SC-500 Sample Questions & Answers
Securing databases, storage accounts and Azure network services carries the most weight, alongside identity access through Key Vault secrets and Microsoft Entra ID plus governance compliance, securing AI and compute, and monitoring posture with Defender and Sentinel.
Launch the full SC-500 simulator →Showing 6 of 12 free samples.
- Question 1IntermediateSelect 2
Manage identity, access, and governance · Scan for secrets by using Defender Cloud Security Posture Management (Defender CSPM)
You enable agentless secrets scanning across your production Azure subscriptions using Microsoft Defender CSPM. Discovered secrets are cataloged and ingested into the cloud security graph.
In which TWO surfaces within the Microsoft Defender for Cloud portal can security engineers investigate these discovered secrets? (Select TWO)
Show answer & explanation
Correct answers: A, E
Attack path analysis uses cloud security graph data to model lateral movement risks, evaluating whether discovered secrets on a VM expose an exploitable path to sensitive crown-jewel assets. It is one of the primary investigation surfaces for Defender CSPM secrets scanning.
Cloud security explorer allows analysts to build custom queries and use pre-built templates against the cloud security graph to search specifically for compute resources containing exposed plaintext secrets.
- Question 2Advanced
Manage identity, access, and governance · Configure security controls for backup protection by using Azure Backup security features
Contoso Pharmaceuticals maintains critical clinical trial database backups in Azure Recovery Services vaults. A recent threat assessment revealed that rogue administrators or compromised credentials could delete backup data or disable security configurations to facilitate ransomware extortion.
The enterprise requirements are:
- Prevent any operation that could cause loss of recovery points by enforcing WORM (write once, read many) storage in an irreversible state.
- Ensure critical backup management actions (such as disabling soft delete or modifying retention) mandate approval from an independent security team using a separate authorization object.
- Elevate the vault security posture to achieve the 'Excellent (Maximum)' vault security level in Azure Backup.
Which combination of Azure Backup security features must you implement to fulfill these requirements?
sequenceDiagram autonumber participant Admin as Backup Administrator participant RG as Resource Guard (Security Subscription) participant Vault as Recovery Services Vault participant Storage as Immutable WORM Storage Admin->>RG: Request authorization for critical operation RG-->>Admin: Approval granted via MUA Admin->>Vault: Submit modify/delete command with MUA token Vault->>Storage: Block deletion (Locked Immutability)Show answer & explanation
Correct answer: A
To achieve the 'Excellent (Maximum)' security level in Azure Backup, a vault must have Multi-User Authorization (MUA) enabled AND either immutability configured in an irreversible 'Locked' state or soft delete configured as irreversible ('always-on'). MUA uses an Azure Resource Guard deployed in a separate subscription with restricted RBAC, requiring secondary approval before executing destructive actions. Locking the immutable vault enforces WORM retention permanently, preventing even subscription owners from revoking immutability or pruning recovery points prematurely.
- Question 3Intermediate
Manage identity, access, and governance · Configure security controls for backup protection by using Azure Backup security features
A security engineer is evaluating the soft delete capabilities of Azure Backup for a newly provisioned Recovery Services vault. The engineer must ensure that soft delete protection cannot be disabled by a compromised administrative identity, and that deleted backup items are retained beyond the default window.
Which configuration achieves this protection?
Show answer & explanation
Correct answer: B
Enhanced soft delete in Azure Backup permits administrators to customize the retention window (from 14 up to 180 days) and set the state to 'Always-On'. Once soft delete is set to 'Always-On', it becomes irreversible and cannot be turned off by any user or administrator, providing robust defense against ransomware attempting to purge backup data before encrypting production systems. Standard soft delete has a fixed 14-day window and can be disabled by a compromised user with Contributor rights on the vault unless protected by MUA or Always-On.
- Question 4Beginner
Manage identity, access, and governance · Configure security controls for backup protection by using Azure Backup security features
True or False: Once an Azure Backup Recovery Services vault has its immutability setting transitioned from 'Unlocked' to 'Locked', the immutable state becomes irreversible and cannot be disabled by any user, including the Subscription Owner and Microsoft Support.
Show answer & explanation
Correct answer: A
An immutable vault protects recovery points by preventing operations that could lead to data loss. In the 'Unlocked' state, immutability can be toggled off or modified. However, once an administrator moves the vault to the 'Locked' state, the immutability configuration becomes permanent and irreversible. No party—including Subscription Owners, Global Administrators, or Microsoft Support—can revert the lock or disable immutability.
- Question 5Intermediate
Secure storage, databases, and networking · Implement Defender for Storage threat protection configurations
A retail organization utilizes Azure Blob Storage to receive order invoices uploaded by branch offices. The security team has enabled Defender for Storage with malware scanning enabled and a monthly scanning cap of 500 GB configured on the storage account to control costs.
During a peak holiday sales week, incoming uploads surge and reach 380 GB within the first ten days of the billing cycle.
Which specific security alert is generated by Defender for Storage when this threshold is reached?
Show answer & explanation
Correct answer: A
380 GB of a 500 GB cap represents 76% consumption, which crosses the 75% threshold. Defender for Storage triggers the specific informational security alert: 'Malware scanning will stop soon: 75% of monthly gigabytes scan cap reached'. If consumption reaches 100% (500 GB), it halts scanning and raises the alert 'Malware scanning stopped: monthly gigabytes scan cap reached'.
- Question 6Intermediate
Secure storage, databases, and networking · Implement Defender for Storage threat protection configurations
A software company requires near-real-time automated containment of malicious files uploaded to its public-facing Azure Blob Storage containers. When Defender for Storage detects a file containing malware, the malicious blob must be immediately moved to a quarantined container and tagged as infected, without manual security analyst intervention.
Which architectural integration fulfills this requirement with the lowest administrative complexity?
flowchart LR Upload[Client Blob Upload] --> Storage[(Azure Blob Storage)] Storage --> Scan{Defender for Storage Malware Scan} Scan -->|Malicious Verdict| EG[Azure Event Grid System Topic] EG --> Sub[Event Subscription] Sub --> Auto[Azure Function / Logic App] Auto --> Quarantine[(Quarantine Container)]Show answer & explanation
Correct answer: D
Defender for Storage malware scanning publishes scan results directly to Azure Event Grid. By creating an Event Grid subscription targeting the Microsoft.Security.MalwareScanningResult event type, organizations can trigger automated serverless workloads (such as Azure Functions or Logic Apps) to delete, quarantine, or apply blob index tags to malicious files in near real time immediately after detection.
Ready for the real thing?
The full SC-500 simulator has every exam-style question, timed mode, and instant scoring.