Weekend Special Sale 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale75best

Free Microsoft SC-500 Practice Exam with Questions & Answers | Set: 4

Questions 31

You have a Microsoft Entra tenant that contains the users shown in the following table.

SC-500 Question 31

You have a Microsoft Security Copilot workspace.

From Microsoft Security Store, you plan to deploy a partner-built agent named Agent1 that requires access to Microsoft Intune.

When User1 selects Agent1, the Get agent option is unavailable.

You need to enable User1 to complete the agent setup. The solution must follow the principle of least privilege.

What should you do first?

Options:
A.

From Security Copilot, create an agent identity for Agent1.

B.

From Security Copilot, configure the required data source for Agent1.

C.

Assign User1 the AI Administrator role in Microsoft Entra.

D.

Assign User1 the Agent ID Administrator role in Microsoft Entra.

E.

Instruct User2 to approve the agent setup.

Microsoft SC-500 Premium Access
Questions 32

You have a Microsoft Entra tenant.

On January 1, you configure a Multifactor authentication registration policy that has the following settings

• Assignments: All users

• Require Microsoft Entra ID multifactor authentication registration: Enabled

• Enforce policy: On

On January 3, you create two new users named User1 and User2.

On January 5, User1 authenticates to Microsoft Entra ID for the first time. On January 7, User2 authenticates to Microsoft Entra ID for the first time.

On which date will User1 and User2 be forced to register for MFA? To answer, drag the appropriate dates to the correct users. Each date may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

SC-500 Question 32

Options:
Questions 33

You have a Microsoft 365 tenant that uses Microsoft Security Copilot and Microsoft Defender XDR.

Access to Microsoft Defender XDR is managed by using Microsoft entra global roles.

The Phishing triage Agent is available in Microsoft Defender. The required agent prerequisites and approvals are complete

Two users will perform the following tasks:

• User1 will enable and manage the Phishing Triage Agent settings.

• User2 will use Security Copilot in Microsoft Defender XDR to manage phishing incidents identified by the agent.

You need to assign the least-privileged built in Microsoft Entra role and Security Copilot role combination to each us Which roles should you assign to each user? To answer, select the appropriate options in the answer area.

SC-500 Question 33

Options:
Questions 34

You have an Azure subscription named Sub1 that contains a storage account named storage1

Sub1 has Microsoft Defender for Storage enabled. Defender for Storage has on-upload malware scanning enabled for a monthly cap of 10,000 GB per storage account.

You use a Microsoft Sentinel workspace to monitor security events on all Azure resources.

You need to configure storage1 to use a malware scanning cap of 2.000 GB per month.

What should you do?

Options:
A.

Enable Override Defender for Storage subscription-level settings for storage1.

B.

From Microsoft Sentinel, modify the data collection rule (DCR) to restrict log ingestion from storage1.

C.

Modify the malware scanning configuration of Sub1.

D.

From the Microsoft Sentinel workspace, modify the daily cap.

Questions 35

You use Microsoft Security Copilot.

Security Copilot contributors currently create custom plugins for their own sessions and manage organization-wide custom plugins.

You need to prevent the contributors from managing the organization-wide custom plugins. The solution must NOT affect the contributors ' ability to create custom plugins for their own sessions.

What should you select in the Plugin settings?

Options:
A.

Contributors and Owners at the tenant scope

B.

Owners only at the user scope

C.

Contributors and Owners at the user scope

D.

Owners only at the tenant scope

Questions 36

You have an Azure subscription named Sub1 that is linked to a Microsoft Entra tenant named contoso.com.

Sub1 contains a Recovery Services vault named RSVault1 that stores virtual machine backups.

Your company’s security team maintains a dedicated Microsoft Entra tenant named security.contoso.com.

You need to ensure that modifying the backup settings of RSVault1 requires approval from an approver in security.contoso.com.

What should you do in contoso.com?

Options:
A.

Enable immutability for RSVault1 and lock the immutability setting.

B.

Create a private endpoint for RSVault1 on the virtual network.

C.

Configure Privileged Identity Management (PIM) activation for the Backup Operator role.

D.

Enable Multi-user authorization (MUA) for RSVault1.

Questions 37

You have a Microsoft Entra tenant that contains a user named User1.

You have an Azure Arc-enabled server named SRV1 that runs Windows Server. SRV1 is configured for Microsoft Entra sign-in.

User1 reports that when they use their Microsoft Entra credentials to sign in to SRV1 over RDP, they receive the following message:

“Your account is configured to prevent you from using this device.”

You need to ensure that User1 can sign in to SRV1 over RDP. The solution must follow the principle of least privilege.

What should you do?

Options:
A.

Assign User1 the Virtual Machine Administrator Login role for SRV1.

B.

Create a Conditional Access policy that requires multifactor authentication (MFA).

C.

Add User1 to the local Remote Desktop Users group on SRV1.

D.

Assign User1 the Virtual Machine User Login role for SRV1.

Questions 38

You have an Azure subscription named Sub1 that contains a storage account named storage1. Sub1 has Microsoft Defender for Storage enabled. Defender for Storage has malware scanning enabled.

You need to configure a solution that automates the remediation of malware detected in storage1.

What should you include in the solution?

Options:
A.

Azure Logic Apps

B.

a Log Analytics workspace

C.

an alert rule

D.

Azure Policy

Questions 39

Vou have a Microsoft Entra tenant that uses Microsoft Entra Agent ID. You have multiple Microsoft Foundry agents that have agent identities assigned. Vou dm OW that one of the identities is flagged as high risk duf in unusual sign-in activity. Vou need to ensure that agent access to resources is restricted automatically based on risk. What should you create?

Options:
A.

a Privileged Identity Management (PIM) activation policy

B.

a Microsoft Entra role assignment policy

C.

a Conditional Access policy for the identities

D.

an Access review for the identities

Questions 40

You have a Microsoft 365 tenant that has Microsoft 365 Copilot enabled for a pilot group.

Users frequently generate responses based on Microsoft Teams chats and Microsoft SharePoint Online sites.

You use Microsoft Purview Data Security Posture Management (DSPM) to identify inversharing risks and create policies based on the recommendations.

You need to manage and edit the policies created by DSPM

Which Microsoft Purview solution should you use?

Options:
A.

Insider Risk Management

B.

Data Loss Prevention

C.

information Protection

D.

Communication Compliance

Exam Code: SC-500
Certification Provider: Microsoft
Exam Name: Microsoft Certified: Cloud and AI Security Engineer Associate
Last Update: Sep 19, 2026
Questions: 135