Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the Microsoft Certified: Information Security Administrator Associate SC-500 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam SC-500 Premium Access

View all detail and faqs for the SC-500 exam


0 Students Passed

0% Average Score

0% Same Questions
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

You have Microsoft Security Copilot agents that authenticate by using Microsoft Entra service principals.

You receive a Microsoft Defender alert triggered by the anomalous OAuth authentication of an agent ' s Microsoft Entra service principal.

You need to assess the impact of the agent identity and identify which resources are affected if the identity is abused for lateral movement The solution must minimize administrative effort.

What should you do?

Options:

A.

From Advanced hunting, create a query against the IdentityLogonEvents table to list all the sign-ins performed by the identity.

B.

From Attack paths, select the identity and view the blast radius.

C.

From AI Observability in Microsoft Purview Data Security Posture Management (DSPM), review the agent activity.

D.

From Microsoft Purview Audit, query the audit logs for all the role assignments granted to the identity.

E.

From Incidents, review incidents related to OAuth events reported by Microsoft Defender for Cloud Apps.

Questions # 2:

You have multiple Microsoft Security Copilot workspaces.

A user named User1 accesses Security Copilot by using the default workspace.

You create a new workspace named Workspace 1 and assign a capacity to Workspace1.

You plan to route Security Copilot agent traffic to Workspace1.

You need to ensure that User1 can use embedded experiences without errors.

What should you do before switching to Workspace1?

Options:

A.

Add User1 to Workspace1.

B.

Assign User1 the Security Operator role in Microsoft Entra.

C.

Disassociate the capacity from the default workspace.

D.

Create a new capacity for Workspace1.

Questions # 3:

You have a Microsoft Entra tenant that has user consent for applications disabled.

You register an application named App1 that requests the following Microsoft Graph delegated permissions:

•user.Read

•Mail.Read

You need to configure tenant permissions to meet the following requirements:

•Enable users to grant consent for low-risk permissions without administrator interaction.

•Ensure that applications requesting higher-privilege permissions require administrator approval.

What should you do?

Options:

A.

Grant tenant-wide admin consent to App1.

B.

Configure application assignments for App1.

C.

Configure Privileged Identity Management (PIM) role assignments.

D.

Create an app consent policy.

Questions # 4:

You have a Microsoft Entra tenant that has the following configurations:

•User consent for applications is disabled.

•Only administrators can grant permissions to applications.

You register an application named App1 that uses delegated Microsoft Graph permissions.

You need to configure App1 to meet the following requirements:

•Enable user sign-ins without interactive consent prompts.

•Enable App1 to access Microsoft Graph on behalf of the signed-in user.

What should you do?

Options:

A.

Configure enterprise applications to require user assignment and assign users to App1.

B.

Modify the app registration to use application permissions instead of delegated permissions.

C.

Add the required delegated Microsoft Graph permissions to the app registration and rely on user consent during sign-in.

D.

Grant admin consent to App1 for the required delegated permissions.

Questions # 5:

You have a Microsoft Entra tenant.

You need to implement password less authentication. The solution must meet the following requirements:

•Users can sign in without a password by using a mobile device.

•New users that sign in for the first time must use a helpdesk issued sign in method that expires.

Which authentication method should you enable for each requirement? To answer, drag the appropriate methods to the correct requirements. Each method may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Question # 5

Options:

Questions # 6:

You have an Azure virtual network that contains 100 virtual machines and an Azure Firewall instance named FW1.

All the traffic from the virtual machines is routed through FW1.

You need to ensure that FW1 allows access to only a URL of updates contoso.com and blocks all other outbound traffic.

What should you use?

Options:

A.

An inbound NAT rule

B.

An application rule

C.

An outbound NAT rule

D.

A network rule

Questions # 7:

You have an Azure subscription that contains the following resources:

•An Azure SQL Database logical server named Server1 that contains a database named DB1

•An Azure SQL Managed Instance named Instance1 that contains a database named DB2

You need to configure database auditing. The solution must meet the following requirements:

•Ensure that audit data is centrally available in a location that supports for KQL queries.

•Minimize ongoing administrative effort as additional databases are added.

What should you configure? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 7

Options:

Questions # 8:

You have an Azure subscription that contains a resource group named RG1.

RG1 contains a Microsoft Security Copilot deployment that is integrated with a Microsoft Sentinel workspace named Workspace1.

Analysts use the Security Copilot standalone experience to retrieve incidents by using the Microsoft Sentinel plugin.

A user named User1 can sign in to Security Copilot but cannot retrieve incidents from Workspace1. You verify that User1 lias only the Security Copilot Contributor role.

You need to ensure that User1 can retrieve the incidents. The solution must follow the principle of least privilege and NOT require any configuration changes to Security Copilot.

Which role should you assign to User1?

Options:

A.

The Security Reader role in Microsoft Entra

B.

The Microsoft Sentinel Reader role for Workspace1

C.

The Security Copilot Owner role

D.

The Security Administrator role in Microsoft Entra

E.

The Contributor role in Azure for RG1

Questions # 9:

You have an Azure subscription named Sub1 that contains a storage account named storage1. Sub1 has Microsoft Defender for Storage enabled. Defender for Storage has malware scanning enabled.

You need to configure a solution that automates the remediation of malware detected in storage1.

What should you include in the solution?

Options:

A.

Application Insights

B.

Azure Event Hubs

C.

Azure Event Grid

D.

Azure Policy

Questions # 10:

You need to protect the applications hosted on AKS1. The solution must meet the technical requirements.

Which Defender for Cloud plan should you enable?

Options:

A.

Microsoft Defender for Servers

B.

Microsoft Defender for App Service

C.

Microsoft Defender for Containers

D.

Microsoft Defender for Resource Manager

E.

Microsoft Defender for Storage

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.