SC-500過去問 & SC-500受験記

我々はSC-500問題集の英語版と日本語版を開発しています。英語版と日本語版の内容が同じですが、言葉だけ違います。SC-500問題集に英語試験と日本語試験を準備する受験者たちは気楽に試験に合格することができます。それに、我々のMicrosoftのSC-500日本語版問題集を購入するなら、英語版をおまけにさし上げます。

Microsoft SC-500 Exam Syllabus Topics:

SectionWeightObjectives
Manage identity, access, and governance20–25%- Secure secrets and keys using Azure Key Vault
  • 1. Defender for Key Vault and CSPM scanning
    • 2. Key Vault deployment and configuration
      • 3. Keys, secrets, and certificates management
        • 4. Access policies and firewall settings
          - Governance and compliance enforcement
          • 1. Azure Policy (built-in and custom)
            • 2. Microsoft Defender for Cloud compliance
              • 3. Infrastructure as Code security controls
                • 4. Azure Backup security controls
                  • 5. Resource locks
                    • 6. RBAC and role management (Azure & Entra roles)
                      - Secure access to resources by using Microsoft Entra ID
                      • 1. Conditional Access policies
                        • 2. Enterprise applications and app registrations
                          • 3. Privileged Identity Management (PIM)
                            • 4. Managed identities for Azure resources
                              • 5. Authentication methods (MFA, passwordless)
                                • 6. OAuth consent and permission grants
                                  Manage and monitor security posture20–25%- Microsoft Defender for Cloud
                                  • 1. Multi-cloud (AWS/GCP) integration
                                    • 2. Defender CSPM risk identification
                                      • 3. External Attack Surface Management (EASM)
                                        • 4. Workload protection plans
                                          • 5. Compliance frameworks evaluation
                                            • 6. Defender Vulnerability Management
                                              - Microsoft Sentinel
                                              • 1. Workspaces and role assignment
                                                • 2. Automation rules and playbooks
                                                  • 3. Data collection rules and WEF
                                                    • 4. Retention policies
                                                      • 5. Data connectors (Azure, syslog, CEF)
                                                        • 6. Custom logs and tables
                                                          - Security Copilot
                                                          • 1. Workspace configuration
                                                            • 2. Permissions and roles
                                                              • 3. Plugins and integrations
                                                                • 4. Security Store agents
                                                                  Secure compute20–25%- Servers and virtual machines
                                                                  • 1. Just-in-time (JIT) VM access
                                                                    • 2. Azure Arc hybrid security
                                                                      • 3. Azure Bastion
                                                                        • 4. Agentless scanning and EDR
                                                                          • 5. Disk encryption
                                                                            • 6. Defender for Servers onboarding
                                                                              • 7. Secure boot and vTPM
                                                                                - Application platform security
                                                                                • 1. API Management security policies
                                                                                  • 2. Container Registry security
                                                                                    • 3. App Service security controls
                                                                                      • 4. Web Application Firewall (WAF)
                                                                                        • 5. AKS security and Defender for Containers
                                                                                          • 6. Azure Functions security
                                                                                            - Security for AI workloads
                                                                                            • 1. Defender for AI services
                                                                                              • 2. Microsoft Purview DSPM for AI
                                                                                                • 3. Entra Agent ID security and access control
                                                                                                  • 4. Microsoft Copilot and AI risk identification
                                                                                                    • 5. Security Copilot agents and monitoring
                                                                                                      • 6. AI Gateway (Azure API Management)
                                                                                                        Secure storage, databases, and networking25–30%- Network security
                                                                                                        • 1. Virtual WAN security
                                                                                                          • 2. Azure Firewall
                                                                                                            • 3. VPN security
                                                                                                              • 4. NSGs and ASGs
                                                                                                                • 5. Azure Virtual Network Manager
                                                                                                                  • 6. Private endpoints and Private Link
                                                                                                                    • 7. Network Watcher diagnostics
                                                                                                                      - Database security
                                                                                                                      • 1. Azure SQL security configuration
                                                                                                                        • 2. Defender for Databases
                                                                                                                          • 3. Database auditing
                                                                                                                            - Storage security
                                                                                                                            • 1. Storage account security configuration
                                                                                                                              • 2. Storage firewall rules
                                                                                                                                • 3. Access policies for storage
                                                                                                                                  • 4. Defender for Storage

                                                                                                                                    >> SC-500過去問 <<

                                                                                                                                    有難いSC-500過去問 & 合格スムーズSC-500受験記 | 完璧なSC-500試験対策

                                                                                                                                    Tech4ExamのSC-500問題集を使用した後、あなたはたくさんののSC-500試験資料を勉強するとか、専門のトレーニング機構に参加するとかなど必要がないと認識します。Tech4Exam SC-500問題集は試験の範囲を広くカバーするだけでなく、質は高いです。Tech4ExamのSC-500問題集を購入し勉強するだけ、あなたは試験にたやすく合格できます。

                                                                                                                                    Microsoft Implementing End-to-End Security Controls for Cloud and AI Workloads 認定 SC-500 試験問題 (Q105-Q110):

                                                                                                                                    質問 # 105
                                                                                                                                    You have an Azure Container Registry named ContReg1 that contains a container Image named image1.
                                                                                                                                    You enable content trust for ContReg1.
                                                                                                                                    After content trust is enabled, you push two images to ContReg1 as shown in the following table.

                                                                                                                                    Which images ate trusted images?

                                                                                                                                    正解:A

                                                                                                                                    解説:
                                                                                                                                    Only image2 is trusted. Azure Container Registry ' s Docker Content Trust (DCT) implementation identifies trusted image tags by cryptographic signatures generated when a publisher pushes an image with client-side Docker Content Trust enabled .
                                                                                                                                    Microsoft explains that enabling DCT at the registry level allows clients to push signed images, but enabling the registry feature does not retroactively sign existing images . Therefore, image1, which already existed before content trust was enabled, doesn ' t automatically become trusted. Microsoft Learn Image2 is pushed after registry content trust is enabled and with client content trust enabled . Its Docker client therefore signs and publishes the corresponding trust metadata, making image2 the trusted image.
                                                                                                                                    Image3 is pushed with client content trust disabled, so it remains unsigned even though the registry itself supports DCT. Microsoft explicitly notes that a DCT-enabled registry can still contain a mixture of signed and unsigned image tags .
                                                                                                                                    There is also a current platform lifecycle point: Microsoft stopped allowing Docker Content Trust to be newly enabled on registries that hadn ' t previously enabled it beginning May 31, 2026 , and DCT is scheduled for complete removal on March 31, 2028. The question nevertheless tests the documented DCT trust semantics.


                                                                                                                                    質問 # 106
                                                                                                                                    You have an Azure subscription named Sub1 that contains an Azure SQL Database logical server named Served.
                                                                                                                                    Server 1 contains a database named D81
                                                                                                                                    Microsoft Defender for Cloud security alerts are being generated for Sub1.
                                                                                                                                    You plan 1o improve investigation capabilities when Microsoft Defender for SOL raises Advanced Threat Profection alerts.
                                                                                                                                    You need to ensure that the Advanced Threat Protection investigations have the audit records of DB1. The solution must include the recommended audit action groups.
                                                                                                                                    How should you configure database auditing for Served? To answer, drag the appropriate action groups to the correct requirements. Each action group may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
                                                                                                                                    NOTE: Each correct selection is worth one point.

                                                                                                                                    正解:

                                                                                                                                    解説:

                                                                                                                                    Explanation:

                                                                                                                                    For successful database logins, configure SUCCESSFUL_DATABASE_AUTHENTICATION_GROUP .
                                                                                                                                    This action group records successful authentication events against the Azure SQL database and supplies identity and connection information that can be valuable during Microsoft Defender for SQL investigations.
                                                                                                                                    For unsuccessful login attempts, configure FAILED_DATABASE_AUTHENTICATION_GROUP . It records failed database authentication attempts, which are particularly relevant to Defender for SQL detections involving suspicious login activity, credential attacks, or anomalous access attempts.
                                                                                                                                    Microsoft ' s Azure SQL auditing documentation identifies a recommended default set of database audit action groups consisting of BATCH_COMPLETED_GROUP , SUCCESSFUL_DATABASE_AUTHENTICATION_GROUP , and FAILED_DATABASE_AUTHENTICATION_GROUP . Together, these capture executed queries and stored procedures plus successful and failed database authentication events. Microsoft specifically warns against unnecessarily combining the recommended set with overlapping action groups because this can generate duplicate audit records. Microsoft Learn For the two authentication requirements represented in this drag-and-drop item, the corresponding selections are therefore the successful and failed database authentication groups. These audit records enrich Defender for SQL Advanced Threat Protection investigations with the authentication context needed to analyze suspicious database activity.


                                                                                                                                    質問 # 107
                                                                                                                                    You need to implement the planned change for storage2. The solution must meet the technical requirements for storage encryption.
                                                                                                                                    What should you do?

                                                                                                                                    正解:A

                                                                                                                                    解説:
                                                                                                                                    Storage2 must be configured to use an account encryption key. The planned storage account must support Azure Table storage , while the technical requirement specifies that all storage data must be encrypted using Fabrikam-managed keys , meaning customer-managed keys (CMKs).
                                                                                                                                    Azure Storage treats Table and Queue encryption differently from Blob Storage and Azure Files. Microsoft states that to encrypt Table Storage or Queue Storage with a customer-managed key , the storage account must be configured at creation time to use an encryption key scoped to the account rather than the default service-scoped key. After creation, this setting cannot be changed. Microsoft Learn An encryption scope does not solve this requirement because encryption scopes apply to Blob Storage containers and individual blobs , not Azure Table data. Microsoft Learn An Azure RBAC assignment may later be required so that the storage account ' s managed identity can access the customer-managed key in Key Vault, but it does not itself configure Table Storage to support account- level CMK encryption. Purge protection applies to Azure Key Vault rather than storage2.
                                                                                                                                    Therefore, when storage2 is created, configure Table Storage to use the account encryption key .


                                                                                                                                    質問 # 108
                                                                                                                                    You have an Azure Subscription that contains the storage accounts shown in the following table.

                                                                                                                                    You enable Microsoft Defender for Storage.
                                                                                                                                    Which storage services of storage5 are monitored by Microsoft for Storage which storage accounts are protected by.

                                                                                                                                    正解:

                                                                                                                                    解説:

                                                                                                                                    Explanation:


                                                                                                                                    質問 # 109
                                                                                                                                    You need to configure the AKS1 and ID 1 managed identities to meet the technical requirements. The solution must follow the principle of least privilege.
                                                                                                                                    Which role should you assign to each identity? To answer, select the appropriate options in the answer area.
                                                                                                                                    NOTE: Each correct selection is worth one point.

                                                                                                                                    正解:

                                                                                                                                    解説:

                                                                                                                                    Explanation:

                                                                                                                                    AKS1: AcrPull; ID1: Contributor
                                                                                                                                    AKS1 needs to pull images from Azure Container Registry, so AcrPull is the least-privilege registry role for the cluster identity. ID1 requires Contributor in the visible answer area because the referenced technical requirement requires resource changes beyond a read-only or pull-only role. The important distinction is scope: AKS image retrieval should not receive Contributor, while the separate managed identity receives the broader role only for its implementation task. This domain is tested through precise scope control: tenant, subscription, resource, application, and data-plane authorization are not interchangeable. The correct choice applies the smallest identity or governance control that enforces the stated requirement. Options that only add users, create registrations, or provide broad administrator access fail because they do not directly enforce the requested access behavior. The result is a direct exam-style implementation choice: it changes the required security behavior without relying on unrelated monitoring, manual cleanup, or excessive privilege. Official Microsoft source/topic: SC-500 Study Guide > AKS and managed identities; Microsoft Learn > ACR pull role and Azure RBAC.
                                                                                                                                    Category Breakdown
                                                                                                                                    Category Number of Questions
                                                                                                                                    Manage identity, access, and governance 40
                                                                                                                                    Manage and monitor security posture 30
                                                                                                                                    Secure compute 31
                                                                                                                                    Secure storage, databases, and networking 34
                                                                                                                                    TOTAL 135
                                                                                                                                    Exam Topic Breakdown
                                                                                                                                    Exam Topic Number of Questions


                                                                                                                                    質問 # 110
                                                                                                                                    ......

                                                                                                                                    市場には試験に関する多くの学習資料があるため、当社からSC-500準備ガイドを選択する決定を下すことは容易ではありません。ただし、当社からSC-500テストプラクティスファイルを購入することに決めた場合は、ここ数年で行った最良の決定の1つになることをお知らせします。私たちに知られているように、当社のSC-500準備資料は、この分野の有名な専門家や教授の多くによって設計されています。 SC-500準備ガイドが想像を超えた高品質であることは間違いありません。

                                                                                                                                    SC-500受験記: https://www.tech4exam.com/SC-500-pass-shiken.html