仕事や学業でまとまった学習時間が取りにくい方こそ、JPNTestのSC-500対策教材が役立ちます。Microsoft Implementing End-to-End Security Controls for Cloud and AI Workloadsの出題傾向を分析した137の練習問題に絞って学習できるため、限られた期間でも効率的に実力を伸ばせます。
Microsoft SC-500 試験概要:
| 認定ベンダー: | Microsoft |
|---|---|
| 試験名: | クラウドおよびAIワークロード向けのエンドツーエンドセキュリティ制御の実装 |
| 試験番号: | SC-500 |
| 関連資格: | Microsoft認定:Azureセキュリティエンジニア アソシエイト(AZ-500、2026年8月31日に廃止予定) |
| 受験料: | 165米ドル |
| 試験時間: | 120 分 |
| 出題数: | 40~60問 |
| 試験形式: | ドラッグアンドドロップ式, インタラクティブシナリオ形式, ケーススタディ形式, 多肢選択式 |
| 対応言語: | 英語, 日本語 |
| 認定の有効期間: | 1年間(無料のオンライン評価により更新可能) |
| 合格点: | 700 / 1000 |
| 推奨トレーニング: | コース SC-500T00-A:クラウドおよびAIワークロード向けのエンドツーエンドセキュリティ制御の実装 Microsoft Learn 無料学習コース集 |
| 受験申し込み: | Pearson VUEでの受験申込み |
| サンプル問題: | Microsoft SC-500 サンプル問題 |
| 受験方法: | オンライン監督付き受験またはPearson VUE認定試験会場での受験 |
| 前提条件: | 受験に必須の前提条件はなし。推奨される経験:Azure環境・ハイブリッド環境の管理業務、Microsoft Entra IDおよびMicrosoft 365の運用経験 |
| 公式シラバスのURL: | https://learn.microsoft.com/en-us/credentials/certifications/resources/study-guides/sc-500 |
Microsoft SC-500 試験シラバストピック:
| セクション | 比重 | 目標 |
|---|---|---|
| トピック 1: セキュリティ体制の管理と監視 | 20~25% | - セキュリティ体制の監視・評価・改善
|
| トピック 2: コンピューティング環境の保護 | 20~25% | - アプリケーションおよびワークロードのID保護
|
| トピック 3: ID・アクセス・ガバナンスの管理 | 20~25% | - コンプライアンスおよびガバナンス制御の適用
|
| トピック 4: ストレージ・データベース・ネットワークの保護 | 25~30% | - ストレージおよびデータサービスの保護
|
Microsoft Implementing End-to-End Security Controls for Cloud and AI WorkloadsのQ&A
「SC-500」は、Microsoftが実施する「クラウドおよびAIワークロード向けのエンドツーエンドセキュリティ制御の実装」の試験コードです。この試験に合格すると、「Microsoft認定:クラウド・AIセキュリティエンジニア アソシエイト」の認定を取得できます。認定レベルはアソシエイトに位置づけられています。関連する認定としては、Microsoft認定:Azureセキュリティエンジニア アソシエイト(AZ-500、2026年8月31日に廃止予定)などが挙げられます。JPNTestでは、SC-500試験対策として137の練習問題をご用意しています。
SC-500試験の出題数は40~60問、制限時間は120 分です。限られた時間内で全問に取り組む必要があるため、1問にかけられる時間を常に意識し、難しい問題に長く留まりすぎないペース配分が求められます。本番で時間不足に慌てないよう、JPNTestのテストエンジンで制限時間つきの模擬試験に挑戦し、時間配分の感覚を体に覚えさせておくことをおすすめします。
SC-500試験の合格ラインは700 / 1000、受験料は165米ドルです。万が一不合格だった場合、再受験には改めて全額の受験料が必要になるため、費用面の負担も無視できません。受験前にJPNTestの137の練習問題で模擬試験に取り組み、安定して合格ラインを超えられることを確認してから本番に臨むと安心です。
受験に必須の前提条件はなし。推奨される経験:Azure環境・ハイブリッド環境の管理業務、Microsoft Entra IDおよびMicrosoft 365の運用経験
受験条件は変更される場合があります。最新かつ正確な情報は、Microsoftの公式ページで必ずご確認ください。
SC-500試験は、以下の公式窓口からお申し込みいただけます。
なお、本試験の受験方式はオンライン監督付き受験またはPearson VUE認定試験会場での受験です。
MicrosoftではSC-500試験向けに、以下の公式トレーニングを用意しています。
公式トレーニングで知識の土台を固めたうえで、JPNTestの137の練習問題に取り組めば、理解度の確認と弱点の洗い出しを効率よく進められます。
はい、ご購入前にJPNTestのSC-500問題集の無料サンプル(PDFデモ)をダウンロードして、問題の品質や形式をご確認いただけます。ご購入後は365日間の無料更新が付帯し、更新期間の終了後も50%割引で継続更新をご利用いただけるため、常に最新の出題傾向に沿った内容で学習を続けられます。
JPNTestでは「返金保証」制度をご用意しています。ご購入後60日以内にSC-500試験を受験して不合格となった場合、全額返金をご申請いただけます。なお、ご購入後3日以内の受験や、ダウンロード後に実際の受験をしていない場合、無料資料や期限切れのご注文は対象外となり、受験者氏名とお支払い者氏名が一致している必要があります。ご申請の際は、受験票(enrollment slip)の写しと公式スコアレポート(Score Report)のPDFを試験後2日以内にご提出いただき、受理後7日以内に手続きが完了します。返金をご希望でない場合は、同等価値の試験資料2点を無料でお受け取りいただき、元の製品の更新サービスを継続する選択肢もございます。
また、ご購入いただいた製品はお支払い完了後すぐにダウンロードでき、メールでも1分以内にお届けします。2時間以内に届かない場合はカスタマーサポートまでご連絡ください。インストール可能なパソコンの台数に制限はありません。
SC-500試験の出題範囲は、全部で4分野で構成されています。主な分野としては、「ID・アクセス・ガバナンスの管理」(20~25%)、「コンピューティング環境の保護」(20~25%)、「セキュリティ体制の管理と監視」(20~25%)などが挙げられます。各分野の詳細なトピックと配点は、上記の試験大綱をご確認ください。JPNTestのSC-500練習問題は、これらの出題分野を幅広くカバーしています。
Microsoft Implementing End-to-End Security Controls for Cloud and AI Workloads 認定 SC-500 試験問題:
You need to implement the planned change for the AKS1 integration.
What should you configure for AKS1?
- A. a workload identity
- B. application scaling
- C. Secrets Store CSI Driver
- D. Kubernetes role-based access control (Kubernetes RBAC)
正解:C 🗳️
解説: (JPNTest メンバーにのみ表示されます)
You have a hybrid Microsoft entra tenant named contoso.com that contains a user named Userl and the servers shown in the following table.
The tenant Is linked to an Azure subscription that contains a storage account named storage 1- The storage!
account contains a file
share named Share1
User1 is assigned the Storage File Data SMB Share Contributor role for storage1.
The security protocol settings for the file shares for storage1 are configured as shown in the following exhibit.
正解:

Explanation:
You have an Azure subscription that contains three storage accounts, an Azure SQL managed instance named SQL1, and three Azure SQL databases.
The storage accounts are configured as shown in the following table.

正解:

Explanation:
You have an Azure subscription that contains the following resources:
*An Azure SQL Database logical server named Server1 that contains a database named DB1
*An Azure SQL Managed Instance named Instance1 that contains a database named DB2 You need to configure database auditing. The solution must meet the following requirements:
*Ensure that audit data is centrally available in a location that supports for KQL queries.
*Minimize ongoing administrative effort as additional databases are added.
What should you configure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
正解:

Explanation:
Auditing scope: Enable on each server or instance; Auditing destination: A Log Analytics workspace
Server-level or instance-level auditing minimizes administration because new databases under the same logical server or managed instance inherit the auditing configuration. The destination must support KQL queries, which points to a Log Analytics workspace, not local database-level files or ad-hoc storage-only output. This design gives the security team a central query plane for audit events while avoiding repeated manual configuration each time another Azure SQL database is added. For this domain, least privilege means granting only the required data operation or allowing only the required network flow. The correct response avoids shared keys, broad peering, general contributor roles, or log-only controls when the scenario demands prevention, routing, event triggering, or account-specific configuration. The result is a direct exam-style implementation choice: it changes the required security behavior without relying on unrelated monitoring, manual cleanup, or excessive privilege. Official Microsoft source/topic: SC-500 Study Guide > Configure database auditing; Microsoft Learn > Azure SQL auditing destinations and Log Analytics.
You need to protect the applications hosted on AKS1. The solution must meet the technical requirements.
Which Defender for Cloud plan should you enable?
- A. Microsoft Defender for Containers
- B. Microsoft Defender for App Service
- C. Microsoft Defender for Servers
- D. Microsoft Defender for Storage
- E. Microsoft Defender for Resource Manager
正解:A 🗳️
解説: (JPNTest メンバーにのみ表示されます)
620 お客様のコメント



