linux virtual machines across Azure and other supported environments.
For Linux systems, Defender for Servers deploys the Defender for Endpoint component that includes antimalware functionality. For Windows Server, Defender Antivirus is integrated with Defender for Endpoint and provides malware protection. In addition, Defender for Servers Plan 2 supports agentless malware scanning , which scans VM disks for malicious files without installing an additional scanning agent.
The fact that the Linux machines host databases does not make Microsoft Defender for Databases the correct answer. Defender for Databases protects supported database workloads against database-specific threats; it does not replace VM-level malware protection.
The SC-500 study guide places onboarding and configuring VMs with Defender for Servers under the Secure compute objective.
NEW QUESTION # 125
Drag and Drop Question
You have a Microsoft Defender External Attack Surface Management (Defender EASM) resource that discovers internet-facing assets for a company named Contoso, Ltd.
You need to classify the assets to meet the following requirements:
- Third-party infrastructure assets must be tracked separately from
assets owned by Contoso.
- Assets with unconfirmed ownership must remain outside the owned
inventory until ownership is verified.
How should you classify the assets? To answer, drag the appropriate asset states to the correct assets. Each state may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
Box 1: Dependency
To best meet this requirement, you should assign the "Dependencies" state to the discovered third-party infrastructure assets, while keeping company-owned assets in the "Approved Inventory" state.
Microsoft Defender External Attack Surface Management (Defender EASM) utilizes predefined classification states to help organizations organize, monitor, and separate their inventory:
Approved Inventory: This state represents the core attack surface directly owned, controlled, and managed by your company. Assets placed here are continuously scanned and populated into default dashboard charts.
Dependencies: This state is purposefully designed for third-party infrastructure that your company relies upon but does not directly own or manage (e.g., third-party SaaS applications, external hosting partners, or web dependencies).
Box 2: Candidate
To meet the requirement of keeping assets with unconfirmed ownership outside the owned inventory, you should classify them into the Candidate state.
Candidate: Discovered assets that have a high likelihood of belonging to your organization but require manual verification to confirm ownership. They remain excluded from your primary owned inventory until approved.
Reference:
https://learn.microsoft.com/en-us/azure/external-attack-surface-management/overview
NEW QUESTION # 126
An organization wants to prevent accidental deployment of AI resources in regions that are not approved by regulatory requirements. Which Azure governance feature should be used?
Answer: B
Explanation:
Azure Policy can enforce compliance requirements by restricting resource deployments to approved regions. Policies can deny noncompliant deployments before resources are created.
Azure Advisor provides recommendations, while Azure Monitor and Automation focus on monitoring and operational tasks rather than governance enforcement.
NEW QUESTION # 127
You have a Microsoft Entra tenant that has user consent for applications disabled.
You register an application named App1 that requests the following Microsoft Graph delegated permissions:
- User.Read
- Mail.Read
You need to configure tenant permissions to meet the following requirements:
- Enable users to grant consent for low-risk permissions without
administrator interaction.
- Ensure that applications requesting higher-privilege permissions
require administrator approval.
What should you do?
Answer: C
Explanation:
An app consent policy defines the conditions under which users can consent to delegated permissions, such as permitting approved low-risk permissions while withholding consent rights for higher-privilege permissions. Permissions outside the allowed policy conditions require administrator consent or approval.
Reference:
https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/manage-app-consent-policies?pivots=ms-powershell
https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/configure-user-consent?pivots=portal
NEW QUESTION # 128
You have a Microsoft Foundry project that contains a model deployment named Deployment1.
Deployment1 contains an agent named Agent1 that uses an existing default guardrail configuration.
You discover that Agent1 generates tool calls that contain harmful language.
You need to ensure that Agent1 responses containing harmful content are prevented from running. The solution must prevent changes to the configuration of Deployment1.
What should you do?
Answer: C
Explanation:
Create a custom guardrail and assign it directly to Agent1 . Microsoft Foundry supports guardrails at both the model-deployment level and the individual-agent level. If an agent has a custom guardrail assigned directly to it, the agent-level guardrail takes precedence over the guardrail inherited from its underlying model deployment . This allows Agent1 to receive stronger runtime protections without modifying Deployment1 or affecting other agents that use the same deployment.
Foundry guardrails can be configured at multiple intervention points , including user input, tool calls , tool responses, and final output. This is critical here because the unsafe content appears in Agent1 ' s tool calls. A custom guardrail can therefore apply the appropriate harmful-content controls before the tool invocation executes, causing content that exceeds the configured safety threshold to be blocked.
An automatic evaluation measures agent behavior but does not provide runtime enforcement. A red teaming run identifies security and safety weaknesses but likewise does not block production tool calls. Fine- tuning changes model behavior and is neither a deterministic content-enforcement mechanism nor necessary for this requirement.
The SC-500 study guide explicitly includes Configure guardrails for agent security in Foundry under the Secure compute domain
NEW QUESTION # 129
......
To pass the Microsoft SC-500 exam on the first try, candidates need Implementing End-to-End Security Controls for Cloud and AI Workloads updated practice material. Preparing with real SC-500 exam questions is one of the finest strategies for cracking the exam in one go. Students who study with Microsoft SC-500 Real Questions are more prepared for the exam, increasing their chances of succeeding.
SC-500 Authorized Pdf: https://www.ipassleader.com/Microsoft/SC-500-practice-exam-dumps.html