Azure Mastery

Microsoft Certification SC-500

SC-500: Predict your score. Know what to study next.

See your predicted score, follow a study plan based on your answers, and revisit topics you're starting to forget. It all runs on your device.

452 practice questions AI score prediction 100% offline
Download free iPhone & iPad · Free to start QR code — scan with your iPhone to open Azure Mastery on the App Store On your Mac?
Scan to install

SC-500 Practice Questions & Exam Prep — Microsoft Cloud and AI Security Engineer

Get exam-ready for SC-500 (Microsoft Cloud and AI Security Engineer) — the new exam succeeding AZ-500 — on iPhone or iPad. Azure Mastery uses on-device AI to predict your readiness score across all four SC-500 domains, build a personalised study plan from your weak spots, and surface topics you're forgetting. Core study stays on-device and works offline; optional sync uses your private iCloud account.

The exam

What is the SC-500 exam?

SC-500 is the Microsoft Certified: Cloud and AI Security Engineer Associate exam — the credential hiring managers expect when posting "Cloud Security Engineer", "Azure Security Specialist", or "Cloud and AI Security" roles. It's the direct successor to AZ-500 (Microsoft Azure Security Engineer), which retired on 31 August 2026.

SC-500 keeps the core Azure security-engineering content and broadens the role to cover securing cloud and AI workloads. It's a natural next step after AZ-104 and pairs with SC-900; Microsoft does not currently list SC-500 as an accepted prerequisite for the SC-100 Cybersecurity Architect Expert credential.

SC-500 is hands-on and operational. It covers:

Expect scenario questions that show you a config snippet or attack signal and ask what you'd do next.

Microsoft published the SC-500 skills outline for the May 2026 beta, with full training and exam expected from July 2026. Every question in Azure Mastery's SC-500 bank is mapped to that outline, including the new AI-security objectives alongside the AZ-500 carry-over content. Read the official outline at learn.microsoft.com.

Skills measured · 13 May 2026

SC-500 exam objectives

Four domains, with weights set by Microsoft's 13 May 2026 update. Every domain below lists Microsoft's own skill groups verbatim from the official skills outline, so you always know which domain you're being tested on and where your weak spots cluster.

Aura presents a visual map of identity, protection, detection, and governance skills.
Security skill map

Manage identity, access, and governancePublished weight 20–25%

110 exam-scoped practice questions in the app

Explore Identity topics
  • Secure access to resources by using Microsoft Entra ID
  • Secure secrets and keys by using Azure Key Vault
  • Implement governance to enforce security and regulatory compliance
  • Covers PIM's eligible-vs-active roles, Conditional Access session controls, and managed identities replacing stored secrets.
  • Governance often gets treated as separate from identity, but RBAC hygiene and policy enforcement sit in this same domain.
  • Prove a policy actually blocks what it claims — don't assume a policy existing means it's enforcing anything.

Secure storage, databases, and networkingPublished weight 25–30%

116 exam-scoped practice questions in the app

Explore Data & Network topics
  • Implement security for storage accounts
  • Implement security for databases
  • Implement security for Azure network services
  • The largest domain: Defender for Storage, Azure SQL auditing, and networking controls across NSGs, endpoints, and firewalls.
  • Candidates default to encryption-at-rest for storage questions when the scenario is really testing Defender threat protection.
  • Practise reading Azure Firewall and Network Watcher output to confirm a rule does what a scenario claims.

Secure computePublished weight 20–25%

113 exam-scoped practice questions in the app

Explore Compute topics
  • Implement security for AI
  • Implement security for servers and virtual machines (VMs)
  • Implement security for application platform services
  • Splits three ways: AI security with no AZ-500 equivalent, server hardening, and application-platform controls across hosting models.
  • Matching a control to its hosting model is the trap — a Container Apps control won't fix a Functions app.
  • New to this exam: Purview DSPM, Entra Agent ID, and Defender for AI Services guardrails need dedicated study.

Manage and monitor security posturePublished weight 20–25%

113 exam-scoped practice questions in the app

Explore Posture topics
  • Manage security posture by using Defender for Cloud
  • Implement activity and event collection in Microsoft Sentinel
  • Implement Microsoft Security Copilot
  • The operational half: proving Defender for Cloud and Sentinel controls actually work, beyond simply configuring them.
  • Candidates guess at Sentinel ingestion mechanics instead of matching a data source to its actual pipeline.
  • Practise picking the right ingestion path — connector, CEF, or a custom log table — for a named data source.

Common traps

Where SC-500 candidates slip

Five recurring misconceptions that trip up otherwise well-prepared SC-500 candidates, grounded in the current skills outline.

Treating SC-500 as AZ-500 with a new name

Candidates study only AZ-500 material and consistently underperform on SC-500's dedicated AI-security slice.

  • Purview DSPM, Entra Agent ID, and Foundry guardrails carry no AZ-500 equivalent, and the exam weights them accordingly.
  • Add AI-security topics to your plan even if you already hold AZ-500 — don't assume the overlap is complete.

Defender for Storage vs a storage firewall rule

Candidates mix up a network-perimeter control with a threat-detection control inside the same storage domain.

  • A firewall rule blocks traffic before authentication; Defender for Storage detects suspicious activity after access has already happened.
  • For a scenario describing an attack already underway, pick the detection answer, not the network-perimeter one.

Treating Entra Agent ID like a normal app registration

Candidates default to classic Conditional Access or PIM patterns for scenarios that actually describe an autonomous agent.

  • Entra Agent ID governs autonomous agents specifically, distinct from human sign-ins and conventional service principals.
  • Look for an agent chaining actions across systems as the cue to reach for Agent ID's own controls.

Defender CSPM vs the free foundational tier

Candidates assume the free foundational tier already covers attack-path analysis and multicloud governance.

  • Attack-path analysis and agentless scanning both sit behind the paid CSPM layer, not the free foundational tier.
  • Match multicloud coverage or governance-at-scale requirements to CSPM, not the free tier.

Assuming every Sentinel source lands the same way

Candidates pick the wrong ingestion mechanism or invent a custom table where a built-in one already exists.

  • Syslog, Windows events, and genuinely custom sources each need a different ingestion path, and mixing them up is the common miss.
  • Check for an existing built-in table like CommonSecurityLog before assuming a source needs a custom one.

Designed for SC-500

How Azure Mastery helps you pass SC-500

Exam-specific practice

  • 452 SC-500 practice questions aligned to the published skills outline.
  • Coverage leans hardest on securing storage, databases, and networking, the domain Microsoft weights up to 30%.
  • Practise reading Firewall and Network Watcher output to prove a security rule really does what it claims.

Predicted score

  • Exam IQ forecasts your SC-500 score on-device after roughly 30 questions, confidence range attached.
  • It flags whether data/network breadth or the newer AI-security topics are dragging that number down.
  • Compare all four domains to see which one is holding your predicted score back.

Adaptive study plan

  • Your plan leans hardest on storage, databases, and networking, the domain Microsoft weights up to 30%.
  • Miss a Defender-for-Storage or Sentinel-ingestion question and the next session surfaces that domain first.
  • Keep a topic solid for three sessions running and the plan shifts its focus to your next weak spot.

Knowledge decay

  • Forget the CSPM-vs-free-tier distinction early on and later posture questions get harder too.
  • The Today screen surfaces a decay warning so you can revisit a topic before it fades for good.
  • Fading topics come back into rotation on their own once you run a Focus Weak Spots session.

Exam rehearsal

  • Practise holding focus through a full 100-minute session, matching SC-500's real length.
  • Each rehearsal session weights all four domains the way Microsoft publishes them, using original questions.
  • Microsoft alone decides the live exam's interface and the order questions arrive in.

Answer Coach

  • Untangles SC-500's near-identical pairs: Defender for Storage vs a firewall rule, and Entra Agent ID vs a normal app registration.
  • Get a question wrong and Answer Coach names the exact scenario detail that should have driven your answer.
  • Supported devices can rephrase the note locally, always checked against the written explanation first.

Aura guidance

  • Aura adjusts its suggestions as your first week of SC-500 practice takes shape.
  • Each session wraps with a brief summary of progress, what to look at again, and your next step.

Private by design

  • Your SC-500 answer history, readiness gauge, and Answer Coach notes stay on your device by default.
  • No Azure Mastery account and no server ever processes your study data.
  • If you switch sync on, it travels only through your own private iCloud account.

6-week study plan

Suggested SC-500 study plan

Move from identity and governance to workload protection, AI security and operations. Use the final blocks of this six-week route for focused review and timed practice.

  1. Identity and access

    • Compare authentication methods, MFA and passwordless access.
    • Review Conditional Access locations, risk and sessions.
    • Practise PIM eligibility, activation and access reviews.
  2. Application identities and keys

    • Review enterprise apps, registrations and OAuth consent.
    • Use managed identities for Azure resources.
    • Configure Key Vault access, networking and protection.
  3. Governance

    • Review built-in and custom Azure Policy definitions.
    • Compare built-in and custom RBAC roles.
    • Remediate excessive permissions and apply resource locks.
  4. Compliance and recovery controls

    • Review compliance in Defender for Cloud.
    • Explore Azure Backup security.
    • Apply security controls through infrastructure as code.
  5. Storage and databases

    • Secure storage accounts, firewalls and access policies.
    • Review Defender for Storage.
    • Explore SQL security, auditing and Defender for Databases.
  6. Network security

    • Review NSGs, ASGs, Virtual Network Manager and Virtual WAN.
    • Compare VPN, Entra Private Access, Private Link and private endpoints.
    • Explore Azure Firewall and Network Watcher.
  7. Compute and app platforms

    • Review disk encryption, Bastion, JIT access, Arc and trusted launch controls.
    • Explore Defender for Servers and container-platform protection.
    • Review Functions, Logic Apps, App Service, WAF and API Management security.
  8. AI security

    • Review Purview DSPM for Copilot.
    • Explore Entra Agent ID controls and Defender XDR blast-radius analysis.
    • Review AI Gateway, Defender for AI and Foundry agent guardrails.
  9. Security posture

    • Review Defender CSPM, compliance and workload protection.
    • Connect AWS and GCP environments.
    • Explore vulnerability management and external attack-surface management.
  10. Sentinel and Security Copilot

    • Configure workspaces, roles and Content Hub solutions.
    • Review connectors, event collection and data collection rules.
    • Explore automation rules, playbooks and Security Copilot plugins or agents.
  11. Target weaker topics

    • Run Focus Weak Spots sessions.
    • Revisit storage, database and networking decisions.
    • Review explanations for missed scenarios.
  12. Timed rehearsal

    • Complete two 100-minute Exam Simulator sessions.
    • Review each run carefully.
    • Use the results to plan further study.

Inside the app

Nine interactive practice formats, on iPhone

Azure Mastery has nine interactive formats for exam practice. The examples below show original SC-500 practice questions in Azure Mastery on iPhone and iPad. The exam simulator uses timed sessions with the published domain weights. Microsoft's live interface and question mix may differ.

Which suffix identifies a custom log table that receives data through the Logs Ingestion API in a Microsoft Sentinel workspace?

  • _CEF
  • _CL
  • _SRCH
  • _RST

Multiple choice

An original SC-500 practice question with one correct answer. The app explains every option after you answer.

Exam-specific sample

Which two Recovery Services vault operations are mandatory Resource Guard protections when MUA is configured? (Choose two.)

  • Disable soft delete or other vault security features
  • Run a restore for a protected backup item
  • Stop backup while retaining the protected data
  • Remove MUA protection from the vault

Multi-select

An original SC-500 multi-select question. Select all the correct options to earn the mark.

All-or-nothing

Drag-and-drop

An original SC-500 ordering question you can answer by touch on iPhone and iPad.

Interactive item

Hotspot

An original SC-500 question with a visual prompt, designed for touch on iPhone and iPad.

Tap target

Case studies

An original SC-500 case study with several questions about the same requirements and environment.

Multi-question

Answer Coach

Answer Coach explains why the answer is correct and, where available, why each option is right or wrong. It helps you understand a mistake and remember the distinction. Read explanations after each question or at the end of a practice test. On supported devices, optional AI can reword a note on your device after checking it against the written guidance.

App exclusive

Frequently asked

SC-500 FAQs

Is SC-500 replacing AZ-500?

Yes. SC-500 (Cloud and AI Security Engineer) is the direct successor to AZ-500, which retired on 31 August 2026. It keeps AZ-500's core security-engineering content and adds securing cloud and AI workloads: Copilot, Entra Agent ID, Foundry, and Defender for AI. If you haven't started AZ-500, prepare for SC-500 instead.

How much does the SC-500 exam cost?

The SC-500 voucher is USD $165 in the United States, around £128 in the UK; regional pricing varies. Watch for free-voucher promotions around Microsoft Build or Microsoft Ignite. Renewal is free, but it's an annual Associate certification, so factor that into long-term cost planning.

Does the SC-500 certification expire?

Yes. Microsoft Associate certifications including SC-500 expire annually. Renewal is a free, short assessment on Microsoft Learn, available in the six-month window before expiry. Fundamentals certifications like SC-900 don't expire.

What is the SC-500 retake policy if I fail?

Each retake takes longer than the last, and every attempt requires its own voucher purchase.

  • First retake: after 24 hours.
  • Second and third retakes: a 14-day wait each.
  • Cap: five attempts per rolling 12 months.
How long should I study for SC-500?

Most candidates pass after four to eight weeks with some prior Azure and Entra experience; plan two to three months if cloud security is genuinely new. The exam expects hands-on knowledge of Defender for Cloud, Sentinel, Entra ID, and Key Vault. Azure Mastery's readiness gauge tells you when you're actually ready.

What prior experience does SC-500 assume?

SC-500 assumes hands-on Azure and hybrid administration — compute, network, storage — plus strong Entra ID familiarity. It isn't a from-scratch security course: you're expected to already operate the infrastructure you're securing. New to Azure administration? Work through AZ-104 or the free AZ-900 first.

SC-500 vs SC-200 — which next on the security track?

Different roles. SC-500 covers implementing security controls across identity, storage, networking, compute, and AI workloads. SC-200 covers running Defender XDR and Sentinel as a SOC analyst, focused on detection and incident response. Many Cybersecurity Architect candidates hold both.

Is Azure Mastery free for SC-500 prep?

The app is free to download and includes a free allowance of SC-500 questions so you can try every feature. The full bank of 452 SC-500 practice questions unlocks with a one-time exam-pack purchase, or you can unlock every exam in the catalogue with a subscription or a one-time lifetime upgrade.

Does SC-500 practice work offline?

Yes — every question, score, and readiness read happens on-device, so SC-500 prep keeps going without a connection. No account is needed, and nothing leaves your device unless you switch on private iCloud sync.

Is there an SC-500 practice test mode?

Yes. Timed practice sessions draw on original, blueprint-weighted SC-500 questions with published timing and the interactive formats this exam uses. Adaptive study and Focus Weak Spots then push you back toward the domains dragging your accuracy down.

Free study guides

Free guides that pair with SC-500

Where SC-500 fits

Certification paths that include SC-500

SC-500 is the cloud-and-AI security Associate cert — the successor to AZ-500 (retired 31 August 2026). It pairs with SC-900 on the way into security work. It can broaden your foundation before architecture work, but Microsoft currently lists SC-200, SC-300, or Azure Security Engineer Associate—not SC-500—as accepted prerequisites for the SC-100 credential.

Ready to pass SC-500?

Download Azure Mastery free. 452 SC-500 practice questions across all four domains, AI score prediction, full-length exam simulator, adaptive study plan. iPhone & iPad.

Download Azure Mastery — free iPhone & iPad · Free to start · No account required
SC-500 practice — free on the App Store Download