EnglishDeutschFrançaisEspañolPortuguês

Microsoft · SC-500 · Associate

Microsoft Cloud and AI Security Engineer Associate (SC-500) — Practice Questions and Mock Exam

Prepare for SC-500 with original practice questions and clear answer explanations. Ask Alex, your AI tutor, when you need more detail, use your results to identify topics to review, and practice your pacing with timed mock exams.

50Mock exam questions
120minTime limit
700/ 1000Passing score

Checked against Microsoft · August 2026 · Current exam version

About the exam

The Microsoft Certified: Cloud and AI Security Engineer Associate certification (Exam SC-500 — Implementing End-to-End Security Controls for Cloud and AI Workloads) validates the ability to design, implement, and manage security controls across Azure, hybrid, and AI-enabled environments, protecting identities, data, applications, and infrastructure. It covers identity, access, and governance; storage, database, and networking security; compute security; and security posture management, drawing on Defender for Cloud and Microsoft Sentinel telemetry. SC-500 succeeds AZ-500, which retires on 31 August 2026, and adds a dedicated focus on securing AI workloads (Copilot, Copilot Studio, Microsoft Entra Agent ID, Azure AI Foundry, and Defender for AI) plus Microsoft Security Copilot.

This associate-level certification is designed for security engineers whose role spans identity, network, application, data, and compute, including the platforms and infrastructure that AI workloads run on. Candidates should have practical experience administering Azure and hybrid environments across compute, network, and storage, along with familiarity with Microsoft Entra ID and Microsoft 365 administration.

Try five SC-500 questions

Try five practice questions from the app’s current Microsoft Certified: Cloud and AI Security Engineer Associate question bank, with answers and explanations.

Secure storage, databases, and networking2 / 5

In Transparent Data Encryption (TDE) with a customer-managed key for Azure SQL, what does the customer-managed key (the TDE protector) actually encrypt?

AlexFull explanation from Alex

TDE uses a two-tier key hierarchy for encryption at rest. The DEK performs the symmetric encryption of database files, and the TDE protector encrypts the DEK. In service-managed TDE, Microsoft controls the protector; in customer-managed (BYOK) TDE, the customer controls the protector in Key Vault or Managed HSM, enabling separation of duties and the ability to revoke access to render the database inaccessible. Switching from service-managed to customer-managed only re-encrypts the DEK, so there is no downtime or re-encryption of the database files.

Sourcelearn.microsoft.com

400 practice questions

The Pass-IT question pool gives you material to practice for SC-500. A Pass-IT mock exam uses 50 questions and a 120-minute time limit; these are practice settings.

Pool details: SC-500

Exam details checked against MicrosoftAugust 28, 2026

date of the last check against the official Microsoft source

Passing score700 / 1,000

as published by Microsoft

Objectives in the guide99 objectives listed in the official guide

across 4 domains in the official exam guide

Pool size400 questions

= The pool size is equivalent to 8 sets of 50 questions; this does not mean that each mock exam uses a separate set.

Blueprint domains4 domains in the exam blueprint

Manage identity, access, and governance 96 · Secure storage, databases, and networking 113 · Secure compute 99 · Manage and monitor security posture 92

Recorded as checked against sources400 of 400

questions recorded as having their answer, options, and explanation checked against official Microsoft documentation

What's on the exam

The four domains sit close in weight, 20% to 30% apiece, with storage, database, and network security carrying the largest share. That domain covers storage-account firewalls and Defender for Storage, Azure SQL auditing and platform security, and the network controls (NSGs, ASGs, private endpoints, JIT access, Bastion) that keep resources reachable only from where they should be.

Securing compute pulls double duty: traditional workload protection for VMs, containers, and Key Vault sits alongside a newer set of controls for AI workloads (Microsoft Entra Agent ID, Copilot Studio, Purview DSPM for AI, Defender for AI) that didn't exist on AZ-500. Identity, access, and governance and posture management round out the blueprint at roughly a fifth each, covering PIM, Conditional Access, and Defender for Cloud's secure score and multicloud connectors.

Exam blueprint: SC-500

Manage identity, access, and governance20–25%

Secure access to resources by using Microsoft Entra ID (PIM, Conditional Access, MFA/passwordless, app registrations and enterprise apps, OAuth consent, managed identities). Secure secrets and keys with Azure Key Vault (deployment, access, firewall, keys/secrets/certificates, Defender for Key Vault, secret scanning with Defender CSPM). Implement governance for security and regulatory compliance (Azure Policy, Defender for Cloud regulatory compliance and security standards, resource locks, Azure and Entra RBAC role assignments and custom roles, overprivileged-access remediation, Azure Backup protection, infrastructure as code).

≈ 14 h
Secure storage, databases, and networking25–30%

Implement security for storage accounts (storage firewall rules, Defender for Storage, access policies). Implement security for databases (Azure SQL platform-level security, auditing for Azure SQL Database and Managed Instance, Defender for Databases). Implement security for Azure network services (NSGs and ASGs, Azure Virtual Network Manager, Virtual WAN, VPN, Microsoft Entra Private Access, private endpoints and Private Link, Azure Firewall, Network Watcher effective security rules).

≈ 17 h
Secure compute20–25%

Implement security for AI (SharePoint data overexposure, Purview DSPM for AI risks in Microsoft Copilot and AI apps, Copilot Studio real-time protection, Conditional Access and blast-radius analysis for Microsoft Entra Agent ID, AI Gateway in Azure API Management for Microsoft Foundry, Defender for AI Service, Foundry agent guardrails, Data and AI security dashboard). Implement security for servers and VMs (disk encryption, Azure Bastion, JIT VM access, Azure Arc, Defender for Servers with vulnerability scanning/EDR/agentless scanning, secure boot/vTPM/integrity monitoring, Azure Machine Configuration). Implement security for application platform services (Defender for Containers, AKS, Azure Container Registry/Instances/Apps, Azure Functions, Logic Apps, App Service, Azure Web Application Firewall, API Management back-end protection).

≈ 14 h
Manage and monitor security posture20–25%

Manage security posture with Microsoft Defender for Cloud (Defender CSPM, security-framework compliance, workload protection plans, multicloud connectors for AWS and GCP, Defender Vulnerability Management, Defender External Attack Surface Management). Implement activity and event collection in Microsoft Sentinel (workspaces and roles, content hub, data connectors, syslog/CEF, Windows Security events via data collection rules and WEF, custom log tables, automation rules and playbooks, data retention, Purview Audit queries in Defender XDR). Implement Microsoft Security Copilot (workspaces, permissions and roles, plugins, Microsoft and Security Store agents).

≈ 14 h

Exam format and question types

SC-500 draws 40–60 questions from a pool spanning four skill areas: identity, access, and governance; storage, database, and network security; compute security, including AI workloads; and security-posture management. The 120-minute exam mixes multiple choice, build list, drag-and-drop, hot area, active screen, and case-study items, matching what Microsoft demonstrates in its official exam sandbox. Most items test generally available features, though frequently used preview capabilities can appear too.

Question types: SC-500

Multiple Choice44%

Select the single answer that best meets the question’s requirements.

Multiple Response20%

Select multiple answers. Follow the question’s instructions on how many to choose.

Dropdown12%

Choose options from dropdown menus to complete a statement or configuration.

Ordering8%

Arrange the steps in the sequence needed to complete the process.

Drag & Drop8%

Move items into the slots, groups, or sequence specified by the task.

True / False8%

Decide whether a statement is true or false, paying attention to its conditions and wording.

See Microsoft for official question-format information. The shares shown describe the Pass-IT practice pool; they do not establish the proportions on the official exam.

Preparing for SC-500

SC-500 runs through Pearson VUE, online with a remote proctor or at an authorized testing center, and is offered in English only. Certification holds for one year, and Microsoft opens a free, unproctored renewal assessment on Learn starting six months before it expires — no need to retake the full exam.

Preparation and logistics: SC-500

Preparation

Illustrative study time35–90 h

illustrative planning range: 35 h with relevant experience to 90 h when starting out; your needs may fall outside this range

LevelAssociate

Taking and maintaining the certification

DeliveryPearson VUE online proctored or at an authorized testing center
Retake policy24-hour wait after the first attempt, 14 days between subsequent attempts, maximum 5 attempts per 12-month period
Certification validity1 year

Valid for one year. Renew for free by passing an online, unproctored renewal assessment on Microsoft Learn during the six months before the certification expires; no need to retake the full proctored exam.

Common pitfalls

Topics to review: SC-500

  1. 01CSPM vs workload protection

    Defender CSPM covers posture, recommendations, and secure score; workload protection plans (Defender for Servers/Storage/Databases/Containers/Key Vault/AI) provide threat detection. They are enabled and priced separately.

  2. 02NSG vs ASG

    NSGs allow/deny traffic with security rules; ASGs are logical groupings of NICs/VMs you reference inside NSG rules to avoid hard-coded IPs. An ASG does not itself filter traffic.

  3. 03Private endpoint vs service endpoint

    A private endpoint (Private Link) assigns a PaaS resource a private IP inside your VNet; a service endpoint keeps the public endpoint but restricts it to specified subnets. Only private endpoints remove the resource’s public exposure.

  4. 04JIT vs Bastion

    Just-in-time VM access opens management ports only on request for a limited time; Azure Bastion brokers RDP/SSH from the portal with no public IP on the VM. They are complementary, not interchangeable.

  5. 05Entra Agent ID and AI security

    Securing AI agents uses Microsoft Entra Agent ID with Conditional Access, blast-radius analysis in Defender XDR, Purview DSPM for AI, real-time guardrails for Copilot Studio agents, and Defender for AI — a newly added and heavily weighted area versus AZ-500.

  6. 06Sentinel data collection

    Match the mechanism to the source: native data connectors for Azure/first-party sources, syslog/CEF for network appliances, and data collection rules (with Windows Event Forwarding) for Windows Security events.

Frequently asked questions

How long is the Microsoft Certified: Cloud and AI Security Engineer Associate exam?

The SC-500 exam has 50 questions and a 120-minute time limit.

What is the passing score for Microsoft Certified: Cloud and AI Security Engineer Associate?

The passing score for the SC-500 exam is 700 / 1000.

Which pitfalls should I review when preparing for Microsoft Certified: Cloud and AI Security Engineer Associate?

Topics to review include CSPM vs workload protection, NSG vs ASG, Private endpoint vs service endpoint, JIT vs Bastion, Entra Agent ID and AI security, Sentinel data collection. Work through examples to check that you understand the distinctions and can explain your answer.

Is SC-500 the exam that replaced AZ-500?

Yes. AZ-500 retires at the end of August 2026 and our catalog records SC-500 as its successor. The scope widened rather than moved across: SC-500 covers identity and governance, storage, database and network security, compute security and posture management, with AI security folded in. Our guide covers whether to sit AZ-500 before it goes or move straight to SC-500. Read the AZ-500 to SC-500 guide

How is SC-500 weighted?

Securing storage, databases and networking is the largest area at 29%, with securing compute and managing and monitoring security posture at 24% each and identity, access and governance at 23%. The four areas are close enough that none can be skipped. Posture management being a quarter of the exam is the clearest signal of how the role has changed.

How often do you have to renew SC-500?

Once a year. Renewal is a free unproctored assessment on Microsoft Learn taken during the six months before expiry, not a repeat of the proctored exam. Passing it extends the certification by another year.

Do you need AZ-500 or SC-300 before SC-500?

No. Microsoft records no prerequisite, and AZ-500 is retiring rather than acting as a stepping stone. The catalog budget is around 60 hours, which is higher than most Microsoft associate exams because the scope spans identity, network, compute and posture.

What happens if you fail SC-500?

A second attempt is possible after 24 hours, with 14 days between later attempts and a limit of five in any 12-month period. The exam is new, so preparation aimed at AZ-500 objectives will leave gaps.

One certification, 12 months

Practice for SC-500

Focus your practice on one certification, or choose Pro to practice across all certifications.

Start a free practice sessionTry the first 20 questions without a card to see whether the practice suits you.

For eligible purchases: money-back guarantee if you fail your exam.

View guarantee terms →