我々はSC-500問題集の英語版と日本語版を開発しています。英語版と日本語版の内容が同じですが、言葉だけ違います。SC-500問題集に英語試験と日本語試験を準備する受験者たちは気楽に試験に合格することができます。それに、我々のMicrosoftのSC-500日本語版問題集を購入するなら、英語版をおまけにさし上げます。
| Section | Weight | Objectives |
|---|---|---|
| Manage identity, access, and governance | 20–25% | - Secure secrets and keys using Azure Key Vault
|
| Manage and monitor security posture | 20–25% | - Microsoft Defender for Cloud
|
| Secure compute | 20–25% | - Servers and virtual machines
|
| Secure storage, databases, and networking | 25–30% | - Network security
|
Tech4ExamのSC-500問題集を使用した後、あなたはたくさんののSC-500試験資料を勉強するとか、専門のトレーニング機構に参加するとかなど必要がないと認識します。Tech4Exam SC-500問題集は試験の範囲を広くカバーするだけでなく、質は高いです。Tech4ExamのSC-500問題集を購入し勉強するだけ、あなたは試験にたやすく合格できます。
質問 # 105
You have an Azure Container Registry named ContReg1 that contains a container Image named image1.
You enable content trust for ContReg1.
After content trust is enabled, you push two images to ContReg1 as shown in the following table.
Which images ate trusted images?
正解:A
解説:
Only image2 is trusted. Azure Container Registry ' s Docker Content Trust (DCT) implementation identifies trusted image tags by cryptographic signatures generated when a publisher pushes an image with client-side Docker Content Trust enabled .
Microsoft explains that enabling DCT at the registry level allows clients to push signed images, but enabling the registry feature does not retroactively sign existing images . Therefore, image1, which already existed before content trust was enabled, doesn ' t automatically become trusted. Microsoft Learn Image2 is pushed after registry content trust is enabled and with client content trust enabled . Its Docker client therefore signs and publishes the corresponding trust metadata, making image2 the trusted image.
Image3 is pushed with client content trust disabled, so it remains unsigned even though the registry itself supports DCT. Microsoft explicitly notes that a DCT-enabled registry can still contain a mixture of signed and unsigned image tags .
There is also a current platform lifecycle point: Microsoft stopped allowing Docker Content Trust to be newly enabled on registries that hadn ' t previously enabled it beginning May 31, 2026 , and DCT is scheduled for complete removal on March 31, 2028. The question nevertheless tests the documented DCT trust semantics.
質問 # 106
You have an Azure subscription named Sub1 that contains an Azure SQL Database logical server named Served.
Server 1 contains a database named D81
Microsoft Defender for Cloud security alerts are being generated for Sub1.
You plan 1o improve investigation capabilities when Microsoft Defender for SOL raises Advanced Threat Profection alerts.
You need to ensure that the Advanced Threat Protection investigations have the audit records of DB1. The solution must include the recommended audit action groups.
How should you configure database auditing for Served? To answer, drag the appropriate action groups to the correct requirements. Each action group may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
正解:
解説:
Explanation:
For successful database logins, configure SUCCESSFUL_DATABASE_AUTHENTICATION_GROUP .
This action group records successful authentication events against the Azure SQL database and supplies identity and connection information that can be valuable during Microsoft Defender for SQL investigations.
For unsuccessful login attempts, configure FAILED_DATABASE_AUTHENTICATION_GROUP . It records failed database authentication attempts, which are particularly relevant to Defender for SQL detections involving suspicious login activity, credential attacks, or anomalous access attempts.
Microsoft ' s Azure SQL auditing documentation identifies a recommended default set of database audit action groups consisting of BATCH_COMPLETED_GROUP , SUCCESSFUL_DATABASE_AUTHENTICATION_GROUP , and FAILED_DATABASE_AUTHENTICATION_GROUP . Together, these capture executed queries and stored procedures plus successful and failed database authentication events. Microsoft specifically warns against unnecessarily combining the recommended set with overlapping action groups because this can generate duplicate audit records. Microsoft Learn For the two authentication requirements represented in this drag-and-drop item, the corresponding selections are therefore the successful and failed database authentication groups. These audit records enrich Defender for SQL Advanced Threat Protection investigations with the authentication context needed to analyze suspicious database activity.
質問 # 107
You need to implement the planned change for storage2. The solution must meet the technical requirements for storage encryption.
What should you do?
正解:A
解説:
Storage2 must be configured to use an account encryption key. The planned storage account must support Azure Table storage , while the technical requirement specifies that all storage data must be encrypted using Fabrikam-managed keys , meaning customer-managed keys (CMKs).
Azure Storage treats Table and Queue encryption differently from Blob Storage and Azure Files. Microsoft states that to encrypt Table Storage or Queue Storage with a customer-managed key , the storage account must be configured at creation time to use an encryption key scoped to the account rather than the default service-scoped key. After creation, this setting cannot be changed. Microsoft Learn An encryption scope does not solve this requirement because encryption scopes apply to Blob Storage containers and individual blobs , not Azure Table data. Microsoft Learn An Azure RBAC assignment may later be required so that the storage account ' s managed identity can access the customer-managed key in Key Vault, but it does not itself configure Table Storage to support account- level CMK encryption. Purge protection applies to Azure Key Vault rather than storage2.
Therefore, when storage2 is created, configure Table Storage to use the account encryption key .
質問 # 108
You have an Azure Subscription that contains the storage accounts shown in the following table.
You enable Microsoft Defender for Storage.
Which storage services of storage5 are monitored by Microsoft for Storage which storage accounts are protected by.
正解:
解説:
Explanation:
質問 # 109
You need to configure the AKS1 and ID 1 managed identities to meet the technical requirements. The solution must follow the principle of least privilege.
Which role should you assign to each identity? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
正解:
解説:
Explanation:
AKS1: AcrPull; ID1: Contributor
AKS1 needs to pull images from Azure Container Registry, so AcrPull is the least-privilege registry role for the cluster identity. ID1 requires Contributor in the visible answer area because the referenced technical requirement requires resource changes beyond a read-only or pull-only role. The important distinction is scope: AKS image retrieval should not receive Contributor, while the separate managed identity receives the broader role only for its implementation task. This domain is tested through precise scope control: tenant, subscription, resource, application, and data-plane authorization are not interchangeable. The correct choice applies the smallest identity or governance control that enforces the stated requirement. Options that only add users, create registrations, or provide broad administrator access fail because they do not directly enforce the requested access behavior. The result is a direct exam-style implementation choice: it changes the required security behavior without relying on unrelated monitoring, manual cleanup, or excessive privilege. Official Microsoft source/topic: SC-500 Study Guide > AKS and managed identities; Microsoft Learn > ACR pull role and Azure RBAC.
Category Breakdown
Category Number of Questions
Manage identity, access, and governance 40
Manage and monitor security posture 30
Secure compute 31
Secure storage, databases, and networking 34
TOTAL 135
Exam Topic Breakdown
Exam Topic Number of Questions
質問 # 110
......
市場には試験に関する多くの学習資料があるため、当社からSC-500準備ガイドを選択する決定を下すことは容易ではありません。ただし、当社からSC-500テストプラクティスファイルを購入することに決めた場合は、ここ数年で行った最良の決定の1つになることをお知らせします。私たちに知られているように、当社のSC-500準備資料は、この分野の有名な専門家や教授の多くによって設計されています。 SC-500準備ガイドが想像を超えた高品質であることは間違いありません。
SC-500受験記: https://www.tech4exam.com/SC-500-pass-shiken.html