HOTSPOT You have a Microsoft Sentinel workspace named Workspace1. You hire a security consultant. You provide the consultant with a guest account named User1 in your Microsoft Entra tenant You need to enable User1 to assign incidents in Workspace1. Which roles should you assign to User1? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. 
Free SC-500 Practice Test Questions and Answers (2026)
HOTSPOT You need to configure the AKS1 and ID 1 managed identities to meet the technical requirements. The solution must follow the principle of least privilege. Which role should you assign to each identity? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
HOTSPOT You have a Microsoft Entra tenant that contains the users shown in the following table. 
HOTSPOT You have an Azure subscription named Sub1 that contains 50 virtual machines. Sub1 has Microsoft Defender for Cloud enabled. Sub1 contains an Azure key vault named KV1 and an Azure policy that enforces storing all secrets in KV1. Occasionally, the developers at your company store plaintext tokens and SSH private keys on the virtual machines. You need to configure Defender for Cloud to detect plaintext secrets on the virtual machines. The solution must minimize administrative changes to the virtual machines. How should you configure Defender for Cloud? To answer, select the appropriate options in the answer area NOTE: Each correct selection is worth one point.
DRAG DROP You have three internet-facing Azure App Service web apps named App1, App2, and App1 Each app uses built-in authentication. App2 hosts a backend API. Some corporate users can sign in to App2, even though they should NOT be able to use the API. You need to restrict App2 access to assigned Microsoft Entra users and groups. What should you configure for App2? To answer, drag the appropriate configurations to the correct methods. Each configuration may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.
DRAG DROP You have a Microsoft 365 subscription. You use Microsoft Entra Agent ID to manage an agent identity. You manage AI agents from the Microsoft 365 admin center. An autonomous agent named Agent1 runs without a signed-in user. The agent must access Microsoft Graph and read secrets from a single Azure key vault. You need to grant Agent 1 access to Microsoft Graph and Key Vault without requiring user interaction or consent at runtime. What should you do for the agent identity? To answer, drag the appropriate actions to the correct services. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.
DRAG DROP You have an Azure subscription named Sub1 that contains a virtual network named VNet1. VNet1 contains multiple virtual machines, including two virtual machines named VM1 and VM2. Sub1 is linked to a Microsoft Entra tenant named contoso.com. A partner company has an Azure subscription named Sub2 that contains a virtual network named VNet2. VNet2 contains a virtual machine named VM3. Sub2 is linked to a Microsoft Entra tenant named fabrikam.com. VM1 and VM2 contain data used by an application that runs on VM3. You need to ensure that VM3 can access VM1 and VM2. The solution must deny VM3 access to any other resources in Sub1. What should you configure on each virtual network? To answer, drag the components to the correct virtual networks. Each component may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.





