Domain 2: Microsoft Entra & Identity Security
Microsoft SC-500 Security Copilot · 52 questions
- A global enterprise wants to enforce Multi-Factor Authentication for all users accessing Azure AI Studio. The policy must exclude break-glass emergency accounts. The company uses Microsoft Entra ID. Which Conditional Access policy configuration is correct?
- An organization uses Azure OpenAI Service and wants to ensure that only specific service principals can call the Azure OpenAI API. The developer team should be blocked from accessing the API key directly. Which combination of controls achieves this?
- A security engineer is implementing Microsoft Entra Privileged Identity Management (PIM) for roles that grant access to sensitive AI resources. The engineer wants to require users to provide a justification and receive manager approval before being assigned the 'Cognitive Services OpenAI Contributor' role. Which PIM setting configures this?
- Microsoft Entra ID Protection has flagged a high-risk sign-in for a user who regularly accesses Azure Machine Learning Studio. The security engineer wants to automatically block high-risk sign-ins without requiring manual intervention. Which policy type in Entra ID Protection achieves this?
- An organization's AI platform team uses a user-assigned managed identity to authenticate Azure Functions to Azure OpenAI Service. A security review finds that the managed identity also has Contributor access at the subscription level from a previous misconfiguration. What is the correct remediation?
- An organization wants to implement periodic reviews of which users have access to an AI model access group in Microsoft Entra ID. If a reviewer does not respond, access should be automatically removed. Which feature implements this?
- A developer needs to authenticate an application to Azure AI Search without storing credentials. The application runs on an Azure VM. Which identity approach should be used, and which Azure AI Search role grants read-only index query access?
- A company is implementing Microsoft Entra External Identities to allow partner organizations' researchers to access an AI experimentation portal. The security team requires that partner users must satisfy the home organization's MFA before accessing the portal. Which Entra External Identities trust setting achieves this?
- An organization wants to require a secondary approval before any user can delete an Azure Machine Learning workspace or remove a private endpoint from an Azure OpenAI resource—even if that user has Owner or Contributor permissions. Which Microsoft Entra ID feature enables this approval gate for specific sensitive Azure management operations?
- A company deploys an AI application on Azure App Service. The application uses a service principal to authenticate to Azure AI services. The security team wants to prevent this service principal's tokens from being used from outside the corporate network. Which Entra ID feature enforces this restriction?
- An organization wants to prevent phishing-resistant authentication bypass for users accessing Azure Machine Learning. They require authentication methods that cannot be intercepted by adversary-in-the-middle attacks. Which Conditional Access setting enforces this requirement?
- An AI platform team uses a system-assigned managed identity for an Azure Functions app that calls Azure OpenAI. The function app has been decommissioned, and a new function app with a different managed identity will replace it. Which Entra ID access control step must be completed to ensure the old identity cannot continue calling Azure OpenAI?
- A company's AI research team regularly has visiting researchers who need temporary access to Azure ML workspace resources for 48-hour engagements. The security team wants just-in-time access with automatic expiration. Which Microsoft Entra ID capability is most appropriate?
- An enterprise is implementing Continuous Access Evaluation (CAE) for applications that consume Azure AI services. A user's account is disabled in Microsoft Entra ID while they have an active session with Azure AI services. How does CAE affect the user's session?
- A security architect is designing identity controls for a multi-tenant SaaS AI application built on Azure. The application uses Microsoft Entra External ID (B2C) for customer authentication. The architect wants to enforce MFA for all customer sign-ins through a standard policy. Which Entra External ID feature provides this?
- An organization is implementing token protection in Microsoft Entra ID Conditional Access for users accessing Azure AI Foundry. Token protection binds the token to the device. Which scenario is prevented by enabling token protection?
- A company wants to ensure that Entra ID guests (external collaborators) who access Microsoft 365 Copilot are subjected to the same MFA and compliant device requirements as internal employees. Which Entra ID Conditional Access configuration achieves this?
- A company's Microsoft Entra ID administrator wants to protect the action of removing a Conditional Access policy that enforces MFA for Azure AI Foundry, so that even Global Administrators cannot remove the policy without satisfying an additional authentication challenge. Which Entra ID feature enables this protection for administrative actions?
- A security administrator needs to create a Conditional Access policy that requires a higher authentication assurance (step-up authentication) only when users attempt to perform model deployment operations in Azure AI Foundry—not for regular read access. Which Conditional Access feature implements this step-up authentication for a specific operation?
- A company uses Azure Machine Learning with a managed online endpoint that authenticates callers using a key. The security team wants to migrate to token-based authentication using managed identities. The endpoint will be called by an Azure App Service. Which steps correctly implement this migration?
- An organization uses Microsoft Entra Permissions Management (CIEM - Cloud Infrastructure Entitlement Management) to monitor Azure AI service permissions. The security team wants to identify service principals with unused permissions to Azure OpenAI resources that have not been exercised in the past 90 days. Which Permissions Management capability provides this analysis?
- A company wants to implement Microsoft Entra Lifecycle Workflows to automatically provision and deprovision access to Azure AI Foundry resources for new hires and terminated employees. Which Lifecycle Workflow trigger and task combination correctly automates this?
- An organization needs to federate a GitHub Actions CI/CD pipeline identity with Microsoft Entra ID so the pipeline can deploy Azure OpenAI models without storing any Azure credentials in GitHub secrets. Which Entra ID feature enables this credential-free federation?
- A large enterprise uses a Microsoft Entra ID Governance access package for AI platform access. The access package includes Azure Machine Learning workspace member role, Azure OpenAI user role, and AI data store access. A business partner organization needs access to the same resources for a 6-month project. Which Entitlement Management feature allows external users to request the access package?
- A security team is implementing Entra ID PIM access reviews for the 'Cognitive Services Contributor' role. The review is quarterly, and active role assignments that are not reviewed within 30 days should be automatically removed. The security team also wants to require a justification from the reviewers. Which PIM access review settings achieve this?
- An organization's Azure OpenAI deployment is experiencing intermittent authentication failures from a legitimate application. The security team suspects the issue is caused by the application's Azure AD token expiring during long-running operations. Which application authentication best practice prevents this?
- A security engineer needs to implement Privileged Identity Management (PIM) for a group of Azure subscription owners. The requirement states that activation must require approval and must generate an approval request to two specific managers. How should PIM be configured?
- Microsoft Entra ID Protection reports a 'Leaked credentials' risk detection for a user account. The organization has a Conditional Access policy that requires MFA for medium and high user risk. The compromised user successfully authenticates with MFA and continues working. What additional remediation step should the security team take?
- An organization uses Microsoft Entra ID Governance Access Packages to manage external partner access. A security engineer needs to ensure that external users automatically lose access when their access package assignment expires, without requiring manual intervention. Which feature should be configured?
- A company has hybrid identity with Microsoft Entra Connect. The security team detects a Golden Ticket attack against the on-premises Active Directory. After remediating the on-premises compromise, which Microsoft Entra ID action is required to prevent the attacker from using synced credentials?
- A security engineer is configuring Microsoft Entra Conditional Access for an application that processes financial data. The policy must enforce that access is granted only when users are on compliant devices AND connecting from a named location AND have low sign-in risk. What grant controls and conditions must be set?
- A security engineer reviews Microsoft Entra ID Protection and sees multiple 'Anonymous IP address' sign-in risk detections for a service account used by an on-premises application for API calls. What is the most likely cause and appropriate remediation?
- An organization needs to implement Microsoft Entra ID entitlement management so that when an employee transfers from the Sales department to Engineering, their Sales access is automatically removed and Engineering access is granted. Which entitlement management feature enables this automation?
- A security engineer is investigating a Microsoft Entra ID sign-in log and notices a user has a 'Token issuer anomaly' risk detection. What does this detection indicate?
- A global organization needs to configure Microsoft Entra External ID for their AI-powered customer portal. External customers must authenticate using their Google or Facebook identities. The security team requires that all external user sign-ins are subject to risk evaluation. How should this be configured?
- A security engineer needs to configure Microsoft Entra ID to require re-authentication for all users when they access a sensitive AI application after being inactive for more than 30 minutes. Which Conditional Access feature should be configured?
- An organization uses Microsoft Entra Verified ID for its AI hiring platform. External candidates must present verifiable credentials from their educational institution before accessing the platform. A security engineer needs to ensure that the issuer (university) of the credential is trusted. How is trust established in Microsoft Entra Verified ID?
- A security engineer is implementing Microsoft Entra ID Protection for a financial institution. The engineer needs to configure the user risk remediation to allow users to self-remediate high user risk by performing password reset and MFA, rather than requiring IT helpdesk involvement. What must be configured?
- A company implements Microsoft Entra ID Cross-Tenant Synchronization to share identities between its parent company and a recently acquired subsidiary's Entra ID tenant. The security team needs to ensure that only the subsidiary's AI research team is synchronized to the parent tenant. What must be configured?
- A security engineer is reviewing an Entra ID application registration used by an AI model training pipeline. The application has the 'Application.ReadWrite.All' permission granted as an application permission (not delegated). A security review flags this as high risk. What is the specific risk this permission poses?
- A security engineer needs to configure Microsoft Entra ID to prevent service accounts used by AI workloads from being modified or deleted by Azure subscription owners. The service accounts are represented as workload identities (service principals). Which Microsoft Entra ID feature prevents unauthorized modification of these service principals?
- A security engineer needs to implement Microsoft Entra ID Application Proxy to publish an internal AI web application securely for remote workers, without requiring a VPN. The AI application uses Windows Integrated Authentication (WIA) for on-premises users. How should Kerberos Constrained Delegation (KCD) be configured for Application Proxy?
- A security team needs to implement Microsoft Entra Permissions Management (CIEM) to identify and remediate over-privileged AI service identities across their Azure subscriptions. After a permissions discovery scan, the team finds several managed identities with unused permissions. Which Permissions Management action remediates over-privileged identities while maintaining operational continuity?
- A security engineer is implementing the Microsoft Cloud Security Benchmark (MCSB) controls for an Azure AI platform deployment. The MCSB control 'IM-1: Use centralized identity and authentication system' requires all service-to-service authentication to use Entra ID. A legacy AI service component uses username/password authentication with a local account. Which migration path aligns with the MCSB IM-1 control?
- An organization implements Microsoft Entra ID Governance entitlement management for a partner company that needs access to an AI analytics portal. The partner company does not have Microsoft Entra ID. How should external access be configured?
- A security engineer needs to configure Microsoft Entra ID to prevent AI automation service accounts from being used interactively (by humans logging in with the service account credentials). Which Microsoft Entra ID feature directly blocks interactive sign-in for service accounts?
- A security engineer is implementing Microsoft Entra ID Password Protection to prevent users and AI automation scripts from using weak or organization-specific banned passwords when rotating credentials. The organization has an on-premises Active Directory. Which component must be deployed to extend Entra ID Password Protection to on-premises AD?
- An organization uses Microsoft Entra ID to manage access to their Azure AI Foundry environments (development, staging, production). The security team needs to ensure that changes to production AI model deployments require approval from two members of the AI Security Review team. Which Microsoft Entra feature provides this approval workflow for Azure resource modifications?
- An organization's AI operations team wants to implement a self-service model to allow data scientists to request access to production AI model deployment permissions via Microsoft Entra ID Governance. The request must trigger an automated security review that checks whether the requester has completed required AI security training. Which Microsoft Entra ID Governance capability supports this requirement?
- A security engineer is implementing Microsoft Entra ID Application Proxy for an internal AI dashboard application. The application uses OAuth 2.0 for authentication. The engineer needs to configure pre-authentication so that only authenticated Entra ID users can reach the application. Which Application Proxy pre-authentication mode should be configured?
- A security engineer needs to configure Microsoft Entra ID to enforce that all OAuth 2.0 applications accessing Azure OpenAI must use the authorization code flow with PKCE (Proof Key for Code Exchange) instead of the implicit flow. Which Entra ID configuration enforces this requirement?
- A security engineer is reviewing Microsoft Entra ID sign-in logs for an AI pipeline service account. The logs show sign-ins using 'Seamless Single Sign-On' from an IP address in an unexpected country. The service account is supposed to run only in Azure datacenters. What is the most appropriate immediate action?