Free SC-500 Questions for Microsoft Implementing End-to-End Security Controls for Cloud and AI Workloads SC-500 Exam as PDF & Practice Test Engine
Drag and Drop Question
You use Azure Virtual Network Manager to manage multiple virtual networks organized into two network groups named Production and Development.
You need to configure Virtual Network Manager to meet the following requirements:
- Allow traffic between all the virtual networks in Production.
- Block traffic between Development and Production.
What should you use for each requirement? To answer, drag the components to the correct requirements. Each component may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

You use Azure Virtual Network Manager to manage multiple virtual networks organized into two network groups named Production and Development.
You need to configure Virtual Network Manager to meet the following requirements:
- Allow traffic between all the virtual networks in Production.
- Block traffic between Development and Production.
What should you use for each requirement? To answer, drag the components to the correct requirements. Each component may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
Box 1: Connectivity configuration
To allow traffic between all the virtual networks in a single network group using Azure Virtual Network Manager, you must configure a Connectivity configuration using a Mesh network topology and deploy it to the target regions.
Box 2: Security Admin Configuration
To block traffic between the two network groups using Azure Virtual Network Manager (AVNM), you must configure a Security Admin Configuration containing a rule collection that explicitly denies traffic between the two groups, and then deploy that configuration to the target regions.
Reference:
https://learn.microsoft.com/en-us/azure/virtual-network-manager/overview
You have an Azure virtual network that contains 100 virtual machines and an Azure Firewall instance named FW1.
All the traffic from the virtual machines is routed through FW1.
You need to ensure that FW1 allows access to only a URL of updates.contoso.com and blocks all other outbound traffic.
What should you use?
All the traffic from the virtual machines is routed through FW1.
You need to ensure that FW1 allows access to only a URL of updates.contoso.com and blocks all other outbound traffic.
What should you use?
Correct Answer: B
Vote an answer
Explanation: Only visible for ExamDiscuss members. You can sign-up / login (it's free).
Drag and Drop Question
You have two Azure subscriptions named Sub1 and Sub2.
You have two groups named Group1 and Group2. Group1 only has access to Sub1 and Group2 only has access to Sub2.
Sub1 contains a Recovery Services vault named RSVault1 that stores virtual machine backups.
RSVault1 is managed by using Group1.
You need to ensure that modifying the backup settings of RSVault1 requires approval from an approver in Group2.
What should you configure for each subscription? To answer, drag the appropriate features to the correct subscriptions. Each feature may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

You have two Azure subscriptions named Sub1 and Sub2.
You have two groups named Group1 and Group2. Group1 only has access to Sub1 and Group2 only has access to Sub2.
Sub1 contains a Recovery Services vault named RSVault1 that stores virtual machine backups.
RSVault1 is managed by using Group1.
You need to ensure that modifying the backup settings of RSVault1 requires approval from an approver in Group2.
What should you configure for each subscription? To answer, drag the appropriate features to the correct subscriptions. Each feature may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
Box 1: Multi-User Authorization (MUA)
Sub1 (where Group1 and the Vault reside):
Enable Multi-User Authorization (MUA) on the Recovery Services vault.
Associate the vault with the Resource Guard located in Sub2.
Box 2: Resource Guard
Sub2 (where Group2 has access):
Deploy the Azure Resource Guard here.
Assign the Resource Guard Reader and Resource Guard Contributor (or a custom role with authorize actions) roles to Group2 over this Resource Guard.
Reference:
https://learn.microsoft.com/en-us/azure/backup/multi-user-authorization
Hotspot Question
You have an Azure Container Instances container group named CGI that has a DNS name of cg1.contoso.com. CG1 has the following configurations:
- A Linux container named container1 that serves HTTPS over TCP port
443 and hosts an application named App1
- A Linux container named contained that listens on TCP port 5000 and
is accessed only by App1
- A public IP address
A security review finds that external clients can reach TCP port 5000 by using the public IP address of CG1.
You need to meet the following requirements:
- Ensure that the external clients can access container1 only by using
TCP port 443.
- Ensure that container1 can continue to access contained.
What should you configure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You have an Azure Container Instances container group named CGI that has a DNS name of cg1.contoso.com. CG1 has the following configurations:
- A Linux container named container1 that serves HTTPS over TCP port
443 and hosts an application named App1
- A Linux container named contained that listens on TCP port 5000 and
is accessed only by App1
- A public IP address
A security review finds that external clients can reach TCP port 5000 by using the public IP address of CG1.
You need to meet the following requirements:
- Ensure that the external clients can access container1 only by using
TCP port 443.
- Ensure that container1 can continue to access contained.
What should you configure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

You have an Azure Logic Apps Consumption workflow that uses a Request trigger. All supported authentication methods are enabled on the Request trigger.
You need to ensure that the endpoint accepts only OAuth-based requests. The solution must minimize costs.
What should you do?
You need to ensure that the endpoint accepts only OAuth-based requests. The solution must minimize costs.
What should you do?
Correct Answer: B
Vote an answer
Explanation: Only visible for ExamDiscuss members. You can sign-up / login (it's free).
You have Microsoft Security Copilot agents that authenticate by using Microsoft Entra service principals.
You receive a Microsoft Defender alert triggered by the anomalous OAuth authentication of an agent's Microsoft Entra service principal.
You need to assess the impact of the agent identity and identify which resources are affected if the identity is abused for lateral movement. The solution must minimize administrative effort.
What should you do?
You receive a Microsoft Defender alert triggered by the anomalous OAuth authentication of an agent's Microsoft Entra service principal.
You need to assess the impact of the agent identity and identify which resources are affected if the identity is abused for lateral movement. The solution must minimize administrative effort.
What should you do?
Correct Answer: B
Vote an answer
Explanation: Only visible for ExamDiscuss members. You can sign-up / login (it's free).
0
0
0
10
