Pass Your Microsoft Exam with SC-500 Exam Dumps (Updated 136 Questions) [Q25-Q46]

Pass Your Microsoft Exam with SC-500 Exam Dumps (Updated 136 Questions)

SC-500 Exam Dumps – Microsoft Practice Test Questions

Microsoft SC-500 Exam Syllabus Topics:

Section Weight Objectives
Manage identity, access, and governance 20–25% – Secure secrets and keys using Azure Key Vault

  • 1. Access policies and firewall settings
    • 2. Keys, secrets, and certificates management
      • 3. Key Vault deployment and configuration
        • 4. Defender for Key Vault and CSPM scanning

          – Secure access to resources by using Microsoft Entra ID

          • 1. Conditional Access policies
            • 2. Enterprise applications and app registrations
              • 3. Authentication methods (MFA, passwordless)
                • 4. OAuth consent and permission grants
                  • 5. Managed identities for Azure resources
                    • 6. Privileged Identity Management (PIM)

                      – Governance and compliance enforcement

                      • 1. RBAC and role management (Azure & Entra roles)
                        • 2. Resource locks
                          • 3. Azure Policy (built-in and custom)
                            • 4. Infrastructure as Code security controls
                              • 5. Microsoft Defender for Cloud compliance
                                • 6. Azure Backup security controls
                                  Manage and monitor security posture 20–25% – Microsoft Sentinel

                                  • 1. Automation rules and playbooks
                                    • 2. Data connectors (Azure, syslog, CEF)
                                      • 3. Data collection rules and WEF
                                        • 4. Custom logs and tables
                                          • 5. Retention policies
                                            • 6. Workspaces and role assignment

                                              – Security Copilot

                                              • 1. Plugins and integrations
                                                • 2. Workspace configuration
                                                  • 3. Permissions and roles
                                                    • 4. Security Store agents

                                                      – Microsoft Defender for Cloud

                                                      • 1. Defender Vulnerability Management
                                                        • 2. Multi-cloud (AWS/GCP) integration
                                                          • 3. Compliance frameworks evaluation
                                                            • 4. Workload protection plans
                                                              • 5. Defender CSPM risk identification
                                                                • 6. External Attack Surface Management (EASM)
                                                                  Secure compute 20–25% – Application platform security

                                                                  • 1. AKS security and Defender for Containers
                                                                    • 2. Web Application Firewall (WAF)
                                                                      • 3. Container Registry security
                                                                        • 4. Azure Functions security
                                                                          • 5. App Service security controls
                                                                            • 6. API Management security policies

                                                                              – Security for AI workloads

                                                                              • 1. AI Gateway (Azure API Management)
                                                                                • 2. Defender for AI services
                                                                                  • 3. Microsoft Purview DSPM for AI
                                                                                    • 4. Entra Agent ID security and access control
                                                                                      • 5. Microsoft Copilot and AI risk identification
                                                                                        • 6. Security Copilot agents and monitoring

                                                                                          – Servers and virtual machines

                                                                                          • 1. Just-in-time (JIT) VM access
                                                                                            • 2. Disk encryption
                                                                                              • 3. Azure Arc hybrid security
                                                                                                • 4. Agentless scanning and EDR
                                                                                                  • 5. Secure boot and vTPM
                                                                                                    • 6. Defender for Servers onboarding
                                                                                                      • 7. Azure Bastion
                                                                                                        Secure storage, databases, and networking 25–30% – Database security

                                                                                                        • 1. Database auditing
                                                                                                          • 2. Azure SQL security configuration
                                                                                                            • 3. Defender for Databases

                                                                                                              – Network security

                                                                                                              • 1. Azure Firewall
                                                                                                                • 2. VPN security
                                                                                                                  • 3. Private endpoints and Private Link
                                                                                                                    • 4. NSGs and ASGs
                                                                                                                      • 5. Azure Virtual Network Manager
                                                                                                                        • 6. Network Watcher diagnostics
                                                                                                                          • 7. Virtual WAN security

                                                                                                                            – Storage security

                                                                                                                            • 1. Access policies for storage
                                                                                                                              • 2. Storage firewall rules
                                                                                                                                • 3. Storage account security configuration
                                                                                                                                  • 4. Defender for Storage

                                                                                                                                     

                                                                                                                                    NEW QUESTION 25
                                                                                                                                    You have a Microsoft Copilot Studio agent.
                                                                                                                                    A Microsoft Power Platform administrator configures external threat detection for the agent by using a Microsoft Entra application.
                                                                                                                                    You need to ensure that real-time protection is enabled during agent runtime.
                                                                                                                                    What should you do in the Microsoft Defender portal?

                                                                                                                                     
                                                                                                                                     
                                                                                                                                     
                                                                                                                                     

                                                                                                                                    NEW QUESTION 26
                                                                                                                                    Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.
                                                                                                                                    After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.
                                                                                                                                    You have an Azure subscription that contains two virtual machines named VM1 and VM2. Each virtual machine has system-assigned managed identity enabled.
                                                                                                                                    You have an Azure Storage account named storage1. Public access from all networks is enabled for storage1.
                                                                                                                                    You need to ensure that VM1 and VM2 can access storage1.
                                                                                                                                    Solution: You add each virtual machine to a security group, and then add the security group to a role on storage1.
                                                                                                                                    Does this meet the goal?

                                                                                                                                     
                                                                                                                                     

                                                                                                                                    NEW QUESTION 27
                                                                                                                                    A company wants to continuously assess cloud resources for security weaknesses and regulatory compliance issues. Which Microsoft security service provides this capability?

                                                                                                                                     
                                                                                                                                     
                                                                                                                                     
                                                                                                                                     

                                                                                                                                    NEW QUESTION 28
                                                                                                                                    You have Microsoft Security Copilot agents that authenticate by using Microsoft Entra service principals.
                                                                                                                                    You receive a Microsoft Defender alert triggered by the anomalous OAuth authentication of an agent’s Microsoft Entra service principal.
                                                                                                                                    You need to assess the impact of the agent identity and identify which resources are affected if the identity is abused for lateral movement. The solution must minimize administrative effort.
                                                                                                                                    What should you do?

                                                                                                                                     
                                                                                                                                     
                                                                                                                                     
                                                                                                                                     
                                                                                                                                     

                                                                                                                                    NEW QUESTION 29
                                                                                                                                    Drag and Drop Question
                                                                                                                                    You have a Microsoft 365 subscription. All users have Microsoft Exchange Online mailboxes.
                                                                                                                                    You use Microsoft Entra Agent ID to register and manage AI agents.
                                                                                                                                    The developers at your company create the following two agents:
                                                                                                                                    – Agent1: An interactive agent that helps users summarize their own
                                                                                                                                    Exchange Online email
                                                                                                                                    – Agent2: An autonomous agent that sends nightly updates to a Microsoft Teams channel You need to grant each agent access to Microsoft Graph. The solution must minimize the access scope, while meeting each agent’s operating model.
                                                                                                                                    Which type of permission should you assign to each agent? To answer, drag the appropriate permission types to the correct agents. Each permission type may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
                                                                                                                                    NOTE: Each correct selection is worth one point.

                                                                                                                                    NEW QUESTION 30
                                                                                                                                    Case Study 1 – Contoso, Ltd.
                                                                                                                                    Overview
                                                                                                                                    Contoso, Ltd. is a consulting company that has a main office in San Francisco and a branch office in Dallas.
                                                                                                                                    Contoso has a hybrid environment that contains on-premises servers connected to Azure, a Microsoft 365 E5 subscription, and an Azure subscription named Sub1.
                                                                                                                                    Existing Environment. Microsoft Entra tenant
                                                                                                                                    Contoso has a Microsoft Entra tenant named contoso.com that contains the users shown in the following table.

                                                                                                                                    Existing Environment. On-premises environment
                                                                                                                                    The on-premises network contains an Active Directory Domain Services (AD DS) forest that syncs with contoso.com. The forest contains a server named Server1 that runs Windows Server.
                                                                                                                                    Existing Environment. Azure subscription
                                                                                                                                    Sub1 contains the storage accounts shown in the following table.

                                                                                                                                    Sub1 contains the virtual networks shown in the following table.

                                                                                                                                    Sub1 contains the virtual machines shown in the following table.

                                                                                                                                    The network interface of VM1 is associated with an application security group named ASG1.
                                                                                                                                    Sub1 contains the resources shown in the following table.

                                                                                                                                    Vault1 stores the objects shown in the following table.

                                                                                                                                    Existing Environment. Privileged Identity Management (PIM) configuration You manage privileged roles by using Privileged Identity Management (PIM). The PIM role settings are configured as shown in the following table.

                                                                                                                                    Existing Environment. Microsoft Sentinel configuration
                                                                                                                                    Contoso has a Microsoft Sentinel workspace that contains the following tables.

                                                                                                                                    Requirements. Planned changes
                                                                                                                                    Contoso plans to implement the following changes:
                                                                                                                                    – Integrate AKS1 with Vault1.
                                                                                                                                    – Enable Microsoft Entra Kerberos authentication for all supported
                                                                                                                                    storage.
                                                                                                                                    – Configure auditing for sql1 by using the Azure portal and store audit logs in a centralized location.
                                                                                                                                    Requirements. Technical requirements
                                                                                                                                    Contoso identifies the following technical requirements:
                                                                                                                                    – Protect Server1 by using file integrity monitoring.
                                                                                                                                    – Protect AKS1 by using Microsoft Defender for Cloud.
                                                                                                                                    – Configure Microsoft Sentinel to retain data for the maximum supported duration without changing the tier.
                                                                                                                                    – Store objects used for authentication and encryption in Vault1 and
                                                                                                                                    ensure that Vault1 regenerates the objects every 30 days, whenever
                                                                                                                                    possible.
                                                                                                                                    Hotspot Question
                                                                                                                                    User1 has requested to use the AI Administrator role.
                                                                                                                                    Which approvers can approve the request, and how long will User1 be an AI administrator after the role is approved? To answer, select the appropriate options in the answer area.
                                                                                                                                    NOTE: Each correct selection is worth one point.

                                                                                                                                    NEW QUESTION 31
                                                                                                                                    Case Study 1 – Contoso, Ltd.
                                                                                                                                    Overview
                                                                                                                                    Contoso, Ltd. is a consulting company that has a main office in San Francisco and a branch office in Dallas.
                                                                                                                                    Contoso has a hybrid environment that contains on-premises servers connected to Azure, a Microsoft 365 E5 subscription, and an Azure subscription named Sub1.
                                                                                                                                    Existing Environment. Microsoft Entra tenant
                                                                                                                                    Contoso has a Microsoft Entra tenant named contoso.com that contains the users shown in the following table.

                                                                                                                                    Existing Environment. On-premises environment
                                                                                                                                    The on-premises network contains an Active Directory Domain Services (AD DS) forest that syncs with contoso.com. The forest contains a server named Server1 that runs Windows Server.
                                                                                                                                    Existing Environment. Azure subscription
                                                                                                                                    Sub1 contains the storage accounts shown in the following table.

                                                                                                                                    Sub1 contains the virtual networks shown in the following table.

                                                                                                                                    Sub1 contains the virtual machines shown in the following table.

                                                                                                                                    The network interface of VM1 is associated with an application security group named ASG1.
                                                                                                                                    Sub1 contains the resources shown in the following table.

                                                                                                                                    Vault1 stores the objects shown in the following table.

                                                                                                                                    Existing Environment. Privileged Identity Management (PIM) configuration You manage privileged roles by using Privileged Identity Management (PIM). The PIM role settings are configured as shown in the following table.

                                                                                                                                    Existing Environment. Microsoft Sentinel configuration
                                                                                                                                    Contoso has a Microsoft Sentinel workspace that contains the following tables.

                                                                                                                                    Requirements. Planned changes
                                                                                                                                    Contoso plans to implement the following changes:
                                                                                                                                    – Integrate AKS1 with Vault1.
                                                                                                                                    – Enable Microsoft Entra Kerberos authentication for all supported
                                                                                                                                    storage.
                                                                                                                                    – Configure auditing for sql1 by using the Azure portal and store audit logs in a centralized location.
                                                                                                                                    Requirements. Technical requirements
                                                                                                                                    Contoso identifies the following technical requirements:
                                                                                                                                    – Protect Server1 by using file integrity monitoring.
                                                                                                                                    – Protect AKS1 by using Microsoft Defender for Cloud.
                                                                                                                                    – Configure Microsoft Sentinel to retain data for the maximum supported duration without changing the tier.
                                                                                                                                    – Store objects used for authentication and encryption in Vault1 and
                                                                                                                                    ensure that Vault1 regenerates the objects every 30 days, whenever
                                                                                                                                    possible.
                                                                                                                                    For which storage accounts can you implement the planned changes for storage?

                                                                                                                                     
                                                                                                                                     
                                                                                                                                     
                                                                                                                                     
                                                                                                                                     
                                                                                                                                     

                                                                                                                                    NEW QUESTION 32
                                                                                                                                    You have an Azure subscription named Sub1 that contains multiple virtual machines and an Azure key vault named KV1.
                                                                                                                                    Each virtual machine has a system-assigned managed identity. Sub1 has Microsoft Defender for Servers enabled. Defender for Servers has agentless scanning enabled.
                                                                                                                                    Some virtual machines use managed disks that are encrypted by using customer-managed keys stored in KV1.
                                                                                                                                    You discover that the affected virtual machines fail to return agentless scanning results in Microsoft Defender for Cloud.
                                                                                                                                    You need to ensure that agentless scanning can analyze the virtual machines.
                                                                                                                                    What should you do?

                                                                                                                                     
                                                                                                                                     
                                                                                                                                     
                                                                                                                                     
                                                                                                                                     

                                                                                                                                    NEW QUESTION 33
                                                                                                                                    You have a hybrid environment that contains the following servers:
                                                                                                                                    – 50 Azure virtual machines that run Windows Server 2019
                                                                                                                                    – 20 physical, on-premises servers that run Windows Server 2019
                                                                                                                                    All the servers use a third-party antivirus solution that must remain active during a phased security rollout.
                                                                                                                                    You need to onboard all the servers to Microsoft Defender for Endpoint by using a centralized deployment method. The solution must meet the following requirements:
                                                                                                                                    – Endpoint detection and response (EDR) capabilities must be enabled.
                                                                                                                                    – Antivirus conflicts must be prevented during onboarding.
                                                                                                                                    What should you do on the servers?

                                                                                                                                     
                                                                                                                                     
                                                                                                                                     
                                                                                                                                     

                                                                                                                                    NEW QUESTION 34
                                                                                                                                    You use Microsoft Security Copilot.
                                                                                                                                    Users are assigned either the Security Copilot Contributor role or the Security Copilot Owner role.
                                                                                                                                    A contributor enables a custom plugin that is NOT approved, and some Security Copilot features in embedded experiences no longer function.
                                                                                                                                    You need to ensure that plugins affecting all users can only be added by owners.
                                                                                                                                    What should you do in the Plugin settings?

                                                                                                                                     
                                                                                                                                     
                                                                                                                                     
                                                                                                                                     

                                                                                                                                    NEW QUESTION 35
                                                                                                                                    You have a Microsoft Sentinel workspace.
                                                                                                                                    You need to collect Windows security events from 200 Azure virtual machines that run Windows Server. The solution must meet the following requirements:
                                                                                                                                    – Use direct agent-based data collection from each virtual machine.
                                                                                                                                    – Use a supported agent for new virtual machine deployments.
                                                                                                                                    Which Microsoft Sentinel connector should you use?

                                                                                                                                     
                                                                                                                                     
                                                                                                                                     
                                                                                                                                     
                                                                                                                                     

                                                                                                                                    NEW QUESTION 36
                                                                                                                                    Your organization plans to allow developers to access Azure OpenAI resources. Management wants to ensure that access permissions follow the principle of least privilege. What should you use?

                                                                                                                                     
                                                                                                                                     
                                                                                                                                     
                                                                                                                                     

                                                                                                                                    NEW QUESTION 37
                                                                                                                                    You have an Azure subscription named Sub1 that contains multiple virtual machines.
                                                                                                                                    You have a Microsoft 365 E5 subscription that contains devices onboarded to Microsoft Defender for Endpoint.
                                                                                                                                    You have an on-premises datacenter that contains multiple servers.
                                                                                                                                    You plan to onboard all existing and future on-premises servers to Azure Arc.
                                                                                                                                    You need to ensure that the Azure Arc-enabled servers are protected by using the same security features as the Microsoft 365 devices immediately after the servers are onboarded. The solution must minimize administrative effort.
                                                                                                                                    What should you do?

                                                                                                                                     
                                                                                                                                     
                                                                                                                                     
                                                                                                                                     

                                                                                                                                    NEW QUESTION 38
                                                                                                                                    Case Study 1 – Contoso, Ltd.
                                                                                                                                    Overview
                                                                                                                                    Contoso, Ltd. is a consulting company that has a main office in San Francisco and a branch office in Dallas.
                                                                                                                                    Contoso has a hybrid environment that contains on-premises servers connected to Azure, a Microsoft 365 E5 subscription, and an Azure subscription named Sub1.
                                                                                                                                    Existing Environment. Microsoft Entra tenant
                                                                                                                                    Contoso has a Microsoft Entra tenant named contoso.com that contains the users shown in the following table.

                                                                                                                                    Existing Environment. On-premises environment
                                                                                                                                    The on-premises network contains an Active Directory Domain Services (AD DS) forest that syncs with contoso.com. The forest contains a server named Server1 that runs Windows Server.
                                                                                                                                    Existing Environment. Azure subscription
                                                                                                                                    Sub1 contains the storage accounts shown in the following table.

                                                                                                                                    Sub1 contains the virtual networks shown in the following table.

                                                                                                                                    Sub1 contains the virtual machines shown in the following table.

                                                                                                                                    The network interface of VM1 is associated with an application security group named ASG1.
                                                                                                                                    Sub1 contains the resources shown in the following table.

                                                                                                                                    Vault1 stores the objects shown in the following table.

                                                                                                                                    Existing Environment. Privileged Identity Management (PIM) configuration You manage privileged roles by using Privileged Identity Management (PIM). The PIM role settings are configured as shown in the following table.

                                                                                                                                    Existing Environment. Microsoft Sentinel configuration
                                                                                                                                    Contoso has a Microsoft Sentinel workspace that contains the following tables.

                                                                                                                                    Requirements. Planned changes
                                                                                                                                    Contoso plans to implement the following changes:
                                                                                                                                    – Integrate AKS1 with Vault1.
                                                                                                                                    – Enable Microsoft Entra Kerberos authentication for all supported
                                                                                                                                    storage.
                                                                                                                                    – Configure auditing for sql1 by using the Azure portal and store audit logs in a centralized location.
                                                                                                                                    Requirements. Technical requirements
                                                                                                                                    Contoso identifies the following technical requirements:
                                                                                                                                    – Protect Server1 by using file integrity monitoring.
                                                                                                                                    – Protect AKS1 by using Microsoft Defender for Cloud.
                                                                                                                                    – Configure Microsoft Sentinel to retain data for the maximum supported duration without changing the tier.
                                                                                                                                    – Store objects used for authentication and encryption in Vault1 and
                                                                                                                                    ensure that Vault1 regenerates the objects every 30 days, whenever
                                                                                                                                    possible.
                                                                                                                                    You need to meet the technical requirements for Vault1.
                                                                                                                                    Which object can you use?

                                                                                                                                     
                                                                                                                                     
                                                                                                                                     
                                                                                                                                     

                                                                                                                                    NEW QUESTION 39
                                                                                                                                    Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals.
                                                                                                                                    More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.
                                                                                                                                    After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.
                                                                                                                                    You have a Microsoft Sentinel workspace
                                                                                                                                    You have a multi-tier Security Operations Center (SOC) team.
                                                                                                                                    You need to ensure that all new security incidents are assigned immediately to the Tier 1 analysts group and flagged for triage.
                                                                                                                                    Solution: You create a playbook
                                                                                                                                    Does this meet the goal?

                                                                                                                                     
                                                                                                                                     

                                                                                                                                    NEW QUESTION 40
                                                                                                                                    Case Study 2 – Fabrikam, Inc.
                                                                                                                                    Overview
                                                                                                                                    Fabrikam, Inc. is a consulting company. The company has a main office in New York City and branch offices in Amsterdam and Singapore.
                                                                                                                                    Existing Environment. Network environment
                                                                                                                                    The on-premises network contains a datacenter in each office.
                                                                                                                                    Existing Environment. Cloud environment
                                                                                                                                    Fabrikam has two Azure subscriptions named Sub1 and Sub2 and a Microsoft 365 subscription that includes Microsoft 365 E5 licenses.
                                                                                                                                    All the subscriptions are linked to a Microsoft Entra tenant named fabrikam.com that contains the identities shown in the following table.

                                                                                                                                    The tenant contains the groups shown in the following table.

                                                                                                                                    All devices are enrolled in Microsoft Intune.
                                                                                                                                    Existing Environment. Sub1 Resources
                                                                                                                                    Sub1 contains a resource group named RG1 that contains the resources shown in the following table.

                                                                                                                                    SQLServer1 uses Microsoft SQL Server authentication.
                                                                                                                                    Sub1 has an Azure Web Application Firewall (WAF) named WAF1 that has the following types of rule sets:
                                                                                                                                    – Bot Manager 1.1
                                                                                                                                    – Azure-managed Default Rule Set (DRS)
                                                                                                                                    Sub1 has the following compliance standards assigned in Microsoft Defender for Cloud:
                                                                                                                                    – NIST SP 800-53 Rev. 4
                                                                                                                                    – Microsoft cloud security benchmark (MCSB)
                                                                                                                                    – System and Organization Controls (SOC) 2 Type 2
                                                                                                                                    Existing Environment. Sub2 Resources
                                                                                                                                    Sub2 contains a resource group named RG2.
                                                                                                                                    Planned Changes and Requirements. Planned Changes
                                                                                                                                    Fabrikam plans to implement the following changes:
                                                                                                                                    – Deploy the following key vaults to RG1:
                                                                                                                                    * AKV2 in the West Europe Azure region
                                                                                                                                    * AKV3 in the Central US Azure region
                                                                                                                                    * AKV4 in the East US Azure region
                                                                                                                                    – Deploy the following key vaults to RG2:
                                                                                                                                    * AKV5 in the East US region
                                                                                                                                    – Configure VM1 to read data from storage1.
                                                                                                                                    – Create function apps that have the following hosting plans:
                                                                                                                                    * Fa1: Flex Consumption hosting plan
                                                                                                                                    * Fa2: Consumption hosting plan
                                                                                                                                    * Fa3: Dedicated hosting plan
                                                                                                                                    – For WAF1, implement rate limiting rules based on the request
                                                                                                                                    location.
                                                                                                                                    – Enable the NIST SP 800-53 Rev. 5 compliance standard in Defender for
                                                                                                                                    Cloud.
                                                                                                                                    – Create a new storage account named storage2 that supports Azure Table storage.
                                                                                                                                    – Enforce multifactor authentication (MFA) when database administrators access SQLdb1.
                                                                                                                                    – Implement ExpressRoute circuits to the on-premises network as shown
                                                                                                                                    in the following table.

                                                                                                                                    – For RG1, create a new Privileged Identity Management (PIM) eligible role assignment that assigns the Contributor role to supported groups.
                                                                                                                                    Planned Changes and Requirements. Technical Requirements
                                                                                                                                    Fabrikam has the following technical requirements:
                                                                                                                                    – If VM1 is deleted, the permissions for VM1 must be removed
                                                                                                                                    automatically.
                                                                                                                                    – The AKS1 managed identity must only be able to pull images from
                                                                                                                                    Registry1.
                                                                                                                                    – The ID1 managed identity must be able to push images to and pull
                                                                                                                                    images from Registry1.
                                                                                                                                    – All the data in the storage accounts must be encrypted by using
                                                                                                                                    Fabrikam-managed keys.
                                                                                                                                    – All outbound traffic from the function apps to the on-premises
                                                                                                                                    network must use ExpressRoute circuits.
                                                                                                                                    – ExpressRoute connectivity between the on-premises network and the
                                                                                                                                    Azure environment must be encrypted by using Layer 2 or Layer 3
                                                                                                                                    encryption.
                                                                                                                                    You need to implement the function apps to meet the technical requirements. Which apps should you include in the implementation?

                                                                                                                                     
                                                                                                                                     
                                                                                                                                     
                                                                                                                                     

                                                                                                                                    NEW QUESTION 41
                                                                                                                                    You have an Azure subscription named Sub1 that contains an Azure Kubernetes Service (AKS) cluster named cluster1 and an Azure container registry named ACR1 Sub1 has Microsoft Defender for Containers enabled, and runtime protection is active on cluster!
                                                                                                                                    The developers at your company deploy pods that have elevated privileges, and the deployments are created in cluster1 You need to prevent pods with elevated privileges from being accepted by cluster!
                                                                                                                                    What should you do?

                                                                                                                                     
                                                                                                                                     
                                                                                                                                     
                                                                                                                                     

                                                                                                                                    NEW QUESTION 42
                                                                                                                                    Case Study 1 – Contoso, Ltd.
                                                                                                                                    Overview
                                                                                                                                    Contoso, Ltd. is a consulting company that has a main office in San Francisco and a branch office in Dallas.
                                                                                                                                    Contoso has a hybrid environment that contains on-premises servers connected to Azure, a Microsoft 365 E5 subscription, and an Azure subscription named Sub1.
                                                                                                                                    Existing Environment. Microsoft Entra tenant
                                                                                                                                    Contoso has a Microsoft Entra tenant named contoso.com that contains the users shown in the following table.

                                                                                                                                    Existing Environment. On-premises environment
                                                                                                                                    The on-premises network contains an Active Directory Domain Services (AD DS) forest that syncs with contoso.com. The forest contains a server named Server1 that runs Windows Server.
                                                                                                                                    Existing Environment. Azure subscription
                                                                                                                                    Sub1 contains the storage accounts shown in the following table.

                                                                                                                                    Sub1 contains the virtual networks shown in the following table.

                                                                                                                                    Sub1 contains the virtual machines shown in the following table.

                                                                                                                                    The network interface of VM1 is associated with an application security group named ASG1.
                                                                                                                                    Sub1 contains the resources shown in the following table.

                                                                                                                                    Vault1 stores the objects shown in the following table.

                                                                                                                                    Existing Environment. Privileged Identity Management (PIM) configuration You manage privileged roles by using Privileged Identity Management (PIM). The PIM role settings are configured as shown in the following table.

                                                                                                                                    Existing Environment. Microsoft Sentinel configuration
                                                                                                                                    Contoso has a Microsoft Sentinel workspace that contains the following tables.

                                                                                                                                    Requirements. Planned changes
                                                                                                                                    Contoso plans to implement the following changes:
                                                                                                                                    – Integrate AKS1 with Vault1.
                                                                                                                                    – Enable Microsoft Entra Kerberos authentication for all supported
                                                                                                                                    storage.
                                                                                                                                    – Configure auditing for sql1 by using the Azure portal and store audit logs in a centralized location.
                                                                                                                                    Requirements. Technical requirements
                                                                                                                                    Contoso identifies the following technical requirements:
                                                                                                                                    – Protect Server1 by using file integrity monitoring.
                                                                                                                                    – Protect AKS1 by using Microsoft Defender for Cloud.
                                                                                                                                    – Configure Microsoft Sentinel to retain data for the maximum supported duration without changing the tier.
                                                                                                                                    – Store objects used for authentication and encryption in Vault1 and
                                                                                                                                    ensure that Vault1 regenerates the objects every 30 days, whenever
                                                                                                                                    possible.
                                                                                                                                    You need to implement the planned change for the AKS1 integration.
                                                                                                                                    What should you configure for AKS1?

                                                                                                                                     
                                                                                                                                     
                                                                                                                                     
                                                                                                                                     

                                                                                                                                    NEW QUESTION 43
                                                                                                                                    You are configuring a new Microsoft Sentinel workspace named Workspace1.
                                                                                                                                    You have an external IT Service Management (ITSM) system that is NOT supported by any Microsoft Sentinel solutions in Azure Marketplace.
                                                                                                                                    You need to ensure that Workspace1 creates service tickets in the ITSM system for all new security incidents.
                                                                                                                                    What should you create?

                                                                                                                                     
                                                                                                                                     
                                                                                                                                     
                                                                                                                                     

                                                                                                                                    NEW QUESTION 44
                                                                                                                                    You have a Microsoft Security Copilot workspace named Workspace1 that is used by Security Operations Center (SOC) analysts and security administrators.
                                                                                                                                    The SOC analysts use only the Security Copilot standalone experience, and the security administrators access Security Copilot from the Microsoft Defender portal.
                                                                                                                                    A new Security Copilot workspace named Workspace2 is created for the security administrators.
                                                                                                                                    Workspace2 is assigned a capacity of five security compute units.
                                                                                                                                    You need to ensure that Security Copilot usage for the SOC analysts is allocated to Workspace1 and Security Copilot usage for the security administrators is allocated to Workspace2.
                                                                                                                                    What should you do?

                                                                                                                                     
                                                                                                                                     
                                                                                                                                     
                                                                                                                                     

                                                                                                                                    NEW QUESTION 45
                                                                                                                                    You have an Azure subscription that contains a resource group named RG1.
                                                                                                                                    RG1 contains a Microsoft Security Copilot deployment that is integrated with a Microsoft Sentinel workspace named Workspace1.
                                                                                                                                    Analysts use the Security Copilot standalone experience to retrieve incidents by using the Microsoft Sentinel plugin.
                                                                                                                                    A user named User1 can sign in to Security Copilot but cannot retrieve incidents from Workspace1. You verify that User1 has only the Security Copilot Contributor role.
                                                                                                                                    You need to ensure that User1 can retrieve the incidents. The solution must follow the principle of least privilege and NOT require any configuration changes to Security Copilot.
                                                                                                                                    Which role should you assign to User1?

                                                                                                                                     
                                                                                                                                     
                                                                                                                                     
                                                                                                                                     
                                                                                                                                     

                                                                                                                                    NEW QUESTION 46
                                                                                                                                    You have an Azure subscription named Sub1 that contains a storage account named storage1.
                                                                                                                                    Sub1 has Microsoft Defender for Storage enabled. Defender for Storage has malware scanning enabled.
                                                                                                                                    You need to configure a solution that automates the remediation of malware detected in storage1.
                                                                                                                                    What should you include in the solution?

                                                                                                                                     
                                                                                                                                     
                                                                                                                                     
                                                                                                                                     

                                                                                                                                    Pass Your SC-500 Exam Easily with Accurate PDF Questions: https://www.premiumvcedump.com/Microsoft/valid-SC-500-premium-vce-exam-dumps.html