Microsoft Implementing End-to-End Security Controls for Cloud and AI Workloads - SC-500 FREE EXAM DUMPS QUESTIONS & ANSWERS
You have an Azure key vault named KV1 that uses role-based access control (RBAC) authorization KV1 stores database connection strings for an Azure App Service web app named App1.
You enable a firewall on KV1 and allow access to KV1 from only the virtual network that contains App1.
You need to ensure that App1 can retrieve secrets from KV1 without using credentials stored in the application configuration.
What should you create?
You enable a firewall on KV1 and allow access to KV1 from only the virtual network that contains App1.
You need to ensure that App1 can retrieve secrets from KV1 without using credentials stored in the application configuration.
What should you create?
Correct Answer: B
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
You have an Azure Functions app named App1 that uses an HTTP trigger, runs on an Elastic Premium plan, and uses virtual network integration.
A partner application sends requests to App1 from a public IP address of xxx.xxx.xxx.xx.
You need to ensure that the requests are accepted from only xxx.xxx.xxx.xx.
What should you do?
A partner application sends requests to App1 from a public IP address of xxx.xxx.xxx.xx.
You need to ensure that the requests are accepted from only xxx.xxx.xxx.xx.
What should you do?
Correct Answer: E
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
You have an Azure environment.
You need to identity any Azure configurations and workloads that are non-compliant with ISO 27001:2013 standards. What should you use?
You need to identity any Azure configurations and workloads that are non-compliant with ISO 27001:2013 standards. What should you use?
Correct Answer: B
Vote an answer
You have an Azure subscription named Sub1 that contains an Azure Kubernetes Service (AKS) cluster named cluster1 and an Azure container registry named ACR1 Sub1 has Microsoft Defender for Containers enabled, and runtime protection is active on cluster!
The developers at your company deploy pods that have elevated privileges, and the deployments are created in cluster1 You need to prevent pods with elevated privileges from being accepted by cluster!
What should you do?
The developers at your company deploy pods that have elevated privileges, and the deployments are created in cluster1 You need to prevent pods with elevated privileges from being accepted by cluster!
What should you do?
Correct Answer: D
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
You have an Azure subscription that contains a resource group named RG1.
RG1 contains a Microsoft Security Copilot deployment that is integrated with a Microsoft Sentinel workspace named Workspace1.
Analysts use the Security Copilot standalone experience to retrieve incidents by using the Microsoft Sentinel plugin.
A user named User1 can sign in to Security Copilot but cannot retrieve incidents from Workspace1. You verify that User1 lias only the Security Copilot Contributor role.
You need to ensure that User1 can retrieve the incidents. The solution must follow the principle of least privilege and NOT require any configuration changes to Security Copilot.
Which role should you assign to User1?
RG1 contains a Microsoft Security Copilot deployment that is integrated with a Microsoft Sentinel workspace named Workspace1.
Analysts use the Security Copilot standalone experience to retrieve incidents by using the Microsoft Sentinel plugin.
A user named User1 can sign in to Security Copilot but cannot retrieve incidents from Workspace1. You verify that User1 lias only the Security Copilot Contributor role.
You need to ensure that User1 can retrieve the incidents. The solution must follow the principle of least privilege and NOT require any configuration changes to Security Copilot.
Which role should you assign to User1?
Correct Answer: D
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
You have an Azure virtual network named VNet1 that contains a subnet named Subnet! A network security group named NSG1 is associated with Subnet1.
Vou have a storage account named storage1.
You need to ensure that access from Subnet1 to storage! uses a private IP address in Subnet1 and ran be filtered by NSG1 Public network access to storage1 must be disabled.
What should you create?
Vou have a storage account named storage1.
You need to ensure that access from Subnet1 to storage! uses a private IP address in Subnet1 and ran be filtered by NSG1 Public network access to storage1 must be disabled.
What should you create?
Correct Answer: A
Vote an answer
For which storage accounts can you implement the planned changes for storage?
Correct Answer: B
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
You have three internet-facing Azure App Service web apps named App1, App2, and App1 Each app uses built-in authentication.
App2 hosts a backend API.
Some corporate users can sign in to App2, even though they should NOT be able to use the API.
You need to restrict App2 access to assigned Microsoft Entra users and groups.
What should you configure for App2? To answer, drag the appropriate configurations to the correct methods.
Each configuration may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

App2 hosts a backend API.
Some corporate users can sign in to App2, even though they should NOT be able to use the API.
You need to restrict App2 access to assigned Microsoft Entra users and groups.
What should you configure for App2? To answer, drag the appropriate configurations to the correct methods.
Each configuration may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
Authentication method: The Microsoft identity provider; Access control method: Enterprise app assignment required

Built-in authentication for App Service should use the Microsoft identity provider for Microsoft Entra sign-in.
To restrict access to selected users and groups, require enterprise app assignment on the corresponding enterprise application. IP restrictions only filter network source and cannot identify assigned corporate users.
Local authentication and broad admin consent do not implement assigned-user enforcement for the backend API. This domain is tested through precise scope control: tenant, subscription, resource, application, and data- plane authorization are not interchangeable. The correct choice applies the smallest identity or governance control that enforces the stated requirement. Options that only add users, create registrations, or provide broad administrator access fail because they do not directly enforce the requested access behavior. The result is a direct exam-style implementation choice: it changes the required security behavior without relying on unrelated monitoring, manual cleanup, or excessive privilege. Official Microsoft source/topic: SC-500 Study Guide > App Service authentication; Microsoft Learn > App Service built-in authentication and enterprise app assignment.
You have an Azure API Management instance named APIM1 that publishes an API named OrdersAPI.
Applications call OrdersAPI by using Microsoft Entra access tokens.
A security review finds that requests that do NOT contain a valid access token can still be forwarded to OrdersAPI.
You need to ensure that APIM1 rejects requests that do NOT contain a valid Microsoft Entra token before the requests reach OrdersAPI.
What should you configure?
Applications call OrdersAPI by using Microsoft Entra access tokens.
A security review finds that requests that do NOT contain a valid access token can still be forwarded to OrdersAPI.
You need to ensure that APIM1 rejects requests that do NOT contain a valid Microsoft Entra token before the requests reach OrdersAPI.
What should you configure?
Correct Answer: C
Vote an answer
You have an Azure subscription that is linked to a Microsoft Entra tenant the tenant contains the groups shown in the following table.

The tenant contains the users shown in the following table.

The subscription contains the Azure SOL servers shown in the following table.

The servers are configured for Microsoft Entra-only authentication.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.


The tenant contains the users shown in the following table.

The subscription contains the Azure SOL servers shown in the following table.

The servers are configured for Microsoft Entra-only authentication.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
