SC-500 practice questions

20 free SC-500 practice questions with answers and explanations, covering identity and governance, storage, database and network security, compute and AI security, and security posture management with Defender for Cloud and Microsoft Sentinel.

Study the full SC-500 course, free to start.

SC-500 exam at a glance

Skills measured

Official SC-500 study guide on Microsoft Learn

20 free SC-500 practice questions

Secure access to resources by using Microsoft Entra

Question 1. A Security Administrator's account needs SSPR configured. Which combination is correct for this account under Microsoft's guidance?

  1. One method is sufficient, since administrators are trusted users
  2. Two methods are required, and security questions may be used as one of them for convenience
  3. Two methods are required, security questions cannot be used at all, and email reset is not recommended
  4. Email-based reset alone is recommended, since it is the fastest option for a privileged user to regain access
Show answer

Answer: C, Two methods are required, security questions cannot be used at all, and email reset is not recommended. Administrator accounts require two authentication methods for reset, explicitly exclude security questions as an eligible method, and are discouraged from using email-based reset. A single method, security questions, or email-only reset are all weaker than what's required for a privileged account.

Question 2. A developer wants to hardcode an API key directly into a declarative agent plugin's configuration so it's easy to find during debugging. What's the recommended approach instead, and why?

  1. Hardcode it as requested, since declarative agent plugins run in a trusted environment
  2. Store the key in the Microsoft 365 vault and reference it by vault entry ID, so it can be rotated without redeploying the plugin and is never exposed to the client
  3. Email the key to the whole development team so anyone can update it manually when needed
  4. Store the key in a public GitHub repository so it's easy to locate later
Show answer

Answer: B, Store the key in the Microsoft 365 vault and reference it by vault entry ID, so it can be rotated without redeploying the plugin and is never exposed to the client. The vault entry ID pattern means the plugin never contains the actual secret: an administrator or developer registers the key in the vault, the plugin references only the entry ID, and rotating a compromised or expired key needs no redeployment. Hardcoding, emailing or publishing a key all expose it needlessly and make rotation harder, not easier.

Secure Azure Key Vault with defense in depth for the cloud and AI workloads

Question 3. A vault holds encryption keys for customer data and must have no internet exposure at all, reachable only from its VNet and an ExpressRoute circuit. Which network configuration meets this?

  1. A firewall rule allowlisting the office's public IP range
  2. A VNet service endpoint on the application's subnet
  3. A private endpoint with public network access disabled
  4. Leaving the vault on its default public endpoint and relying on RBAC alone
Show answer

Answer: C, A private endpoint with public network access disabled. Only a private endpoint, combined with disabling public network access, removes the vault's internet exposure entirely, restricting access to the VNet and connected networks like ExpressRoute. A firewall rule and a service endpoint both leave the vault's endpoint public. RBAC controls who can authenticate and act, not whether the network path is exposed, so it doesn't substitute for network isolation.

Question 4. Defender CSPM's agentless scanning flags a database connection string hardcoded in a Bicep template. After moving the secret into Key Vault and updating the template to reference it via managed identity, the finding still shows as open. What's missing?

  1. Nothing; the finding auto-resolves within 24 hours regardless of further action
  2. The plaintext credential must actually be removed from the template; leaving it alongside the new vault reference doesn't resolve the finding
  3. Defender for Key Vault, not Defender CSPM, needs to be enabled to clear this specific finding
  4. The secret needs to be re-scanned manually from the Key Vault portal blade
Show answer

Answer: B, The plaintext credential must actually be removed from the template; leaving it alongside the new vault reference doesn't resolve the finding. The remediation pattern requires deleting the plaintext credential from its exposed location, not just adding a vault reference alongside it; if the hardcoded value is still present, the exposure the finding describes still exists. This is a Defender CSPM finding about exposed secrets in code, not something Defender for Key Vault (which monitors the vault itself) would resolve, and there's no manual re-scan step described that substitutes for actually removing the plaintext.

Enforce security governance and regulatory compliance

Question 5. You just toggled a new regulatory standard on for a subscription in Defender for Cloud's security policies. Roughly how long before the first assessment results populate the compliance dashboard?

  1. Up to 12 hours
  2. Up to 7 days
  3. Up to 30 days
  4. Instantly
Show answer

Answer: A, Up to 12 hours. Initial assessment results for a newly assigned standard can take up to 12 hours to populate; the dashboard is not instant. The 7-day figure applies to a separate system, the Purview Compliance Manager aggregation.

Question 6. A tagging policy has run in Audit for three weeks. The team remediates everything it surfaced and completes the audit-first rollout by switching the effect to Deny. A week later the compliance dashboard still lists 40 noncompliant resources. What is the most likely explanation?

  1. Switching to Deny resets compliance state, so these are stale entries that clear on the next evaluation
  2. Deny is not supported for tag policies, so the assignment silently fell back to Audit
  3. Those resources were created or last updated before the switch, and Deny only evaluates create and update requests, so it never fixes or removes what already exists
  4. The assignment needs a managed identity before a Deny effect takes effect
Show answer

Answer: C, Those resources were created or last updated before the switch, and Deny only evaluates create and update requests, so it never fixes or removes what already exists. Deny is evaluated when a create or update request reaches Azure Resource Manager, so it prevents new noncompliant resources without touching anything already deployed. Those 40 stay noncompliant until they are remediated or exempted. Deny works on tag policies, and a managed identity is a requirement of the DeployIfNotExists and Modify effects, which actually change resources, not of Deny.

Implement security for Azure Storage for the cloud and AI security engineer

Question 7. Which authentication method keeps working after Shared Key authorization is disabled on a storage account?

  1. Account SAS signed with the storage account key
  2. Service SAS signed with the storage account key
  3. User delegation SAS signed with Microsoft Entra ID credentials
  4. Direct use of a storage account access key
Show answer

Answer: C, User delegation SAS signed with Microsoft Entra ID credentials. Disabling Shared Key blocks any authentication signed with the account key, including Shared Key itself, Service SAS, and Account SAS. User delegation SAS is signed with Entra ID credentials instead, so it, along with Entra ID RBAC, continues to function.

Question 8. A polymorphic malware sample is uploaded to blob storage, using a modified signature not present in any known malware hash database. Which Defender for Storage detection method is designed to still catch it?

  1. Hash reputation analysis only
  2. Sensitive data threat detection
  3. Full content scanning using the Defender Antivirus engine
  4. Trusted services bypass
Show answer

Answer: C, Full content scanning using the Defender Antivirus engine. Hash reputation only catches known signatures and would miss a modified, polymorphic sample. Full content scanning analyses file structure and behavioural patterns using the Defender Antivirus engine, specifically designed to catch threats that evade hash-based detection.

Implement security for Azure SQL databases

Question 9. A Retail Banking user with UNMASK permission on the CreditCardNumber column queries the Transactions table, which also has a Row-Level Security FILTER predicate scoping rows to their own division. What do they see?

  1. Only Retail Banking division rows, with the credit card number unmasked
  2. Only Retail Banking division rows, with the credit card number still masked
  3. Every division's rows, with the credit card number still masked
  4. Every division's rows, with the credit card number unmasked
Show answer

Answer: A, Only Retail Banking division rows, with the credit card number unmasked. UNMASK only affects Dynamic Data Masking, revealing the actual column value; it has no effect on Row-Level Security, which independently still filters the rows to only the user's own division. The two controls operate independently in the same query, layered together.

Question 10. An AI fraud-detection service begins querying customer tables at 3am with ten times its normal daily volume, using entirely valid, unrevoked credentials. Which Defender for SQL capability is responsible for surfacing this as worth investigating?

  1. Vulnerability assessment baselining
  2. Anomalous database access and query pattern detection, based on a learned behavioural baseline
  3. Transparent Data Encryption alerts
  4. The SQL Security Manager RBAC role
Show answer

Answer: B, Anomalous database access and query pattern detection, based on a learned behavioural baseline. Anomaly detection compares current behaviour against a learned baseline for each database, so a large deviation in volume and timing triggers an alert even with valid credentials, since credential validity alone doesn't rule out a compromised account or a misbehaving integration being investigated. TDE and RBAC roles don't generate behavioural alerts, and baselining applies to vulnerability findings, not live threat detection.

Implement network security controls in Azure

Question 11. An engineer needs to determine exactly why traffic from one specific IP address on a specific port to a database VM is being blocked, identifying the exact rule responsible. Which Network Watcher capability is designed for this specific question?

  1. Effective security rules, since it lists every rule affecting the NIC
  2. NSG flow logs, since they record historical traffic
  3. IP flow verify, since it tests one specific flow and reports the allow/deny result plus the exact rule responsible
  4. Connection Monitor, since it continuously tracks connectivity over time
Show answer

Answer: C, IP flow verify, since it tests one specific flow and reports the allow/deny result plus the exact rule responsible. IP flow verify is built specifically to test one exact traffic flow, given source, destination, port, and protocol, and reports whether it's allowed or denied along with the specific rule making that decision. Effective security rules shows everything affecting a NIC but doesn't test one specific flow directly, and the other tools serve different purposes.

Question 12. A company still needs to support a legacy application that depends on broad SMB file-share access across an entire subnet, which can't easily be segmented into individual application entries. What is the most appropriate access method for this specific scenario?

  1. Per-app Microsoft Entra Private Access for each individual file
  2. Quick Access in Microsoft Entra Private Access, or continued VPN use, since this scenario genuinely needs network-layer connectivity
  3. Azure Private Link Service
  4. Disabling remote access to the file share entirely
Show answer

Answer: B, Quick Access in Microsoft Entra Private Access, or continued VPN use, since this scenario genuinely needs network-layer connectivity. Quick Access, or traditional VPN, is appropriate specifically because this scenario requires broad, network-level connectivity to an entire subnet that can't be cleanly segmented into per-application access, unlike scenarios suited to per-app Private Access.

Implement security for AI

Question 13. An organisation wants to enable real-time runtime protection for its Copilot Studio agents. Which two teams need to coordinate, and where is protection ultimately enabled?

  1. Security and Power Platform administrators, enabled through the Microsoft Defender portal's Security for AI settings
  2. Only Microsoft support, since this cannot be self-configured
  3. Only the Power Platform team, entirely within Copilot Studio itself
  4. Only the network team, through Azure Firewall policy
Show answer

Answer: A, Security and Power Platform administrators, enabled through the Microsoft Defender portal's Security for AI settings. Enabling this protection specifically requires coordinating Power Platform administration, for App ID configuration, with enabling the setting in the Defender portal's Security for AI area, making it a joint security and Power Platform responsibility rather than something owned entirely by one team.

Question 14. A team wants Azure AI services workloads to be actively monitored for threats and to appear in the Data and AI security dashboard. What is the correct first step?

  1. Assign the SQL Security Manager RBAC role
  2. Create a Conditional Access policy scoped to the workload's service principal
  3. Configure a custom IPsec/IKE policy
  4. Enable the Defender for AI Services plan on the relevant Azure subscription
Show answer

Answer: D, Enable the Defender for AI Services plan on the relevant Azure subscription. Threat detection and dashboard visibility for Azure AI services workloads specifically require the Defender for AI Services plan to be enabled on the subscription; the other options are unrelated identity, network, and database controls.

Implement security for servers and virtual machines

Question 15. A rootkit attempts to load an unsigned, malicious bootloader during a VM's startup sequence. Which Trusted Launch component is specifically responsible for blocking this?

  1. Secure Boot, since it validates boot components using digital signatures before allowing them to load
  2. The vTPM's credential storage function
  3. Microsoft Defender for Cloud integrity monitoring, since it runs before boot
  4. Measured Boot
Show answer

Answer: A, Secure Boot, since it validates boot components using digital signatures before allowing them to load. Secure Boot is the component that validates boot components against digital signatures and refuses to load anything unsigned or unauthorised, which is exactly what stops this rootkit at boot time. Measured Boot records what happened for later analysis rather than blocking anything itself, and integrity monitoring analyses those measurements after the fact, not before boot.

Question 16. Which Defender for Servers capability specifically analyses a server's disk contents for vulnerabilities, secrets, and malware without requiring an agent to be installed?

  1. File integrity monitoring
  2. Agent-based vulnerability assessment
  3. Agentless scanning, which runs automatically roughly every 24 hours
  4. Just-in-time VM access
Show answer

Answer: C, Agentless scanning, which runs automatically roughly every 24 hours. Agentless scanning is specifically the capability that inspects disk contents without an agent, running on an automatic roughly-24-hour cycle; agent-based vulnerability assessment, by contrast, requires an agent, and file integrity monitoring and JIT access address different concerns entirely.

Secure Azure application platform services for the cloud and AI security engineer

Question 17. A team wants group membership changes in Microsoft Entra ID to automatically update who can perform actions inside an AKS namespace, without editing any cluster configuration when membership changes. What should they configure?

  1. The Azure Kubernetes Service Cluster Admin role for every group member
  2. A ClusterRoleBinding scoped to the whole cluster for convenience
  3. A Kubernetes RoleBinding whose subject is the Microsoft Entra group's object ID
  4. A static kubeconfig file distributed to each group member
Show answer

Answer: C, A Kubernetes RoleBinding whose subject is the Microsoft Entra group's object ID. Binding a Kubernetes Role or ClusterRole to a Microsoft Entra group's object ID means access follows group membership automatically. A static kubeconfig does not update with membership, granting Cluster Admin is overly broad for namespace-scoped needs, and a cluster-wide ClusterRoleBinding is broader than required and not what enables automatic membership-based updates on its own.

Manage security posture by using Microsoft Defender for Cloud

Question 18. A security engineer sees an empty attack paths list for a subscription in Defender CSPM. What does this most directly indicate?

  1. Agentless scanning is disabled
  2. No confirmed externally exploitable attack paths were found
  3. Defender CSPM is not enabled on the subscription
  4. The cloud security graph has not been updated yet
Show answer

Answer: B, No confirmed externally exploitable attack paths were found. Attack path analysis focuses on externally driven, exploitable threats, so an empty list is a positive signal that no confirmed externally exploitable path currently exists. It does not by itself indicate the plan is disabled or the graph is stale, and agentless scanning being off would typically limit findings rather than produce a confirmed empty result.

Implement activity and event collection in Microsoft Sentinel

Question 19. A security team wants to reduce ingestion costs from the Microsoft Entra ID connector because they don't use automated user provisioning. What should they do?

  1. Move all Entra logs to the Basic plan and take no other action
  2. Create a restore job that excludes provisioning events
  3. Disable ingestion of the provisioning log category while keeping other Entra log categories enabled
  4. Disconnect the Microsoft Entra connector entirely
Show answer

Answer: C, Disable ingestion of the provisioning log category while keeping other Entra log categories enabled. Each log category the Entra connector offers, including provisioning logs, can be independently enabled or disabled, so turning off just that category reduces cost while preserving other log types like sign-ins and audit logs. Disconnecting the whole connector loses all Entra visibility, changing the plan alone doesn't stop ingesting unwanted data, and restore jobs apply to archived data, not live ingestion filtering.

Deploy and operate Microsoft Security Copilot

Question 20. A managed security provider runs Security Copilot for several client teams from one tenant. Each team needs its own capacity budget, its own plugin configuration, and session data kept in its client's region. What should the provider set up?

  1. One workspace with a promptbook per team
  2. One workspace and a custom plugin per team
  3. A separate Microsoft Entra tenant per team
  4. A separate Security Copilot workspace per team, each with its own capacity and data storage location
Show answer

Answer: D, A separate Security Copilot workspace per team, each with its own capacity and data storage location. Workspaces are exactly this segmentation boundary: each has its own SCU capacity, its own plugin and role configuration, and its own data storage location. Promptbooks and custom plugins do not isolate capacity or data residency, and separate tenants would be a far heavier change than the requirement needs.

A 6-week SC-500 study plan

Frequently asked questions

How hard is SC-500?

It's an associate-level exam that spans more products than most: identity, networking, data, compute, AI and security operations. Expect breadth, and plan time for the newer AI security topics.

How long should I study for SC-500?

Most people studying part-time should plan six to eight weeks, given the number of services covered. Hands-on practice in an Azure subscription helps the configuration questions stick.

Are these real SC-500 exam questions?

No. Microsoft exam questions are confidential, and sharing them breaks the agreement every candidate accepts. These are original questions written to the published skills outline, so they test the same knowledge in the same style.

Is CertBuddi free?

You can enrol free with no card. Free accounts get the opening modules of every course; Pro (£9.99 a month, or £79.99 a year) unlocks every module, the full timed mock exam and an adaptive study plan.

How should I use these practice questions?

Answer each one before you look at the explanation, and keep a list of the ones you get wrong. That list is your study plan: it's made of exactly the things you don't know yet.

CertBuddi is an independent study aid, not affiliated with or endorsed by Microsoft. These are original practice questions, not real exam questions.