Instiq

Microsoft Cloud and AI Security EngineerStudy guide

Implement end-to-end security controls for cloud and AI workloads (SC-500, successor to AZ-500).

About Microsoft Cloud and AI Security Engineer (SC-500)

Microsoft Cloud and AI Security Engineer (SC-500) is a Associate-level certification from Microsoft. This page organizes the exam scope into a 4-chapter, 12-section study guide and lets you check your understanding with exam-style practice questions. A good flow is to read the chapters below in order, then test yourself via "Practice questions."

Exam domains (approximate weighting)

  • Manage identity, access, and governance~22%
  • Secure storage, databases, and networking~28%
  • Secure compute (including AI security)~25%
  • Manage and monitor security posture~25%

Weights are approximate guidance for the live exam. Each domain is covered in detail in the chapters and sections below.

Official exam information: https://learn.microsoft.com/en-us/credentials/certifications/resources/study-guides/sc-500

1Manage identity, access, and governance

  • 1.1Securing access with Microsoft Entra ID

    Learn the identity foundations of SC-500: Privileged Identity Management (PIM), conditional access, multifactor authentication (MFA) and passwordless, application identities (enterprise apps / app registrations) and OAuth consent management, and managed identities for Azure resources—implemented through least privilege and Zero Trust.

  • 1.2Protecting secrets and keys with Azure Key Vault

    Learn Azure Key Vault for safely storing secrets, keys, and certificates: deployment, the access models (RBAC vs access policies), network restriction (firewall / private endpoint), managing keys/secrets/certificates, and threat detection via Defender CSPM secret scanning and Defender for Key Vault.

  • 1.3Enforcing security and compliance through governance

    Learn to enforce controls with Azure Policy (built-in/custom definitions), evaluate regulatory compliance and configure security standards/recommendations with Microsoft Defender for Cloud, apply resource locks, manage built-in/custom roles and remediate over-privileged access (RBAC), use Azure Backup security features, and implement security controls via infrastructure as code.

2Secure storage, databases, and networking

  • 2.1Securing storage and databases

    Learn storage account security (firewall rules, access policies, Defender for Storage) and platform-level security for Azure SQL (authentication, networking, auditing, Defender for Databases) through the lens of layered data protection.

  • 2.2Controlling Azure network access

    Learn network security groups (NSGs) and application security groups (ASGs), network access policies via Azure Virtual Network Manager, security for Virtual WAN and VPN, Microsoft Entra Private Access, and protecting PaaS with private endpoints and Private Link services.

  • 2.3Azure Firewall and evaluating effective security rules

    Learn centralized traffic inspection and protection with Azure Firewall (application/network rules, threat intelligence, DNAT, Firewall Policy) and how to evaluate effective security rules and troubleshoot using Azure Network Watcher diagnostics.

3Secure compute (including AI security)

  • 3.1Securing AI solutions

    The area SC-500 expands most beyond AZ-500. Learn to identify data overexposure in SharePoint, assess Copilot/AI-app risk with Microsoft Purview DSPM, apply real-time protection to Copilot Studio agents, use conditional access and blast-radius analysis for Microsoft Entra Agent ID, configure the AI Gateway and guardrails in Microsoft Foundry, and use Defender for AI and the Data and AI security dashboard in Defender for Cloud.

  • 3.2Securing servers and virtual machines

    Learn disk encryption, Azure Bastion, just-in-time (JIT) VM access, extending controls to hybrid/multicloud with Azure Arc, Defender for Servers (vulnerability scanning, EDR, agentless scanning), and secure boot/vTPM/integrity monitoring plus Azure Machine Configuration.

  • 3.3Securing application platform services

    Learn protecting container workloads (Defender for Containers), security controls for AKS, Azure Container Registry, and Container Instances/Apps, securing Azure Functions, Logic Apps, and App Service, Web Application Firewall, and back-end API protection with API Management.

4Manage and monitor security posture

  • 4.1Managing security posture with Defender for Cloud

    Learn to identify risks with Defender CSPM, evaluate compliance against security frameworks, enable workload protection plans, connect hybrid/multicloud (AWS, GCP), configure Defender Vulnerability Management for Azure VMs, and discover unprotected assets with External Attack Surface Management (EASM).

  • 4.2Event collection and automated response with Microsoft Sentinel

    Learn Microsoft Sentinel, the cloud-native SIEM/SOAR: workspaces and roles, content hub, data connectors, Syslog/CEF and Windows Security events (data collection rules, WEF), custom log tables, automation rules and playbooks, data retention, and querying Purview Audit in Defender XDR.

  • 4.3Microsoft Security Copilot

    Learn Microsoft Security Copilot, which applies generative AI to security operations: configuring workspaces, managing permissions and roles, enabling and configuring plugins, and enabling and configuring Microsoft agents and Security Store agents.