Microsoft Microsoft SC-500 PDF Microsoft Microsoft SC-500 PDF Questions Available Here at: https://www.certification-exam.com/en/dumps/microsoft-exam/sc-500-dumps/quiz.html Enrolling now you will get access to 16 questions in a unique set of Microsoft SC-500 Question 1 A user receives an email containing a URL that was considered safe during delivery but is later identified as malicious. The organization wants to block the user when the link is clicked. Which Microsoft Defender for Office 365 capability should be configured? Options: A. Safe Attachments dynamic analysis B. Safe Links time-of-click protection C. Anti-spam bulk complaint filtering D. Attack simulation training Answer: B Explanation: Safe Links can evaluate URLs at the time of clicking and block access if the destination is determined to be malicious after the message was delivered. Safe Attachments analyzes files, anti-spam filtering addresses unwanted mail characteristics, and attack simulation training is used for controlled phishing exercises. Question 2 A Microsoft Sentinel team wants every incident involving a suspicious IP address to trigger threat- intelligence enrichment and then post the results to a security channel. The process must run automatically when the incident is created. Which design best meets the requirement? Options: A. Create a workbook containing the enrichment steps and configure a KQL query to publish the results B. Create a playbook backed by a Logic App and invoke it through an incident-triggered Microsoft Microsoft SC-500 PDF https://www.certification-exam.com/ automation rule C. Create a scheduled KQL query rule that displays the enrichment results in a workbook D. Create a workbook parameter that calls the notification connector when an analyst opens the incident Answer: B Explanation: A playbook in Microsoft Sentinel is implemented with Azure Logic Apps and can automate actions such as threat-intelligence lookups and notifications. An automation rule can invoke the playbook when an incident is created. Workbooks are primarily for visualization, while KQL queries retrieve and analyze data rather than orchestrating multistep response actions. Question 3 A security team wants to prioritize posture improvements across several Azure subscriptions. They need a metric that reflects the relative security posture of the environment and changes as recommendations are remediated. Which Defender for Cloud capability best meets this requirement? Options: A. The Secure score, calculated from active security recommendations B. The Microsoft Defender for Cloud attack path inventory C. The regulatory compliance assessment, calculated from audit logs D. The workload protection alert queue, calculated from detected threats Answer: A Explanation: Defender for Cloud Secure score summarizes the security posture based on applicable security recommendations and changes as those recommendations are addressed. Attack paths, regulatory compliance assessments, and threat alerts provide related information but do not serve as the overall posture score in this scenario. Question 4 A security analyst notices an alert for a suspicious PowerShell process on a Windows device and needs to review the process's parent, child processes, file activity, and network connections in chronological order. Which Microsoft Defender for Endpoint capability is most appropriate for this investigation? Options: A. Advanced hunting B. Automated investigation and response Microsoft Microsoft SC-500 PDF https://www.certification-exam.com/ C. Device timeline D. Live response Answer: C Explanation: The device timeline presents a chronological view of events associated with a device, including process execution, file activity, and network connections. Advanced hunting is used to query telemetry across devices, live response provides an interactive remote investigation session, and automated investigation and response analyzes and remediates alerts without being primarily a timeline view. Question 5 A company needs documents containing confidential financial data to remain protected after they are downloaded from SharePoint. The protection must travel with the files and restrict access based on the permissions assigned to the label. Which Microsoft Purview capability should the company configure? Options: A. A retention label that automatically deletes the documents after a specified period B. A sensitivity label with encryption and access-control settings C. A data loss prevention policy that blocks every SharePoint download D. A retention policy that moves the documents to an archive mailbox Answer: B Explanation: Sensitivity labels can apply protection such as encryption and usage rights that remain associated with the content after it is downloaded or shared. Retention labels and retention policies govern how long content is retained or disposed of, while a DLP policy can restrict actions but does not provide the same persistent file-level protection. Question 6 A company allows employees to access an internal payroll application from managed devices without additional verification because the devices are connected to the corporate network. Which Zero Trust change best addresses this design? Options: A. Require authentication and authorization for each access request based on identity, device state, and applicable policy B. Allow access automatically when the device is connected through the corporate network C. Move the payroll application to a separate internal subnet and trust that subnet Microsoft Microsoft SC-500 PDF https://www.certification-exam.com/ D. Require users to connect through the corporate VPN before permitting access Answer: A Explanation: Zero Trust assumes that network location does not establish trust. Each request should be evaluated using signals such as user identity, device health, and policy, with access granted according to the current risk and required permissions. A VPN or network segmentation can improve security but does not replace per- request verification. Question 7 A web application hosted in Azure App Service must access an Azure Storage account without exposing the storage service through its public endpoint. Access must be restricted to the virtual network used by the application. Which configuration best meets these requirements? Options: A. Create a private endpoint for the storage account and link its private DNS zone to the application virtual network B. Enable a service endpoint for Storage on the application subnet and allow the storage account's public endpoint C. Add the App Service outbound IP addresses to the storage account firewall and retain public network access D. Deploy a network security group on the application subnet and allow outbound traffic to the storage account's public IP addresses Answer: A Explanation: A private endpoint assigns the storage account a private IP address in the virtual network, allowing access without using the public endpoint. A linked private DNS zone ensures the storage account name resolves to that private address. A service endpoint still uses the Azure service's public endpoint, and firewall rules or network security groups do not by themselves remove public exposure. Question 8 A security analyst has a hypothesis that recently observed PowerShell activity may be related to a known threat actor. The analyst wants to run a KQL query across historical data, inspect the results, and refine the investigation without automatically creating incidents. Which Microsoft Sentinel capability best fits this task? Options: A. An automation rule B. A hunting query Microsoft Microsoft SC-500 PDF https://www.certification-exam.com/ C. An analytics rule D. A workbook Answer: B Explanation: A hunting query is designed for proactive, analyst-driven investigation of collected data and allows the analyst to test and refine a hypothesis. An analytics rule is intended to detect conditions automatically and can generate incidents, while automation rules respond to existing alerts or incidents and workbooks primarily visualize data. Question 9 During a quarterly risk review, an organization confirms that a new access control has reduced the likelihood of unauthorized access but cannot eliminate the risk. The business process owner has not yet decided whether to accept the remaining exposure. Which governance action is appropriate next? Options: A. Close the risk because the control has been implemented B. Transfer responsibility for the remaining exposure to the security team C. Record the residual risk and obtain a risk-owner decision to accept or treat it D. Rewrite the security policy so that the remaining exposure is no longer classified as a risk Answer: C Explanation: A control can reduce risk without eliminating it, leaving residual risk. The residual risk should be documented, and the accountable risk owner must decide whether to accept it or implement additional treatment. Implementing a control does not automatically close the risk or transfer business accountability to the security team. Question 10 Several alerts involving the same user account, endpoint, and suspicious process appear in Microsoft Defender XDR as one incident. An analyst wants to understand why the alerts were combined and investigate the attack as a single sequence. Which capability explains this behavior? Options: A. Cross-domain correlation groups related alerts and entities into a unified incident B. Automated investigation removes duplicate alerts before analysts review them C. Advanced hunting converts every matching event into a separate incident Microsoft Microsoft SC-500 PDF https://www.certification-exam.com/ D. The Action center combines alerts only after a remediation action is approved Answer: A Explanation: Microsoft Defender XDR correlates related alerts, entities, and activities across its protection domains into an incident. This gives analysts a unified investigation context instead of requiring them to investigate each alert independently. Automated investigation and the Action center support response activities but do not explain the initial incident grouping. Would you like to see more? Don't miss our Microsoft SC- 500 PDF file at: https://www.certification-exam.com/en/pdf/microsoft-pdf/sc-500-pdf/ Microsoft Microsoft SC-500 PDF https://www.certification-exam.com/