Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
You need to implement the planned change for storage2 The solution must meet the technical requirements for storage encryption.
What should you do?
An encryption scope provides a named encryption boundary for blobs and can use Microsoft-managed or customer-managed keys depending on configuration. The planned change refers to storage encryption, and the visible answer set points to a storage2-specific encryption configuration rather than vault purge protection or Azure RBAC. Account-level encryption keys affect the entire account; encryption scopes are the correct more granular storage encryption control. The important exam skill is separating data-plane access, management-plane administration, and network reachability. A storage, database, or firewall setting must be selected because it enforces the exact path requested in the scenario. Distractors often look plausible because they improve security generally, but they do not satisfy the protocol, scope, or automation requirement stated in the question. The result is a direct exam-style implementation choice: it changes the required security behavior without relying on unrelated monitoring, manual cleanup, or excessive privilege. Official Microsoft source/topic: SC-500 Study Guide > storage encryption; Microsoft Learn > Azure Storage encryption scopes.
You have an Azure subscription that has Microsoft Defender for Cloud enabled.
You have an Amazon Web Services (AWS) account connected to Defender for Cloud that has the Defender Cloud Security Posture Management (CSPM) plan enabled.
You need to identify the potential impact of security incidents that exploit multiple risks reported by Defender CSPM.
What should you use?
Attack path analysis in Defender CSPM identifies how multiple misconfigurations and risks can be chained to produce business impact. The scenario asks for potential impact of incidents that exploit multiple risks, which is exactly the attack path use case. Regulatory compliance shows framework alignment, security recommendations show individual controls, and Cloud Security Explorer is useful for querying posture data but does not automatically rank chained exploit paths. The SC-500 study guide places these tasks under security posture, event collection, Defender CSPM, EASM, Sentinel, and Security Copilot operations. The exam expects the control that minimizes analyst effort while preserving correct permissions and data flow. The selected answer reflects that service boundary and avoids a broader or merely investigative alternative. The result is a direct exam-style implementation choice: it changes the required security behavior without relying on unrelated monitoring, manual cleanup, or excessive privilege. Official Microsoft source/topic: SC-500 Study Guide > Defender CSPM; Microsoft Learn > attack path analysis.
You have an Azure Storage account named storage1 that contains Azure Files shares.
You have an application named App1 that uses a system-assigned managed identity to access the shares.
Administrators access the shares by using storage account keys.
You need to ensure that App1 access the shares without using the storage account keys.
What should you do on storage1?
The workload already has a managed identity, so the required control is an Azure Storage data-plane role assignment. Storage account keys are shared secrets and do not identify App1; putting them in Key Vault or rotating them only improves secret handling, not keyless authorization. Disabling shared key access or setting portal defaults is not enough unless the identity has the file-share data role required to read the share. Storage File Data Privileged Reader grants the managed identity Azure Files read access through Microsoft Entra authorization. Microsoft platform security questions usually hinge on where enforcement occurs: at the resource, server, subnet, firewall policy, private endpoint, or subscription level. The selected answer uses the control plane that owns that enforcement point. Other options are rejected when they only log activity, broaden network access, or protect a different service category. The result is a direct exam-style implementation choice: it changes the required security behavior without relying on unrelated monitoring, manual cleanup, or excessive privilege. Official Microsoft source/topic: SC-500 Study Guide > secure storage access; Microsoft Learn > Azure Files identity-based access and Azure Storage data-plane RBAC.
You have two management groups named MG1 and MG2 that contain multiple Azure subscriptions. The subscriptions are linked to a Microsoft Entra tenant.
You have a user named User1 and a global administrator named Admin 1
You are informed that User1 created an Azure subscription named Sub1 under the MG2 management group and is the only owner of the subscription.
You need to ensure that Admin1 can remove the Owner role from User1 for Sub1.
What should you do first?
A Global Administrator does not automatically have access to every Azure subscription. The first step is to enable Access management for Azure resources, which elevates the global administrator to manage Azure role assignments at the root scope. After that elevation, Admin1 can remove the Owner assignment from User1 on Sub1. Moving subscriptions or requesting Security Administrator would not provide the Azure RBAC authority needed to modify ownership. The exam objective emphasizes practical identity enforcement rather than cosmetic configuration. A valid answer must identify who authenticates, what permission is granted, where the scope is applied, and whether the method continues to work without passwords or secrets. That is why the selected answer is preferred over broader administrative roles or unrelated access settings. The result is a direct exam-style implementation choice: it changes the required security behavior without relying on unrelated monitoring, manual cleanup, or excessive privilege. Official Microsoft source/topic: SC-500 Study Guide > Azure role assignments; Microsoft Learn > elevate access to manage Azure resources.
You have an Azure subscription named Sub1 that contains a storage account named storage1
Sub1 has Microsoft Defender for Storage enabled. Defender for Storage has on-upload malware scanning enabled.
The security team at your company requires that all malicious files be processed automatically by a serverless workflow for quarantine and notification.
You need to ensure that the malware scan results trigger an automated response. The solution must minimize operational effort.
What should you configure?
The security team wants a serverless workflow to run when scan results are produced. Defender for Storage malware scanning emits events that can be subscribed to through Azure Event Grid, and Event Grid can trigger Azure Functions, Logic Apps, or other serverless handlers. Diagnostic settings and Log Analytics are useful for investigation but are not the lowest-effort event trigger for each malicious upload. Lifecycle policies are storage-management controls, not security remediation workflows. Microsoft platform security questions usually hinge on where enforcement occurs: at the resource, server, subnet, firewall policy, private endpoint, or subscription level. The selected answer uses the control plane that owns that enforcement point. Other options are rejected when they only log activity, broaden network access, or protect a different service category. The result is a direct exam-style implementation choice: it changes the required security behavior without relying on unrelated monitoring, manual cleanup, or excessive privilege. Official Microsoft source/topic: SC-500 Study Guide > Defender for Storage; Microsoft Learn > Event Grid events for malware scanning results.
81 questions covering all exam domains, starting from $20
Exam domains verified against: Official Microsoft SC-500 exam guide, last checked September 2026.
Secure access to resources using Microsoft Entra ID, implement Privileged Identity Management and conditional access, configure authentication methods including MFA and passwordless sign-in, and implement managed identities for Azure resources. Secure secrets and keys using Azure Key Vault including deployment, configuration, and access control. Implement governance through Azure Policy, resource locks, role assignments, and backup security features.
Implement security for storage accounts with firewall rules and Defender for Storage threat protection, configure access policies, and manage encryption. Implement platform-level security for Azure SQL and configure database auditing and Defender for Databases protection. Implement network security groups, application security groups, Azure Virtual Network Manager policies, secure VPN connections, Private Link services, and Azure Firewall. Evaluate effective security rules using Azure Network Watcher.
Implement AI security by identifying data overexposure in SharePoint, evaluating risks from Copilot and AI apps, enabling real-time protection for Copilot Studio agents, and configuring guardrails for agent security in Foundry. Secure servers and virtual machines through disk encryption, Azure Bastion, just-in-time VM access, and onboarding to Defender for Servers. Implement security for application platform services including containers, Kubernetes, Functions, Logic Apps, and App Service with Web Application Firewall protection.
Manage security posture using Defender for Cloud including Defender CSPM for identifying risks, workload protection plans, and connection of hybrid and multicloud environments. Implement activity and event collection in Microsoft Sentinel including workspace creation, role assignment, data connectors, syslog and CEF collections, Windows Security events, custom log tables, automation rules, and data retention. Implement Microsoft Security Copilot by configuring workspaces, managing permissions, and enabling plugins.
Common questions about the exam itself