dc dotCreds
Microsoft SC-500 Practice Test

Microsoft SC-500 Practice Test

Start today’s free 10-question Microsoft SC-500 set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 22, 2026, 7:44 PM CDT

Go Pro - One Time Unlock

Unlock the full SC-500 bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 Microsoft SC-500 questions

Use this Microsoft SC-500 practice test to review Microsoft SC-500. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective Create custom log tables and transformations Manage and monitor security posture (20%-25%)

A custom application sends JSON telemetry to Log Analytics. Security wants to normalize a field, discard debug records, and store the final schema in a custom table before Sentinel queries it. Which Azure Monitor construct performs the transformation?

Concept tested:
Question 2 of 10
Objective Implement MFA and passwordless authentication Manage identity, access, and governance (20%-25%)

An organization is migrating from legacy per-user MFA settings to a centrally governed model. Administrators need to enable passkeys for a pilot group without enabling the method tenant-wide, and the same control plane must later support broader rollout. Where should the method be scoped?

Concept tested:
Question 3 of 10
Objective Prioritize security posture with Defender CSPM Manage and monitor security posture (20%-25%)

A security manager is optimizing remediation work and wants to avoid chasing hundreds of low-impact findings. Which Defender for Cloud capability best supports sorting recommendations using environment context rather than raw finding count?

Concept tested:
Question 4 of 10
Objective Discover exposed secrets with Defender CSPM Manage identity, access, and governance (20%-25%)

A code scan finds a production database password committed six months ago. The password was later removed from the current branch, but the credential remains valid. Which remediation addresses the security exposure rather than only the code finding?

Concept tested:
Question 5 of 10
Objective Protect containers with Microsoft Defender for Containers Secure compute resources (20%-25%)

An organization wants Defender for Cloud to assess supported ACR images for vulnerabilities, surface AKS security recommendations, and generate supported runtime detections from Kubernetes activity. The team already has Defender CSPM enabled but no container workload-protection plan. What must be added?

Concept tested:
Question 6 of 10
Objective Protect web applications with WAF Secure compute resources (20%-25%)

A new Azure Front Door WAF policy is expected to have false positives because the application uses unusual request patterns. Security wants to collect matches and tune exclusions before the policy blocks production requests. Which rollout is best?

Concept tested:
Question 7 of 10
Objective Protect databases with Microsoft Defender for Cloud Secure storage, databases, and networking (25%-30%)

A security team enables Defender for Databases expecting protection only for one Azure SQL Database. The plan configuration indicates broader database workload coverage. What should the team validate before assuming cost and scope are limited to that single database?

Concept tested:
Question 8 of 10
Objective Secure secrets and keys with Azure Key Vault Manage identity, access, and governance (20%-25%)

An application team asks for Contributor on a Key Vault because their app must rotate a certificate stored in the vault. Security wants the app to manage only certificates, not change vault networking or read unrelated secrets. What is the best design?

Concept tested:
Question 9 of 10
Objective Protect AI agents with Microsoft Defender Secure compute resources (20%-25%)

A cloud AI agent triggers a dangerous tool action. A custom real-time protection rule blocks the action. Hunters want to query the recorded behavior to understand the agent, user, and tool involved. Where should they look for the behavior telemetry described by the protection feature?

Concept tested:
Question 10 of 10
Objective Troubleshoot network security with Network Watcher Secure storage, databases, and networking (25%-30%)

A VM NIC is affected by a subnet NSG, a NIC NSG, and Azure Virtual Network Manager security admin rules. A connection is unexpectedly denied. Which Network Watcher view is best for seeing the combined rules that effectively apply to that NIC?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
SC-500 Pro $4.99 one-time

Best if you only need this one certification.

50 Exam Practice Test $1.99 one-time

A 50-question SC-500 PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

Microsoft Access $6.99/month

Unlock Microsoft, Azure, Power Platform, Copilot, and AI practice exams.

Why it fitsUnlock Microsoft, Azure, Power Platform, Copilot, and AI practice exams, Includes MS-700 Managing Microsoft Teams, Includes current and future Microsoft practice banks on dotCreds, Best for learners taking more than one Microsoft exam, PDF downloads sold separately where available

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full SC-500 bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily SC-500 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily Microsoft SC-500 set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 A custom application sends JSON telemetry to Log Analytics. Security wants to normalize a field, discard debug records, and store the final schema in a custom table before Sentinel queries it. Which Azure Monitor construct performs the transformation?

Answer choices

  1. A. Use a Sentinel automation rule to normalize the raw JSON after an incident has already been created from the data.
  2. B. Use a DCR transformation to map fields, filter debug records, and route the normalized records into the target custom table.
  3. C. Use an Azure Policy initiative to rewrite the incoming JSON schema before the records reach the Log Analytics ingestion endpoint.
  4. D. Use an NSG application security group to classify telemetry records and discard debug events before they enter the workspace.

Correct answer

Use a DCR transformation to map fields, filter debug records, and route the normalized records into the target custom table.

Data collection rules can transform and filter incoming records before they are stored in custom Log Analytics tables.

Wrong-answer review

  • A. Use a Sentinel automation rule to normalize the raw JSON after an incident has already been created from the data.: Automation rules operate on incidents and related SOC workflow; they are not ingestion-time log transformation mechanisms.
  • C. Use an Azure Policy initiative to rewrite the incoming JSON schema before the records reach the Log Analytics ingestion endpoint.: Azure Policy governs Azure resource configuration; it does not transform individual log records during ingestion.
  • D. Use an NSG application security group to classify telemetry records and discard debug events before they enter the workspace.: ASGs group network interfaces for NSG rules; they do not classify or transform log payloads.

Extra learning features

Why candidates miss this

The incorrect choice of ‘Use a Sentinel automation rule to normalize the raw JSON after an incident has already been created from the data.’ is tempting because automation rules are a common tool in Sentinel. However, automation rules operate on incidents and related SOC workflow; they are not ingestion-time log transformation mechanisms. Likely wrong answer: Use a Sentinel automation rule to normalize the raw JSON after an incident has already been created from the data. Review focus: Create a custom table in Azure Monitor Logs

Why this matters

Failure to correctly transform telemetry data before storage in Log Analytics tables can lead to inaccurate incident investigations and delayed response times. This results in a prolonged security incident, increased potential damage, and ultimately, a compromised system. The correct transformation ensures data integrity and efficient analysis.

Objective/domain: Manage and monitor security posture (20%-25%)

Source: Create a custom table in Azure Monitor Logs

Question 2 An organization is migrating from legacy per-user MFA settings to a centrally governed model. Administrators need to enable passkeys for a pilot group without enabling the method tenant-wide, and the same control plane must later support broader rollout. Where should the method be scoped?

Answer choices

  1. A. Use a PIM role activation setting to enable passkeys during sign-in.
  2. B. Create a Key Vault access policy that contains the pilot users.
  3. C. Target the pilot group with the passkey method in the Entra authentication methods policy.
  4. D. Enable Security Defaults only for the pilot group.

Correct answer

Target the pilot group with the passkey method in the Entra authentication methods policy.

Objective/domain: Manage identity, access, and governance (20%-25%)

Source: Microsoft Entra authentication overview

Question 3 A security manager is optimizing remediation work and wants to avoid chasing hundreds of low-impact findings. Which Defender for Cloud capability best supports sorting recommendations using environment context rather than raw finding count?

Answer choices

  1. A. Use only the number of recommendations per resource.
  2. B. Disable low-severity recommendations globally.
  3. C. Sort resources alphabetically in Azure Resource Graph.
  4. D. Use Defender CSPM risk prioritization and contextual recommendation insights.

Correct answer

Use Defender CSPM risk prioritization and contextual recommendation insights.

Objective/domain: Manage and monitor security posture (20%-25%)

Source: Risk prioritization in Microsoft Defender for Cloud

Question 4 A code scan finds a production database password committed six months ago. The password was later removed from the current branch, but the credential remains valid. Which remediation addresses the security exposure rather than only the code finding?

Answer choices

  1. A. Move the plaintext password into a different repository directory.
  2. B. Add an NSG rule allowing only the developer subnet.
  3. C. Mark the Defender recommendation exempt because the current branch no longer contains the password.
  4. D. Rotate or revoke the credential and remove it from reachable code/history.

Correct answer

Rotate or revoke the credential and remove it from reachable code/history.

Objective/domain: Manage identity, access, and governance (20%-25%)

Source: Secrets scanning in Microsoft Defender for Cloud

Question 5 An organization wants Defender for Cloud to assess supported ACR images for vulnerabilities, surface AKS security recommendations, and generate supported runtime detections from Kubernetes activity. The team already has Defender CSPM enabled but no container workload-protection plan. What must be added?

Answer choices

  1. A. Enable Microsoft Defender for Containers with the required cluster and registry coverage/components for the supported environment.
  2. B. Enable Defender CSPM only, because posture-management enablement automatically provides all container runtime detections and registry protection.
  3. C. Enable Defender for Servers on AKS worker nodes and treat server-plan coverage as equivalent to the container workload-protection plan.
  4. D. Enable Defender for Storage on the container registry because registry images are stored as blob objects under the service.

Correct answer

Enable Microsoft Defender for Containers with the required cluster and registry coverage/components for the supported environment.

Objective/domain: Secure compute resources (20%-25%)

Source: Defender for Containers in Azure overview

Question 6 A new Azure Front Door WAF policy is expected to have false positives because the application uses unusual request patterns. Security wants to collect matches and tune exclusions before the policy blocks production requests. Which rollout is best?

Answer choices

  1. A. Put the WAF policy in ReadOnly mode.
  2. B. Use an NSG instead because NSGs understand HTTP payload attacks better than WAF.
  3. C. Start in Prevention and disable logging so users are not affected by log overhead.
  4. D. Start WAF in Detection, tune from logs, then move to Prevention.

Correct answer

Start WAF in Detection, tune from logs, then move to Prevention.

Objective/domain: Secure compute resources (20%-25%)

Source: Azure Web Application Firewall on Azure Front Door best practices

Question 7 A security team enables Defender for Databases expecting protection only for one Azure SQL Database. The plan configuration indicates broader database workload coverage. What should the team validate before assuming cost and scope are limited to that single database?

Answer choices

  1. A. Review environment settings and the Defender for Databases plan's actual subscription coverage.
  2. B. Review only the Azure SQL firewall because Defender billing is determined by firewall rules.
  3. C. Install Defender for Endpoint on the Azure SQL logical server to constrain coverage.
  4. D. Create an NSG around the SQL logical server to select the protected database.

Correct answer

Review environment settings and the Defender for Databases plan's actual subscription coverage.

Objective/domain: Secure storage, databases, and networking (25%-30%)

Source: Enable the Defender for Databases plan

Question 8 An application team asks for Contributor on a Key Vault because their app must rotate a certificate stored in the vault. Security wants the app to manage only certificates, not change vault networking or read unrelated secrets. What is the best design?

Answer choices

  1. A. Assign a Key Vault certificate data-plane role at the narrowest supported scope.
  2. B. Grant Contributor plus deny assignments for secrets.
  3. C. Store the certificate in an App Service setting so Key Vault authorization is unnecessary.
  4. D. Grant Key Vault Administrator because all vault data uses one authorization plane.

Correct answer

Assign a Key Vault certificate data-plane role at the narrowest supported scope.

Objective/domain: Manage identity, access, and governance (20%-25%)

Source: Azure Key Vault RBAC guide

Question 9 A cloud AI agent triggers a dangerous tool action. A custom real-time protection rule blocks the action. Hunters want to query the recorded behavior to understand the agent, user, and tool involved. Where should they look for the behavior telemetry described by the protection feature?

Answer choices

  1. A. Query Key Vault secret versions because every tool call creates a secret version.
  2. B. Query only the agent's NSG flow log because the tool action is represented as a packet deny.
  3. C. Query the Microsoft Defender behavior telemetry, including the BehaviorInfo table, for the recorded agent action context.
  4. D. Query Azure Policy compliance state because blocked tool calls are stored as policy assignments.

Correct answer

Query the Microsoft Defender behavior telemetry, including the BehaviorInfo table, for the recorded agent action context.

Objective/domain: Secure compute resources (20%-25%)

Source: Protect AI agents in real time using Microsoft Defender

Question 10 A VM NIC is affected by a subnet NSG, a NIC NSG, and Azure Virtual Network Manager security admin rules. A connection is unexpectedly denied. Which Network Watcher view is best for seeing the combined rules that effectively apply to that NIC?

Answer choices

  1. A. Use Azure Policy compliance because it calculates packet-level effective rules.
  2. B. Use Key Vault diagnostic settings.
  3. C. Use Connection Monitor only and infer the governing rule from latency.
  4. D. Use Effective security rules for the VM NIC.

Correct answer

Use Effective security rules for the VM NIC.

Objective/domain: Secure storage, databases, and networking (25%-30%)

Source: Effective security rules overview

Where to go after the daily web set

How are Microsoft SC-500 questions generated?

dotCreds builds Microsoft SC-500 practice questions from public exam objectives and Microsoft Learn and exam-objective references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start Microsoft SC-500 practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.