SC-500 sample questions with answers

10 free practice questions for the Exam SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads exam. Try each one, then open the answer to see why the right option wins and every other option loses.

Question 1Manage identity, access, and governance

An audit of Contoso subscriptions finds 38 permanent Owner assignments on production subscriptions, and sign-in data shows that most of the holders have not used the permissions for 90 days. You must reduce standing privilege and make the remaining entitlements subject to periodic confirmation, without removing the ability to perform emergency changes. Which two actions should you perform? Each correct answer presents part of the solution.

Choose 2.

  1. A.

    Enable security defaults in the Microsoft Entra tenant.

  2. B.

    Apply a ReadOnly lock to each production subscription.

  3. C.

    Convert the Owner assignments to eligible assignments for the Azure resource role in Microsoft Entra Privileged Identity Management.

  4. D.

    Create a custom role that includes Microsoft.Authorization/roleAssignments/write and assign it to all 38 users.

  5. E.

    Replace every Owner assignment with a Contributor assignment at the subscription scope.

  6. F.

    Create an access review in Privileged Identity Management for the Owner role on each production subscription, with reviewers required to confirm continued need.

Show answer

Answer: C, F

Eligible assignments in PIM remove standing Owner privilege while keeping emergency activation, and access reviews force periodic confirmation of who still needs it.

  • A. Security defaults enforce baseline authentication settings for the tenant and have no effect on Azure resource role assignments.
  • B. A ReadOnly lock blocks all write operations, which directly contradicts the requirement to keep emergency changes possible.
  • C. Eligibility eliminates standing Owner privilege while leaving a governed, time-bound activation path for emergencies.
  • D. Granting role-assignment write rights hands out the most dangerous Owner permission and increases privilege rather than reducing it.
  • E. Contributor is still broad standing privilege across the subscription and removes legitimate role-assignment capability during incidents.
  • F. A recurring PIM access review forces reviewers to reconfirm each entitlement and can remove unused access automatically with an audit record.
Question 2Manage identity, access, and governance

Northwind publishes an internal expenses app as an enterprise application in Microsoft Entra ID. Only members of the group Finance-Staff may obtain a token for the application. A background component of the app runs on Azure App Service and must call Microsoft Graph with application permissions, and no credential may be stored anywhere. Which two actions should you perform? Each correct answer presents part of the solution.

Choose 2.

  1. A.

    Set Assignment required to Yes on the enterprise application and assign the Finance-Staff group to it.

  2. B.

    Assign the Application Administrator role to the members of Finance-Staff.

  3. C.

    Set the supported account types of the app registration to Accounts in this organizational directory only.

  4. D.

    Enable a system-assigned managed identity on the App Service and grant that identity the required Microsoft Graph application permission.

  5. E.

    Add a client secret to the app registration and store the secret in Azure Key Vault.

  6. F.

    Create a Conditional Access policy that blocks all users except the members of Finance-Staff from the application.

Show answer

Answer: A, D

Assignment required plus a group assignment gates token issuance, and a managed identity with a Graph app role removes the stored credential.

  • A. Assignment required makes Microsoft Entra ID refuse tokens to principals with no app role assignment, so only Finance-Staff can use the app.
  • B. Application Administrator is a privileged directory role that lets holders manage applications and credentials, the opposite of least privilege here.
  • C. Supported account types limits which tenants can use the application, which does nothing to restrict users inside the home tenant.
  • D. A system-assigned managed identity gives the App Service a platform-issued token for Microsoft Graph with no credential stored anywhere.
  • E. A client secret is still a stored credential that must be rotated, and the app needs another credential to read it from the vault.
  • F. Conditional Access evaluates sign-in risk and conditions, not entitlement; unassigned users remain assigned to the app and the control costs premium licences.
Question 3Manage identity, access, and governance

Contoso stores Azure virtual machine backups in a Recovery Services vault. A ransomware playbook requires that a compromised backup administrator who holds the Backup Contributor role cannot disable soft delete or shorten the retention of a backup policy, and that a separate security team must approve any such change. What should you implement?

  1. A.

    Multi-user authorization by using a Resource Guard that is owned by the security team in a different subscription

  2. B.

    A ReadOnly lock on the Recovery Services vault

  3. C.

    Reassign the backup administrators from Backup Contributor to Backup Operator, and require them to activate that role through an eligible assignment in Privileged Identity Management

  4. D.

    Immutable vault with the immutability setting left unlocked

Show answer

Answer: A

Multi-user authorization with a Resource Guard forces critical vault operations through a second principal that the backup administrator does not control.

  • A. Multi-user authorization requires rights on a Resource Guard held by another team, creating an enforced approval step for destructive vault operations.
  • B. A ReadOnly lock blocks legitimate backup and policy operations too, and an Owner can delete the lock before making the change.
  • C. Changing the role and adding PIM activation narrows standing permissions but introduces no second-party approval of soft delete or retention changes on the vault.
  • D. Immutability protects recovery points from early deletion, and while the setting is unlocked the same administrator can simply disable it.
Question 4Manage identity, access, and governance

A support team at Contoso must be able to update the redirect URIs and the owners of one specific application registration in Microsoft Entra ID. The team must have no rights over any other application registration and no rights over Azure resources. What should you do?

  1. A.

    Create a custom Microsoft Entra role that contains the application management permissions the team needs, and assign it scoped to that single application registration.

  2. B.

    Add the team to the owners of the application registration and assign them the Cloud Application Administrator role.

  3. C.

    Create a custom Azure role that contains the application update actions, set AssignableScopes to the subscription that hosts the workload, and assign the role to the support team at that subscription.

  4. D.

    Assign the built-in Application Administrator role to the team at the directory scope.

Show answer

Answer: A

A custom Microsoft Entra role assigned at the scope of a single application registration grants exactly the needed permissions on exactly one object.

  • A. A custom Entra role with object-level scope grants only the required application permissions on only the named registration.
  • B. Cloud Application Administrator restores tenant-wide application rights, so the scope requirement is violated even though ownership alone would be scoped.
  • C. Azure roles govern Resource Manager resources and cannot express permissions over Microsoft Entra directory objects.
  • D. Application Administrator applies to every application in the directory and can manage credentials, which is a privilege escalation path.
Question 5Manage identity, access, and governance

Litware discovers that users have consented to unverified multitenant applications that read their mailboxes. Users must still be able to consent to applications published by verified publishers when the application requests only low-impact delegated permissions such as User.Read. Every other consent request must reach an administrator for approval. What should you configure in Microsoft Entra ID?

  1. A.

    Set user consent settings to allow user consent for apps from verified publishers for selected permissions, and enable the admin consent workflow.

  2. B.

    Assign the Cloud Application Administrator role to the members of each department who request applications.

  3. C.

    Create a Conditional Access policy that blocks access to all cloud apps except the approved enterprise applications, and require a compliant device for every sign-in to those applications.

  4. D.

    Set user consent settings to Do not allow user consent, and tell users to email the help desk when they need an application.

Show answer

Answer: A

The verified-publisher consent tier plus the admin consent workflow allows low-impact self-service consent while routing everything else to an approver.

  • A. It keeps self-service consent for verified publishers and classified low-impact permissions while routing all other requests through the admin consent workflow.
  • B. Cloud Application Administrator can grant tenant-wide admin consent, so it widens the exposure instead of constraining it.
  • C. Conditional Access evaluates sign-in conditions and grant controls; it has no control over OAuth permission grants or consent decisions, and a compliant-device rule does not stop a user from consenting.
  • D. Blocking all user consent removes the required self-service path for low-impact verified apps and replaces a tracked workflow with untracked email.
Question 6Manage identity, access, and governance

You migrate the key vault kv-fin to the Azure role-based access control permission model. An application that runs with a user-assigned managed identity must use an RSA key in the vault to decrypt payloads and to sign tokens. The identity must not be able to create, import, rotate, or delete keys. Which built-in role should you assign to the identity?

  1. A.

    Key Vault Crypto Officer

  2. B.

    Key Vault Crypto User

  3. C.

    Key Vault Reader

  4. D.

    Key Vault Crypto Service Encryption User

Show answer

Answer: B

Key Vault Crypto User permits cryptographic operations with existing keys while withholding key lifecycle management.

  • A. Crypto Officer adds full key lifecycle management, including delete and import, which the requirement explicitly forbids.
  • B. It allows decrypt, sign, wrap, and unwrap with existing keys while withholding create, import, rotate, and delete.
  • C. Key Vault Reader exposes vault and object metadata only and grants no cryptographic operations whatsoever.
  • D. That role is limited to get, wrap, and unwrap for service-side envelope encryption, so decrypt and sign operations would be denied.
Question 7Manage identity, access, and governance

Tailspin Toys wants engineers to receive just-in-time membership of a group that holds the Key Vault Administrator role on a production vault. The only existing candidate is SG-KV-Admins, a security group synchronized from on-premises Active Directory by Microsoft Entra Connect. What should you do so that the membership can be managed in Privileged Identity Management?

  1. A.

    Convert SG-KV-Admins to a dynamic membership group with a rule on the department attribute

  2. B.

    Recreate SG-KV-Admins as a role-assignable group, because PIM for Groups accepts only role-assignable groups

  3. C.

    Create a cloud-only Microsoft Entra security group, assign it the vault role, and enable the new group in PIM for Groups

  4. D.

    Enable SG-KV-Admins in PIM for Groups and make each engineer an eligible member of the synchronized group

Show answer

Answer: C

PIM for Groups accepts cloud security groups and Microsoft 365 groups, but not dynamic groups or groups synchronized from on-premises, so a new cloud group is needed.

  • A. Dynamic membership groups are also excluded from PIM for Groups, and a rule grants standing membership rather than just-in-time access.
  • B. The role-assignable requirement for PIM for Groups was removed in January 2023; any cloud security or Microsoft 365 group can be enabled.
  • C. PIM for Groups supports cloud security groups and Microsoft 365 groups but excludes groups synchronized from on-premises, so a new cloud group is required.
  • D. Groups synchronized from an on-premises environment can't be enabled in PIM for Groups, so the synchronized group can't be onboarded.
Question 8Manage identity, access, and governance

A. Datum runs nightly Azure CLI scripts on a build server. The scripts sign in as svc-deploy, a Microsoft Entra user account with a password, and create resource groups. Since Azure mandatory MFA enforcement reached Azure CLI in the tenant, every create operation fails with an MFA claims challenge. What should you do?

  1. A.

    Exclude svc-deploy from every Conditional Access policy that requires multifactor authentication

  2. B.

    Enable security defaults so that svc-deploy is prompted to register Microsoft Authenticator

  3. C.

    Replace svc-deploy with a managed identity or a service principal and update the scripts to sign in with that workload identity

  4. D.

    Ask a Global Administrator to opt the tenant out of mandatory MFA for Azure CLI and PowerShell

Show answer

Answer: C

Mandatory Azure MFA applies to user accounts, not to managed identities or service principals, so automation must move to a workload identity.

  • A. Mandatory MFA is enforced by Azure Resource Manager regardless of Conditional Access exclusions, so excluding the account changes nothing.
  • B. An unattended script can't complete an interactive MFA prompt, so registering a method doesn't make the nightly job work.
  • C. Mandatory MFA applies to user accounts; managed identities and service principals aren't affected, and Microsoft recommends migrating user-based service accounts to them.
  • D. Learn states there is no way to opt out; postponement was only available for a limited period, not as a permanent exclusion.
Question 9Manage identity, access, and governance

Proseware deleted the vault kv-billing-prod last week during a cleanup. Purge protection was enabled with a 90-day retention period. A pipeline that redeploys kv-billing-prod in the same region now fails with a conflict because the name is in use. The original keys and secrets are still needed. What should you do?

  1. A.

    Purge the deleted vault after assigning yourself the Key Vault Purge Operator role, and then rerun the pipeline so that it creates a new, empty vault with the original name

  2. B.

    Disable soft delete on the subscription and rerun the pipeline

  3. C.

    Rerun the pipeline with a new resource group, because vault names are unique only within a resource group

  4. D.

    Recover the soft-deleted vault kv-billing-prod, and then let the pipeline update the recovered vault in place instead of creating it

Show answer

Answer: D

A soft-deleted vault holds its name until retention ends; with purge protection the answer is to recover it, which also restores its contents.

  • A. Purge protection prevents purging until the 90-day retention ends, and purging would destroy the keys and secrets that are still needed.
  • B. Soft delete can't be disabled once enabled, and turning it off wouldn't release a name that is already held by a deleted vault.
  • C. The name of a soft-deleted vault is reserved and can't be reused for a new vault in that location until the retention period expires.
  • D. A soft-deleted vault reserves its name and can be recovered with its objects intact; purge protection blocks purging, so recovery is the path forward.
Question 10Manage identity, access, and governance

An engineer at Fourth Coffee assigned a built-in policy to a resource group ten minutes ago, but the compliance page for the assignment still shows no results. The engineer must see results before a change review this afternoon instead of waiting for the next standard cycle. What should the engineer do?

  1. A.

    Set enforcementMode to DoNotEnforce so that evaluation runs without the effect

  2. B.

    Run az policy state trigger-scan for the resource group

  3. C.

    Delete and re-create the assignment so that it's applied again

  4. D.

    Create a remediation task for the assignment

Show answer

Answer: B

An on-demand evaluation scan, such as az policy state trigger-scan, produces compliance results without waiting for the 24-hour cycle.

  • A. Enforcement mode doesn't speed up evaluation, and it would stop the effect from being enforced.
  • B. An on-demand evaluation scan starts compliance evaluation immediately for the subscription or a specified resource group.
  • C. Re-creating the assignment restarts the same process and adds delay; it doesn't force faster evaluation.
  • D. Remediation tasks apply DeployIfNotExists or Modify changes; they aren't a way to produce compliance results.

Keep going with 502 more SC-500 questions

Free papers every day, in the real exam formats, with progress by exam domain. Unlock every paper and timed mock exam when you are ready.

SC-500 sample questions with answers (10 free) · CertifyCloudx