Cheat sheet

Microsoft SC-500 Cheat Sheet

Quick Facts

Exam
SC-500
Credential
Cloud and AI Security Engineer
Level
Associate
Time
120 min
Pass
700/1000
Fee
$165 USD
Items
Not published (40-60 typical)
Delivery
Pearson VUE, proctored
Renewal
1 year, free online
Replaces
AZ-500
Blueprint
May 13 2026

Key Vault Retention

Soft delete 7-90 days | default 90

Soft delete cannot be disabledPurge protection is optionalSet once at creation

Policy vs Lock

Azure Policy

  • Allow, deny, remediate
  • Audits compliance
  • Scales by scope

Resource lock

  • CanNotDelete or ReadOnly
  • Stops accidental change
  • Inherited by children

Standard vs protection

Identity Control Picker

  1. Standing admin rightsPIM eligible role(Just-in-time)
  2. Risky sign-inConditional Access(Risk condition)
  3. App calls AzureManaged identity(No stored secret)
  4. Identity shared by appsUser-assigned identity(Own lifecycle)
  5. App holds a secretKey Vault(Use RBAC model)
  6. Stop accidental deletionResource lock(CanNotDelete)
  7. Enforce required tagsAzure Policy(deny effect)
  8. Too many role assignmentsAzure RBAC review(Least privilege)
  9. Prove compliance stateDefender for Cloud(Regulatory compliance)

PIM Essentials

Eligible
Must activate before useJIT
Active
Rights already granted
Activate
MFA, justification, approval
Time-bound
Start and end dates
Permanent eligible
Always able to activate
Approver
Approves or denies request
Access review
Confirms access still needed
Audit history
Downloadable activation record
PIM scope
Entra roles, Azure roles, groups

Conditional Access Formula

Assignments + conditions -> grant or session

Assignments: who and whatConditions: risk and deviceGrant: block or requireSession: limit the experience

Eligible vs Active

Eligible

  • Activation required
  • MFA and justification
  • Expires after activation

Active

  • Rights already usable
  • No activation step
  • Can still be time-bound

Request it vs have it

Conditional Access

Assignments
Who, what, where
Users and groups
Include or exclude
Target resources
Apps, actions, auth context
Network
IP ranges and geographies
Conditions
Risk, platform, client app
Grant
Block or require controls
Session
Sign-in frequency, app restrictions
Report-only
Evaluate without enforcing
Many policies
All must be satisfied
Block control
Wins over every grant

Key Vault RBAC vs Access Policy

Azure RBAC

  • Recommended and default
  • Granting needs Owner
  • Works with PIM

Access policy

  • Legacy data-plane only
  • Vault-wide permissions
  • Contributor can self-grant

Central vs vault-local

App and Managed Identities

App registration
Tenant application object
Enterprise app
Service principal instance
System-assigned
Tied to resource lifecycle
User-assigned
Standalone, shareable identity
OAuth grant
Delegated permission consent
Consent settings
Limit what users approve
Admin consent workflow
Users request admin approval

Key Vault Protection

Soft delete
On by default, permanent
Retention range
7 to 90 days
Default retention
90 days
Retention set once
Fixed at vault creation
Purge protection
Optional, blocks early purge
Key Vault Purge Operator
Role allowed to purge
RBAC model
Recommended and now default
Access policy
Legacy data-plane model
Vault firewall
Deny public, allow trusted
Defender for Key Vault
Vault access threat alerts

Azure Policy Effects

deny
Blocks noncompliant creation
audit
Flags but allows
auditIfNotExists
Checks related resource
deployIfNotExists
Deploys missing configuration
modify
Changes properties or tags
append
Adds required fields
denyAction
Blocks a named action
disabled
Turns the rule off
Order
Append, modify, deny, audit
Initiative
Grouped policy definitions

RBAC and Locks

Owner
Full access plus granting
Contributor
Manages, cannot grant access
User Access Administrator
Assigns roles only
Reader
View only
Custom role
Actions plus notActions
Deny assignment
Blocks despite role grant
CanNotDelete lock
Read and edit allowed
ReadOnly lock
No edits or deletes
Lock inheritance
Child scopes inherit locks

Firewall Order

Threat intel -> DNAT -> Network -> Application

Threat intel firstDNAT before networkApplication rules lastMatch stops processing

NSG vs ASG

NSG

  • Allow or deny rules
  • Subnet or NIC
  • Priority 100-4096

ASG

  • Named group of NICs
  • Used inside NSG rules
  • No rules of its own

Rule vs grouping

Network Control Picker

  1. Filter subnet trafficNSG(Layer 3-4)
  2. Group VMs by roleASG(Reusable source)
  3. Enforce rule tenant-wideSecurity admin rule(Beats NSG)
  4. Filter outbound FQDNAzure Firewall(Application rule)
  5. Inspect encrypted egressFirewall Premium(TLS inspection)
  6. Block SQL injectionWAF(Prevention mode)
  7. Reach PaaS privatelyPrivate endpoint(Private IP)
  8. Offer your own servicePrivate Link service
  9. Retire the VPNEntra Private Access(Per-app access)
  10. Rule not applyingNetwork Watcher(Effective rules)

Storage Account Security

User delegation SAS
Signed by Entra credentialsBest
Service SAS
One service, account key
Account SAS
Many services, account key
Stored access policy
Revoke a service SAS
Disable Shared Key
Forces Entra authorization
Storage firewall
Default deny public networks
Trusted services
Exception for Azure platform
Defender for Storage
Malware and exfiltration alerts
Sensitive data detection
Prioritizes alerts by sensitivity

NSG Default Priorities

65000 VNet | 65001 edge | 65500 deny

65000: VNet to VNet65001: LB in, internet out65500: deny allCustom: 100-4096

Azure Firewall vs WAF

Azure Firewall

  • Network and FQDN egress
  • DNAT, network, application
  • IDPS on Premium

WAF

  • Inbound HTTP inspection
  • SQL injection and XSS
  • Gateway or Front Door

Egress vs web requests

Azure SQL Security

TDE
Encrypts at rest, default
TDE with CMK
Key Vault wraps key
Always Encrypted
Client-side column encryption
Dynamic data masking
Hides values in results
Row-level security
Filters rows per user
Ledger
Tamper-evident change proof
Server firewall rule
Applies to all databases
SQL auditing
Storage, Log Analytics, Event Hubs
Entra-only auth
Blocks SQL logins
Defender for SQL
Vulnerability assessment plus alerts

Private Endpoint vs Service Endpoint

Private endpoint

  • Private IP in VNet
  • Reachable from on-premises
  • Needs private DNS

Service endpoint

  • Source stays public IP
  • Subnet scoped
  • No cost, no DNS

Bring service in vs route out

NSG Default Rules

Custom priority
100 to 4096
Lower number
Processed first, wins
AllowVNetInBound
Priority 65000
AllowAzureLoadBalancerInBound
Priority 65001
DenyAllInbound
Priority 65500
AllowVnetOutBound
Priority 65000
AllowInternetOutBound
Priority 65001
DenyAllOutBound
Priority 65500
Stateful
Return traffic auto-allowed
ASG
Groups NICs, not addresses

Firewall Rule Order

Threat intelligence
Runs before all rules
DNAT rules
Inbound translation, evaluated first
Network rules
Layer 3-4, after DNAT
Application rules
FQDN based, evaluated last
Terminating
First match stops processing
Parent policy
Beats child policy priority
Premium SKU
TLS inspection, IDPS, URL filtering
IDPS Alert
Runs parallel, logs only
IDPS Alert and Deny
Inline, drops matching flow
Default action
Deny anything unmatched

Private Access Options

Private endpoint
Private IP inside VNet
Private Link service
Publish your own service
Service endpoint
Subnet keeps public IP
Private DNS zone
Resolves FQDN to private
Connection approval
Automatic or manual request
Entra Private Access
Replaces VPN for apps
Quick Access
Primary FQDN and IP set
Network Watcher
Shows effective security rules

Security Admin Rules

Owner
Azure Virtual Network Manager
Scope
Applied at virtual network
Order
Evaluated before NSG rules
Allow
NSG rules still evaluated
Always Allow
Terminates, bypasses NSG
Deny
Terminates, drops traffic
Priority
1 to 4096
One config per region
Use multiple rule collections

AI Security Stack

Discover -> Identity -> Guardrail -> Detect

Discover: Purview DSPMIdentity: Entra Agent IDGuardrail: Prompt ShieldsDetect: Defender for AI

Agent ID vs Managed Identity

Entra Agent ID

  • Identity for AI agents
  • Blueprints create agents
  • Conditional Access applies

Managed identity

  • Identity for Azure resources
  • System or user assigned
  • Gets RBAC roles

Agent vs resource

AI Control Picker

  1. Copilot sees too muchPurview DSPM for AI
  2. SharePoint oversharingData risk assessment
  3. Agent needs an identityEntra Agent ID
  4. Limit agent accessConditional Access(Target agents)
  5. Trace agent blast radiusDefender XDR
  6. Block jailbreak promptsPrompt Shields(Foundry guardrail)
  7. Cap model token spendAPIM token limit
  8. Alert on AI attacksDefender for AI Services
  9. Watch AI postureData and AI dashboard

Security for AI

Purview DSPM for AI
Copilot and AI data risk
Data risk assessment
Finds SharePoint oversharing
Restricted Content Discovery
Hides sites from Copilot
Agent runtime protection
Copilot Studio security status
Entra Agent ID
Identities for AI agents
Agent identity blueprint
Template creating agent identities
Conditional Access for agents
Blocks or limits agents
Risky Agents report
Agent risk from ID Protection
Defender XDR
Agent blast radius analysis
Microsoft 365 admin center
Where agents are managed

AI Guardrails

Foundry guardrails
Filters for models and agents
Prompt Shields
Detects prompt injection attacks
User prompt attack
Direct jailbreak attempt
Document attack
Indirect injection in content
Spotlighting
Marks untrusted document text
Intervention points
Input, tool call, output
Guardrail action
Annotate or block
Harm categories
Hate, Sexual, Violence, Self-Harm
Trimmed severity
0, 2, 4, 6
Groundedness detection
Flags unsupported model claims

APIM AI Gateway

llm-token-limit
Caps tokens per consumer
llm-emit-token-metric
Token metrics to Monitor
llm-semantic-cache-lookup
Reuses similar prompt completions
llm-content-safety
Moderates prompts inline
Backend load balancer
Round-robin, weighted, priority
Circuit breaker
Stops calling failing backend
Managed identity auth
Removes stored API keys

VM and Server Hardening

Trusted launch
Default for new Gen2
Secure boot
Only signed components boot
vTPM
Measures the boot chain
Integrity monitoring
Remote boot attestation health
Encryption at host
Encrypts on the host
Azure Disk Encryption
In-guest BitLocker or DM-Crypt
Bastion
RDP/SSH without public IP
AzureBastionSubnet
/26 or larger
JIT VM access
Opens ports on request
Azure Arc
Extends controls to hybrid
Machine Configuration
Enforces guest OS baselines

Containers and App Platform

Defender for Containers
Misconfiguration and runtime risk
Registry scanning
Container image vulnerabilities
AKS hardening
Cluster security recommendations
App Service auth
Built-in identity provider
Access restrictions
IP allow list for apps
Functions network access
Private endpoints, inbound rules
Logic Apps
Secure inputs and outputs
WAF modes
Detection or Prevention
APIM policies
Protect back-end APIs

Sentinel Retention

30 default | 730 interactive | 12 years total

Analytics default 30 daysInteractive max 730 daysBasic and Auxiliary fixed 30Total retention 12 years

Sentinel vs Defender XDR

Sentinel

  • Cloud-native SIEM
  • Any connector or syslog
  • KQL and playbooks

Defender XDR

  • Microsoft-first XDR
  • Correlates Microsoft alerts
  • Agent blast radius

Any source vs Microsoft

Defender Plan Picker

  1. Need attack pathsDefender CSPM(Paid plan)
  2. Need EDR onlyServers Plan 1
  3. Need JIT and FIMServers Plan 2
  4. Scan blobs for malwareDefender for Storage
  5. Database threat alertsDefender for Databases
  6. Find hardcoded secretsDefender CSPM(Secrets scanning)
  7. Vault access threatsDefender for Key Vault
  8. Container runtime riskDefender for Containers
  9. Unknown internet assetsDefender EASM
  10. Protect AWS and GCPMulticloud connector

CSPM Plan Split

Foundational CSPM
Free posture plan
MCSB
Default free security standard
Secure score
Free, based on MCSB
Asset inventory
Free in both plans
Defender CSPM
Paid advanced posture
Attack path analysis
Defender CSPM only
Cloud security explorer
Defender CSPM only
Agentless VM scanning
Defender CSPM only
AI security posture
Defender CSPM only
Defender EASM
Finds unprotected internet assets

Foundational vs Defender CSPM

Foundational

  • Free plan
  • MCSB and secure score
  • Recommendations and inventory

Defender CSPM

  • Paid plan
  • Attack paths and explorer
  • Agentless and AI posture

Score vs risk context

Defender Workload Plans

Servers Plan 1
Defender for Endpoint integration
Servers Plan 2
Adds JIT, agentless, FIM
File integrity monitoring
Plan 2 only
Data ingestion benefit
Plan 2 free allowance
Defender for Storage
Priced per storage account
Malware scanning
Billed per GB scanned
Defender for Databases
Azure database threat alerts
Defender for AI Services
Generative AI threat alerts
Multicloud connectors
Onboard AWS and GCP

Sentinel Setup

Workspace
Log Analytics is required
Content hub
Installs solutions and connectors
Sentinel Reader
Views data and incidents
Sentinel Responder
Adds incident management
Sentinel Contributor
Creates rules, manages content
Playbook Operator
Runs playbooks manually
Logic App Contributor
Creates and edits playbooks
Automation Contributor
Service role, not people
Automation rule
Orchestrates incident response
Playbook
Logic App workflow

Sentinel Data Collection

Data collection rule
Defines what AMA collects
Syslog via AMA
Lands in Syslog table
CEF via AMA
Lands in CommonSecurityLog
Log forwarder
Linux VM running rsyslog
Windows Security events
Collected through a DCR
Custom log table
Stores ingested custom data
Analytics default
30 days interactive
Analytics maximum
730 days interactive
Basic and Auxiliary
Fixed 30-day interactive
Total retention
Up to 12 years

Security Copilot

SCU
Security compute unit
Provisioned capacity
Baseline, billed hourly
Overage capacity
Absorbs usage spikes
Capacity calculator
Estimates SCUs needed
Owner role
Changes capacity units
Plugins
Extend Copilot data sources
Workspace
Where capacity is associated

Common Traps

Sign in vs act

Entra ID authenticates Azure RBAC authorizes

Eligible vs active

Eligible needs activation Active works immediately

Soft delete vs purge protection

Soft delete always on Purge protection is optional

Allow vs Always Allow

Allow still hits NSG Always Allow skips NSG

Private vs service endpoint

Private endpoint gets private IP Service endpoint keeps public IP

Firewall vs WAF

Firewall filters network egress WAF inspects HTTP requests

Servers Plan 1 vs 2

Plan 1 is EDR Plan 2 adds JIT

Free vs paid posture

Foundational gives secure score Defender CSPM gives attack paths

Detection vs prevention

Detection only logs Prevention blocks the request

Masking vs encryption

Masking hides query output Always Encrypted protects stored data

Last Minute

  1. 1.Storage, database, network is heaviest: 25-30%
  2. 2.Other three areas: 20-25% each
  3. 3.Pass = 700 of 1000
  4. 4.Entra authenticates; Azure RBAC authorizes
  5. 5.PIM eligible means activate first
  6. 6.Key Vault soft delete: 7-90 days
  7. 7.Purge protection is not default
  8. 8.NSG deny-all inbound is 65500
  9. 9.Firewall: DNAT, network, then application
  10. 10.Always Allow bypasses NSG rules
  11. 11.Private endpoint = private VNet IP
  12. 12.WAF stops HTTP attacks, not egress
  13. 13.JIT needs Defender Servers Plan 2
  14. 14.Attack paths need paid Defender CSPM
  15. 15.DSPM for AI finds Copilot oversharing
  16. 16.Prompt Shields block jailbreak and injection
  17. 17.Entra Agent ID identifies AI agents
  18. 18.Sentinel default retention: 30 days
Same family resources

Explore More Microsoft Azure Certifications

Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.