3Secure compute (including AI security)
- 3.1Securing AI solutions
The area SC-500 expands most beyond AZ-500. Learn to identify data overexposure in SharePoint, assess Copilot/AI-app risk with Microsoft Purview DSPM, apply real-time protection to Copilot Studio agents, use conditional access and blast-radius analysis for Microsoft Entra Agent ID, configure the AI Gateway and guardrails in Microsoft Foundry, and use Defender for AI and the Data and AI security dashboard in Defender for Cloud.
- 3.2Securing servers and virtual machines
Learn disk encryption, Azure Bastion, just-in-time (JIT) VM access, extending controls to hybrid/multicloud with Azure Arc, Defender for Servers (vulnerability scanning, EDR, agentless scanning), and secure boot/vTPM/integrity monitoring plus Azure Machine Configuration.
- 3.3Securing application platform services
Learn protecting container workloads (Defender for Containers), security controls for AKS, Azure Container Registry, and Container Instances/Apps, securing Azure Functions, Logic Apps, and App Service, Web Application Firewall, and back-end API protection with API Management.

