SC-500: Predict your score.
Know what to study next.
See your predicted score, follow a study plan based on your answers, and revisit topics you're starting to forget. It all runs on your device.
452 practice questions
AI score prediction
100% offline
Download free
iPhone & iPad · Free to startOn your Mac? Scan to install
SC-500Microsoft Cloud and AI Security Engineer
SC-500 · 30 days left ›
PREDICTED786 ±37✓ Exam Ready · 87% confidence
SC-500 Practice Questions & Exam Prep — Microsoft Cloud and AI Security Engineer
Get exam-ready for SC-500 (Microsoft Cloud and AI Security Engineer) — the new exam succeeding AZ-500 — on iPhone or iPad. Azure Mastery uses on-device AI to predict your readiness score across all four SC-500 domains, build a personalised study plan from your weak spots, and surface topics you're forgetting. Core study stays on-device and works offline; optional sync uses your private iCloud account.
The exam
What is the SC-500 exam?
SC-500 is the Microsoft Certified: Cloud and AI Security Engineer Associate exam — the credential hiring managers expect when posting "Cloud Security Engineer", "Azure Security Specialist", or "Cloud and AI Security" roles. It's the direct successor to AZ-500 (Microsoft Azure Security Engineer), which retired on 31 August 2026.
SC-500 keeps the core Azure security-engineering content and broadens the role to cover securing cloud and AI workloads. It's a natural next step after AZ-104 and pairs with SC-900; Microsoft does not currently list SC-500 as an accepted prerequisite for the SC-100 Cybersecurity Architect Expert credential.
SC-500 is hands-on and operational. It covers:
Manage identity, access, and governance — Microsoft Entra ID, Conditional Access, PIM, managed identities, Azure Key Vault, Azure Policy and RBAC
Secure storage, databases, and networking — Defender for Storage, Azure SQL security, NSGs, Azure Firewall, Private Link
Secure compute and AI workloads — disk encryption, Defender for Servers and Containers, plus securing AI with Microsoft Entra Agent ID, Defender for AI, AI Gateway in API Management for Foundry, and Purview DSPM for Copilot
Manage and monitor security posture with Microsoft Defender for Cloud, Microsoft Sentinel, and Microsoft Security Copilot
Expect scenario questions that show you a config snippet or attack signal and ask what you'd do next.
Microsoft published the SC-500 skills outline for the May 2026 beta, with full training and exam expected from July 2026. Every question in Azure Mastery's SC-500 bank is mapped to that outline, including the new AI-security objectives alongside the AZ-500 carry-over content. Read the official outline at learn.microsoft.com.
Questions40–60 questions, mixed formats
Duration100 minutes (120 min seat)
Pass score700 / 1000
CostUSD $165 (≈ £128 UK)
ValidityRenew annually (Associate)
FormatOnline or test centre
Skills measured · 13 May 2026
SC-500 exam objectives
Four domains, with weights set by Microsoft's 13 May 2026 update. Every domain below lists Microsoft's own skill groups verbatim from the official skills outline, so you always know which domain you're being tested on and where your weak spots cluster.
Security skill mapIdentityProtectDetectGovern
Manage identity, access, and governancePublished weight 20–25%
110 exam-scoped practice questions in the app
Explore Identity topics
Secure access to resources by using Microsoft Entra ID
Secure secrets and keys by using Azure Key Vault
Implement governance to enforce security and regulatory compliance
Governance often gets treated as separate from identity, but RBAC hygiene and policy enforcement sit in this same domain.
Prove a policy actually blocks what it claims — don't assume a policy existing means it's enforcing anything.
Secure storage, databases, and networkingPublished weight 25–30%
116 exam-scoped practice questions in the app
Explore Data & Network topics
Implement security for storage accounts
Implement security for databases
Implement security for Azure network services
The largest domain: Defender for Storage, Azure SQL auditing, and networking controls across NSGs, endpoints, and firewalls.
Candidates default to encryption-at-rest for storage questions when the scenario is really testing Defender threat protection.
Practise reading Azure Firewall and Network Watcher output to confirm a rule does what a scenario claims.
Secure computePublished weight 20–25%
113 exam-scoped practice questions in the app
Explore Compute topics
Implement security for AI
Implement security for servers and virtual machines (VMs)
Implement security for application platform services
Splits three ways: AI security with no AZ-500 equivalent, server hardening, and application-platform controls across hosting models.
Matching a control to its hosting model is the trap — a Container Apps control won't fix a Functions app.
New to this exam: Purview DSPM, Entra Agent ID, and Defender for AI Services guardrails need dedicated study.
Manage and monitor security posturePublished weight 20–25%
113 exam-scoped practice questions in the app
Explore Posture topics
Manage security posture by using Defender for Cloud
Implement activity and event collection in Microsoft Sentinel
Implement Microsoft Security Copilot
The operational half: proving Defender for Cloud and Sentinel controls actually work, beyond simply configuring them.
Candidates guess at Sentinel ingestion mechanics instead of matching a data source to its actual pipeline.
Practise picking the right ingestion path — connector, CEF, or a custom log table — for a named data source.
Common traps
Where SC-500 candidates slip
Five recurring misconceptions that trip up otherwise well-prepared SC-500 candidates, grounded in the current skills outline.
Treating SC-500 as AZ-500 with a new name
Candidates study only AZ-500 material and consistently underperform on SC-500's dedicated AI-security slice.
Purview DSPM, Entra Agent ID, and Foundry guardrails carry no AZ-500 equivalent, and the exam weights them accordingly.
Add AI-security topics to your plan even if you already hold AZ-500 — don't assume the overlap is complete.
Defender for Storage vs a storage firewall rule
Candidates mix up a network-perimeter control with a threat-detection control inside the same storage domain.
A firewall rule blocks traffic before authentication; Defender for Storage detects suspicious activity after access has already happened.
For a scenario describing an attack already underway, pick the detection answer, not the network-perimeter one.
Treating Entra Agent ID like a normal app registration
Candidates default to classic Conditional Access or PIM patterns for scenarios that actually describe an autonomous agent.
Entra Agent ID governs autonomous agents specifically, distinct from human sign-ins and conventional service principals.
Look for an agent chaining actions across systems as the cue to reach for Agent ID's own controls.
Defender CSPM vs the free foundational tier
Candidates assume the free foundational tier already covers attack-path analysis and multicloud governance.
Attack-path analysis and agentless scanning both sit behind the paid CSPM layer, not the free foundational tier.
Match multicloud coverage or governance-at-scale requirements to CSPM, not the free tier.
Assuming every Sentinel source lands the same way
Candidates pick the wrong ingestion mechanism or invent a custom table where a built-in one already exists.
Syslog, Windows events, and genuinely custom sources each need a different ingestion path, and mixing them up is the common miss.
Check for an existing built-in table like CommonSecurityLog before assuming a source needs a custom one.
Designed for SC-500
How Azure Mastery helps you pass SC-500
Exam-specific practice
452 SC-500 practice questions aligned to the published skills outline.
Coverage leans hardest on securing storage, databases, and networking, the domain Microsoft weights up to 30%.
Practise reading Firewall and Network Watcher output to prove a security rule really does what it claims.
Predicted score
Exam IQ forecasts your SC-500 score on-device after roughly 30 questions, confidence range attached.
It flags whether data/network breadth or the newer AI-security topics are dragging that number down.
Compare all four domains to see which one is holding your predicted score back.
Adaptive study plan
Your plan leans hardest on storage, databases, and networking, the domain Microsoft weights up to 30%.
Miss a Defender-for-Storage or Sentinel-ingestion question and the next session surfaces that domain first.
Keep a topic solid for three sessions running and the plan shifts its focus to your next weak spot.
Knowledge decay
Forget the CSPM-vs-free-tier distinction early on and later posture questions get harder too.
The Today screen surfaces a decay warning so you can revisit a topic before it fades for good.
Fading topics come back into rotation on their own once you run a Focus Weak Spots session.
Exam rehearsal
Practise holding focus through a full 100-minute session, matching SC-500's real length.
Each rehearsal session weights all four domains the way Microsoft publishes them, using original questions.
Microsoft alone decides the live exam's interface and the order questions arrive in.
Answer Coach
Untangles SC-500's near-identical pairs: Defender for Storage vs a firewall rule, and Entra Agent ID vs a normal app registration.
Get a question wrong and Answer Coach names the exact scenario detail that should have driven your answer.
Supported devices can rephrase the note locally, always checked against the written explanation first.
Aura guidance
Aura adjusts its suggestions as your first week of SC-500 practice takes shape.
Each session wraps with a brief summary of progress, what to look at again, and your next step.
Private by design
Your SC-500 answer history, readiness gauge, and Answer Coach notes stay on your device by default.
No Azure Mastery account and no server ever processes your study data.
If you switch sync on, it travels only through your own private iCloud account.
6-week study plan
Suggested SC-500 study plan
Move from identity and governance to workload protection, AI security and operations. Use the final blocks of this six-week route for focused review and timed practice.
Identity and access
Compare authentication methods, MFA and passwordless access.
Review Conditional Access locations, risk and sessions.
Practise PIM eligibility, activation and access reviews.
Application identities and keys
Review enterprise apps, registrations and OAuth consent.
Use managed identities for Azure resources.
Configure Key Vault access, networking and protection.
Governance
Review built-in and custom Azure Policy definitions.
Compare built-in and custom RBAC roles.
Remediate excessive permissions and apply resource locks.
Compliance and recovery controls
Review compliance in Defender for Cloud.
Explore Azure Backup security.
Apply security controls through infrastructure as code.
Storage and databases
Secure storage accounts, firewalls and access policies.
Review Defender for Storage.
Explore SQL security, auditing and Defender for Databases.
Network security
Review NSGs, ASGs, Virtual Network Manager and Virtual WAN.
Compare VPN, Entra Private Access, Private Link and private endpoints.
Explore Azure Firewall and Network Watcher.
Compute and app platforms
Review disk encryption, Bastion, JIT access, Arc and trusted launch controls.
Explore Defender for Servers and container-platform protection.
Review Functions, Logic Apps, App Service, WAF and API Management security.
AI security
Review Purview DSPM for Copilot.
Explore Entra Agent ID controls and Defender XDR blast-radius analysis.
Review AI Gateway, Defender for AI and Foundry agent guardrails.
Security posture
Review Defender CSPM, compliance and workload protection.
Connect AWS and GCP environments.
Explore vulnerability management and external attack-surface management.
Sentinel and Security Copilot
Configure workspaces, roles and Content Hub solutions.
Review connectors, event collection and data collection rules.
Explore automation rules, playbooks and Security Copilot plugins or agents.
Target weaker topics
Run Focus Weak Spots sessions.
Revisit storage, database and networking decisions.
Review explanations for missed scenarios.
Timed rehearsal
Complete two 100-minute Exam Simulator sessions.
Review each run carefully.
Use the results to plan further study.
Inside the app
Nine interactive practice formats, on iPhone
Azure Mastery has nine interactive formats for exam practice. The examples below show original SC-500 practice questions in Azure Mastery on iPhone and iPad. The exam simulator uses timed sessions with the published domain weights. Microsoft's live interface and question mix may differ.
Which suffix identifies a custom log table that receives data through the Logs Ingestion API in a Microsoft Sentinel workspace?
_CEF
_CL
_SRCH
_RST
Multiple choice
An original SC-500 practice question with one correct answer. The app explains every option after you answer.
Exam-specific sample
Which two Recovery Services vault operations are mandatory Resource Guard protections when MUA is configured? (Choose two.)
Disable soft delete or other vault security features
Run a restore for a protected backup item
Stop backup while retaining the protected data
Remove MUA protection from the vault
Multi-select
An original SC-500 multi-select question. Select all the correct options to earn the mark.
All-or-nothing
You are standing up Microsoft Sentinel for the first time in a subscription that has no existing Log Analytics workspace. Order the steps to enable…
⋮⋮1In the Azure portal, search for and select Microsoft Sentinel, then…
⋮⋮2Select the newly created workspace from the list and select Add to…
⋮⋮3Open the Content hub and install a solution such as Azure Activity
⋮⋮4Open the Azure Activity data connector page and complete its setup to…
Drag-and-drop
An original SC-500 ordering question you can answer by touch on iPhone and iPad.
Interactive item
An auditor flags that blobs in a general-purpose v2 storage account could be read without any authorization if a container's access level were changed. You want to…
Hotspot
An original SC-500 question with a visual prompt, designed for touch on iPhone and iPad.
Tap target
Fabrikam Research Platform Fabrikam is deploying an Azure-hosted research platform. An application reads secrets from Azure Key Vault, stores regulated files in Azure Storage, and writes…
1How should the application authenticate to Key Vault?
3A researcher needs temporary read access to one blob. Which authorization design…
4A regulatory control appears unavailable in Defender for Cloud. What should…
Case studies
An original SC-500 case study with several questions about the same requirements and environment.
Multi-question
✕Your answer: _CEF
✨ Answer Coach:There is no _CEF table suffix; Common Event Format data lands in the built-in CommonSecurityLog table, which uses no custom suffix.
— grounded in authored certification guidance
Answer Coach
Answer Coach explains why the answer is correct and, where available, why each option is right or wrong. It helps you understand a mistake and remember the distinction. Read explanations after each question or at the end of a practice test. On supported devices, optional AI can reword a note on your device after checking it against the written guidance.
App exclusive
Frequently asked
SC-500 FAQs
Is SC-500 replacing AZ-500?
Yes. SC-500 (Cloud and AI Security Engineer) is the direct successor to AZ-500, which retired on 31 August 2026. It keeps AZ-500's core security-engineering content and adds securing cloud and AI workloads: Copilot, Entra Agent ID, Foundry, and Defender for AI. If you haven't started AZ-500, prepare for SC-500 instead.
How much does the SC-500 exam cost?
The SC-500 voucher is USD $165 in the United States, around £128 in the UK; regional pricing varies. Watch for free-voucher promotions around Microsoft Build or Microsoft Ignite. Renewal is free, but it's an annual Associate certification, so factor that into long-term cost planning.
Does the SC-500 certification expire?
Yes. Microsoft Associate certifications including SC-500 expire annually. Renewal is a free, short assessment on Microsoft Learn, available in the six-month window before expiry. Fundamentals certifications like SC-900 don't expire.
What is the SC-500 retake policy if I fail?
Each retake takes longer than the last, and every attempt requires its own voucher purchase.
First retake: after 24 hours.
Second and third retakes: a 14-day wait each.
Cap: five attempts per rolling 12 months.
How long should I study for SC-500?
Most candidates pass after four to eight weeks with some prior Azure and Entra experience; plan two to three months if cloud security is genuinely new. The exam expects hands-on knowledge of Defender for Cloud, Sentinel, Entra ID, and Key Vault. Azure Mastery's readiness gauge tells you when you're actually ready.
What prior experience does SC-500 assume?
SC-500 assumes hands-on Azure and hybrid administration — compute, network, storage — plus strong Entra ID familiarity. It isn't a from-scratch security course: you're expected to already operate the infrastructure you're securing. New to Azure administration? Work through AZ-104 or the free AZ-900 first.
SC-500 vs SC-200 — which next on the security track?
Different roles. SC-500 covers implementing security controls across identity, storage, networking, compute, and AI workloads. SC-200 covers running Defender XDR and Sentinel as a SOC analyst, focused on detection and incident response. Many Cybersecurity Architect candidates hold both.
Is Azure Mastery free for SC-500 prep?
The app is free to download and includes a free allowance of SC-500 questions so you can try every feature. The full bank of 452 SC-500 practice questions unlocks with a one-time exam-pack purchase, or you can unlock every exam in the catalogue with a subscription or a one-time lifetime upgrade.
Does SC-500 practice work offline?
Yes — every question, score, and readiness read happens on-device, so SC-500 prep keeps going without a connection. No account is needed, and nothing leaves your device unless you switch on private iCloud sync.
Is there an SC-500 practice test mode?
Yes. Timed practice sessions draw on original, blueprint-weighted SC-500 questions with published timing and the interactive formats this exam uses. Adaptive study and Focus Weak Spots then push you back toward the domains dragging your accuracy down.
Free study guides
Free guides that pair with SC-500
Where SC-500 fits
Certification paths that include SC-500
SC-500 is the cloud-and-AI security Associate cert — the successor to AZ-500 (retired 31 August 2026). It pairs with SC-900 on the way into security work. It can broaden your foundation before architecture work, but Microsoft currently lists SC-200, SC-300, or Azure Security Engineer Associate—not SC-500—as accepted prerequisites for the SC-100 credential.
SC-500 is the successor to AZ-500, which was retired by Microsoft on 31 August 2026, and a sibling of the SC-200 Security Operations Analyst cert. Most AZ-500 content carries over to SC-500; if you run detection-and-response, SC-200 is the natural pair.
Ready to pass SC-500?
Download Azure Mastery free. 452 SC-500 practice questions across all four domains, AI score prediction, full-length exam simulator, adaptive study plan. iPhone & iPad.