MICROSOFT · SC-500

Microsoft SC-500 Exam Practice Questions

121 questionsInstant PDF downloadUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 121 questions in this pack

Question 1

You have an Azure SQL Database logical server named Server1 that contains a database named DB1.

You need to configure authentication for Server1 to meet the following requirements:

SQL authentication cannot be used for any databases on Server1.

The solution must be enforced centrally at the server level.

What should you do?

  1. Configure a Microsoft Entra administrator for Server1.
  2. Enable a managed identity for Server1.
  3. Enable Microsoft Entra-only authentication for Server1.
  4. Remove SQL logins from DB1.
Show answer and explanation

Correct answer: C. Enable Microsoft Entra-only authentication for Server1.

Server1. Microsoft Entra-only authentication is a server-level setting on the Azure SQL logical server. Once enabled, the server refuses every SQL authentication connection across all of its databases, while existing SQL logins stay in place. That is exactly what the requirements ask for: SQL authentication unusable for any database on Server1, enforced centrally in one place rather than database by database.

Why the other options are wrong

  • A. Adding a Microsoft Entra administrator enables Entra authentication alongside SQL authentication. It permits the new method but never disables the old one.
  • B. A managed identity gives Server1 an identity for reaching out to other Azure resources. It has no bearing on how clients authenticate inbound to the server.
  • D. Removing SQL logins from DB1 is a per-database action that leaves other databases untouched and does not stop new SQL logins being created later. It fails the central enforcement requirement.

Question 2

You have a Microsoft Entra tenant that has the following configurations:

User consent for applications is disabled.

Only administrators can grant permissions to applications.

You register an application named App1 that uses delegated Microsoft Graph permissions.

You need to configure App1 to meet the following requirements:

Enable user sign-ins without interactive consent prompts.

Enable App1 to access Microsoft Graph on behalf of the signed-in user.

What should you do?

  1. Configure enterprise applications to require user assignment and assign users to App1.
  2. Modify the app registration to use application permissions instead of delegated permissions.
  3. Add the required delegated Microsoft Graph permissions to the app registration and rely on user consent during sign-in.
  4. Grant admin consent to App1 for the required delegated permissions.
Show answer and explanation

Correct answer: D. Grant admin consent to App1 for the required delegated permissions.

delegated permissions. User consent is disabled tenant-wide, so a user can never approve the delegated permissions themselves and would be blocked at sign-in. Granting tenant-wide admin consent pre-approves the delegated Microsoft Graph permissions on behalf of the whole organization. Users then sign in with no interactive consent prompt, and because the permissions remain delegated, App1 still calls Graph as the signed-in user.

Why the other options are wrong

  • A. Requiring user assignment controls which users are allowed to access App1. It governs access, not consent, so the consent prompt still blocks sign-in.
  • B. Application permissions run as the app itself with no signed-in user, which breaks the requirement that App1 act on behalf of the user.
  • C. Relying on user consent during sign-in is precisely what the tenant configuration forbids, so sign-in fails.

Question 3

You have two management groups named MG1 and MG2 that contain multiple Azure subscriptions. The subscriptions are linked to a Microsoft Entra tenant.

You have a user named User1 and a global administrator named Admin1.

You are informed that User1 created an Azure subscription named Sub1 under the MG2 management group and is the only owner of the subscription.

You need to ensure that Admin1 can remove the Owner role from User1 for Sub1.

What should you do first?

  1. Move Sub1 to MG1.
  2. Assign Admin1 the User Access Administrator role for Sub1.
  3. Instruct Admin1 to use Privileged Identity Management (PIM) to request the Security Administrator role.
  4. Instruct Admin1 to enable Access management for Azure resources.
Show answer and explanation

Correct answer: D. Instruct Admin1 to enable Access management for Azure resources.

Azure resources. A Global Administrator has no Azure RBAC permission over subscriptions by default, which is why Admin1 cannot touch the Owner assignment. Enabling Access management for Azure resources elevates the Global Administrator and assigns them User Access Administrator at the root scope, covering every management group and subscription in the tenant. From there Admin1 can manage role assignments on Sub1.

Why the other options are wrong

  • A. Moving Sub1 between management groups changes where it sits in the hierarchy but grants Admin1 no permission over it.
  • B. Assigning that role on Sub1 requires someone who already has role-assignment rights there, and User1 is the only owner. This is the problem, not the fix.
  • C. Security Administrator is a Microsoft Entra role. It carries no Azure RBAC write permission over subscriptions.

See all 10 free questions Get the full pack, US$39

121 practice questions for Microsoft Cloud and AI Security Engineer (SC-500), with full explanations.

Every question comes with the correct answer, a full explanation, and a note on why each wrong option is wrong. Work through the answered copy first, then the questions-only PDF under timed conditions.

  • 121 questions mapped to the SC-500 exam objectives, across all four domains
  • Answers and explanations for every question, including why each wrong option is wrong
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A failed SC-500 attempt costs US$165 in the US, plus the weeks it takes to get ready again. This pack is US$39, paid once, and refunded if you fail.

Try 10 questions free before you buy.

Last updated September 2026 · 121 questions

What makes the SC-500 hard

Microsoft retired AZ-500, the Azure Security Engineer Associate certification, along with its renewal assessments, on 31 August 2026. SC-500 is the current Microsoft security engineer exam, and Microsoft has not published a transition path: if you want the credential now, you sit SC-500.

Studying it as AZ-500 with an AI chapter bolted on is what catches people out. SC-500 carries a dedicated “Implement security for AI” section inside the Secure compute domain, naming Microsoft Entra Agent ID conditional access, blast radius analysis for Entra Agent ID in Defender XDR, real-time protection for Microsoft Copilot Studio agents, Purview DSPM for Copilot and AI app risk, AI Gateway in Azure API Management for Microsoft Foundry, agent guardrails in Foundry, Defender for AI Service in Defender for Cloud, and the Data and AI security dashboard. None of that existed on AZ-500.

The rest of the blueprint moved too. Azure Virtual Network Manager, Microsoft Entra Private Access, Defender EASM, and a full Microsoft Security Copilot section covering workspaces, roles, plugins and Security Store agents are all new or expanded. The classic AZ-500 material is still there, including PIM, conditional access, Key Vault, NSGs, Azure Firewall, private endpoints, Defender for Cloud and Sentinel, but it now shares the exam with everything above.

Because the exam is new, there is very little practice material in circulation. Microsoft’s own Practice Assessment for SC-500 is not currently available, which makes an independent question bank more useful than usual.

About the exam

SC-500 (Implementing End-to-End Security Controls for Cloud and AI Workloads) leads to Microsoft Certified: Cloud and AI Security Engineer Associate. It covers securing identity, storage, databases, networking and compute across Azure and hybrid environments, securing AI workloads, and managing posture with Defender for Cloud, Microsoft Sentinel and Security Copilot. Associate level, no prerequisites. Microsoft retired AZ-500 and the Azure Security Engineer Associate certification on 31 August 2026.

Exam domains

  • Manage identity, access, and governance: 20 to 25%
  • Secure storage, databases, and networking: 25 to 30%
  • Secure compute: 20 to 25%
  • Manage and monitor security posture: 20 to 25%

120 minutes, passing score 700 out of 1000, online proctored or test centre, currently offered in English, renews annually for free. US$165 in the US, priced in local currency elsewhere.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the Microsoft SC-500 pack?

121 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Straight away. The full PDF and a questions-only copy are emailed to you the moment your payment goes through, and the same links are on your order page.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.