StudyToCert

All certifications / SC-500 / Cheat sheet

SC-500 SC-500 cheat sheet

Every exam tip and key term from the free SC-500 lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: Manage identity, access, and governance (24%)

Exam tips

Key terms

Microsoft Entra role
A directory role that grants permissions over identity objects and tenant settings, such as User Administrator or Security Administrator.
Azure RBAC role
A role definition that grants permissions over Azure resources through Azure Resource Manager, such as Owner, Contributor or Reader.
Scope
The level at which a role assignment applies: management group, subscription, resource group or resource; lower levels inherit it.
User Access Administrator
An Azure RBAC role that can manage role assignments but not the resources themselves.
Least privilege
Granting only the permissions needed, at the narrowest scope and for the shortest time.
Actions
Control-plane operations the role allows, such as creating or restarting a VM.
NotActions
Operations removed from the Actions wildcard for this role only; not a deny if another role grants them.
DataActions
Data-plane operations the role allows, such as reading blobs or Key Vault secrets.
AssignableScopes
The management groups, subscriptions or resource groups where a custom role may be assigned.
Eligible assignment
A PIM assignment that lets a user activate a role when needed; it grants no permissions until activated.
Active assignment
A role assignment whose permissions are currently in effect, either permanently or for a set time.
Activation
The just-in-time step where an eligible user turns on a role, subject to MFA, justification, ticket or approval settings.
Access review
A scheduled check in which reviewers confirm or remove users' continued access to a role, group or app.
Conditional Access policy
An if-then rule in Entra ID that evaluates sign-in signals and enforces grant or session controls.
Grant control
The part of a policy that blocks access or grants it only if requirements such as MFA or a compliant device are met.
Session control
A control that limits the session after access is granted, such as sign-in frequency or app-enforced restrictions.
Named location
A set of IP ranges or countries used as a condition; it can be marked as trusted.
Report-only mode
A policy state that logs what would happen without enforcing the policy.
Authentication methods policy
The Entra ID policy that enables or disables each sign-in method for all users or selected groups.
Phishing-resistant MFA
Methods bound cryptographically to the legitimate site, such as FIDO2 keys, passkeys, Windows Hello for Business and certificate-based authentication.
Passkey
A FIDO2 credential stored on a security key or device that signs in with a private key unlocked by PIN or biometrics.
Authentication strength
A Conditional Access grant control that requires specific combinations of methods, such as the built-in phishing-resistant MFA strength.
Temporary Access Pass
A time-limited passcode used to register or recover strong methods without a password.
Managed identity
An Entra identity for an Azure resource whose credentials Azure manages and rotates automatically.
System-assigned identity
A managed identity created on and tied to one resource's life cycle.
User-assigned identity
A standalone managed identity resource that can be attached to many resources and persists independently.
IMDS
The Azure Instance Metadata Service at 169.254.169.254 that VMs use to request managed identity tokens.
Application object
The global app definition in its home tenant, managed under App registrations.
Service principal
The tenant-local instance of an application, managed under Enterprise applications, that receives consent and assignments.
Delegated permission
A permission used by an app on behalf of a signed-in user, limited by that user's own access.
Application permission
An app-only permission used with no signed-in user; it always needs admin consent.
Admin consent workflow
A process that lets users request admin approval for apps they are not allowed to consent to.
Access policy model
The legacy Key Vault data-plane authorization that grants vault-wide permission sets per principal.
Key Vault RBAC
Data-plane authorization using Azure roles like Key Vault Secrets User, scopable to a single secret.
Soft delete
Keeps deleted vaults and objects recoverable for a 7 to 90 day retention period.
Purge protection
Prevents permanent deletion until the retention period passes; cannot be disabled once enabled.
Key rotation policy
A schedule that automatically creates new key versions and can notify before expiry.
Policy definition
A JSON rule with a condition and an effect that describes allowed resource configurations.
Initiative
A group of policy definitions assigned and reported on together, also called a policy set.
DeployIfNotExists
An effect that deploys a missing related resource or configuration using a template.
Remediation task
A job that applies Modify or DeployIfNotExists to resources that already existed before assignment.
Exemption
A record excluding a resource or scope from an assignment, categorized as Waiver or Mitigated, optionally time-limited.
CanNotDelete lock
A lock that allows reads and updates but blocks deletion of the resource and its children.
ReadOnly lock
A lock that blocks both updates and deletion, allowing only read operations.
Management group
A container above subscriptions whose RBAC and policy assignments are inherited by all subscriptions beneath it.
Root management group
The single top-level management group in every tenant that contains all others.
Sign-in risk
The likelihood that a specific authentication request was not made by the legitimate user.
User risk
The likelihood that an identity is compromised, for example because its credentials leaked.
Risk-based Conditional Access
Policies that require MFA or a secure password change based on sign-in or user risk level.

Domain 2: Secure storage, databases, and networking (28%)

Exam tips

Key terms

Data-plane RBAC
Azure roles such as Storage Blob Data Reader that authorize access to data inside a storage account.
Account access key
One of two keys granting full access to all data in a storage account via Shared Key authorization.
allowSharedKeyAccess
The storage account property that, when false, rejects requests authorized with account keys or key-signed SAS.
Key expiration policy
A storage account setting that flags account keys that have not been rotated within a set number of days.
User delegation SAS
A Blob SAS signed with a key obtained through Entra ID credentials, bounded by the creator's RBAC permissions.
Service SAS
A SAS signed with an account key granting access to resources in a single storage service.
Account SAS
A key-signed SAS that can span multiple services and service-level operations.
Stored access policy
A named policy on a container, queue, table or share that service SAS tokens can reference, allowing central change or revocation.
Customer-managed key
A key in Key Vault or Managed HSM that wraps the storage account's data encryption keys under your control.
Infrastructure encryption
A second, independent layer of encryption enabled only at storage account creation.
Time-based retention policy
An immutability policy keeping blobs undeletable and unmodifiable for a set interval; once locked, it can only be extended.
Legal hold
An immutability setting that preserves data indefinitely until the hold tag is removed.
Storage firewall
Network rules that restrict which subnets, public IP ranges or private endpoints can reach a storage account.
Trusted services exception
A firewall setting that allows listed Azure services, such as Azure Backup, to bypass network rules.
Resource instance rule
A firewall rule that allows a specific Azure resource instance, identified by its managed identity, to access the account.
Malware scanning
A Defender for Storage feature that scans uploaded blobs for malware and tags or alerts on results.
Sensitive data threat detection
Defender for Storage prioritization that uses Purview sensitive information types to flag threats to accounts holding sensitive data.
Microsoft Entra-only authentication
A server setting that disables SQL authentication so only Entra identities can sign in.
TDE
Transparent data encryption that encrypts database files, logs and backups at rest.
Always Encrypted
Client-side column encryption that keeps plaintext hidden from the database engine and its administrators.
Dynamic data masking
A policy that obfuscates column values in query results for users without UNMASK permission.
Database-level firewall rule
An IP rule stored in one database that applies only to that database.
Network security group
A stateful set of allow and deny rules applied to subnets or NICs.
Rule priority
A number from 100 to 4096; lower numbers are processed first and the first match wins.
Service tag
A Microsoft-maintained label representing the IP prefixes of an Azure service or category, such as Storage or Internet.
Application security group
A logical grouping of NICs used as a source or destination in NSG rules instead of IP addresses.
Azure Virtual Network Manager
A central service that groups virtual networks and deploys connectivity and security configurations to them at scale.
Network group
A static or policy-driven dynamic set of virtual networks targeted by AVNM configurations.
Security admin rule
A centrally managed rule evaluated before NSGs, with Allow, Deny or Always Allow actions.
Always Allow
A security admin action that permits traffic and bypasses NSG evaluation for it.
Service endpoint
A subnet setting that routes traffic to an Azure service over the backbone and lets the service firewall allow that subnet; the service keeps its public IP.
Private endpoint
A NIC with a private IP in your subnet mapped to one specific resource through Private Link.
Private Link service
Your own service behind a Standard Load Balancer, exposed to consumers through private endpoints.
Private DNS zone
An Azure DNS zone, such as privatelink.blob.core.windows.net, that resolves service names to private endpoint IPs for linked VNets.
Application rule
An Azure Firewall rule that allows or denies outbound traffic by FQDN or FQDN tag.
TLS inspection
A Premium feature that decrypts and re-encrypts HTTPS traffic using an intermediate CA certificate from Key Vault.
IDPS
Signature-based intrusion detection and prevention in Azure Firewall Premium.
Firewall policy
A resource holding firewall rules and settings, reusable across firewalls and supporting parent-child inheritance.
User-defined route
A custom route, such as 0.0.0.0/0 to the firewall's private IP, that overrides Azure's system routes.
Web application firewall
A layer 7 filter that inspects HTTP requests for attacks such as SQL injection and cross-site scripting.
Managed rule set
Microsoft-maintained WAF rules based on the OWASP Core Rule Set or Microsoft Default Rule Set.
Custom rule
A user-defined WAF rule, evaluated before managed rules, matching conditions such as IP, geography or rate.
Detection mode
A WAF mode that logs rule matches without blocking requests.
DDoS Network Protection
The paid Azure DDoS tier that adds adaptive tuning, telemetry, rapid response and cost protection for VNet resources.
Site-to-site VPN
An IPsec/IKE tunnel connecting an on-premises network's VPN device to an Azure VPN gateway.
Point-to-site VPN
A VPN from individual client devices to an Azure virtual network using OpenVPN, IKEv2 or SSTP.
Secured virtual hub
A Virtual WAN hub with Azure Firewall managed by Firewall Manager, with routing intent to inspect traffic.
ZTNA
Zero Trust network access, granting per-application access after identity and device checks instead of network-wide access.
Microsoft Entra Private Access
Microsoft's ZTNA service that publishes private apps through Global Secure Access with Conditional Access per app.
IP flow verify
A Network Watcher tool that tests whether a specific packet is allowed or denied to or from a VM and names the deciding rule.
Effective security rules
The merged view of all NSG and default rules that actually apply to a NIC.
VNet flow logs
Flow records captured at the virtual network, subnet or NIC level, independent of NSGs, stored in a storage account.
Traffic analytics
A feature that aggregates flow logs into Log Analytics for dashboards, queries and threat insights.

Domain 3: Secure compute (24%)

Exam tips

Key terms

Jailbreak
A direct prompt injection in which a user tries to make a model ignore its instructions or safety rules.
Indirect prompt injection
Malicious instructions hidden in documents or data that a model processes, rather than typed by the user.
Prompt Shields
An Azure AI Content Safety feature that detects jailbreak attempts in prompts and indirect attacks in documents.
Defender for AI services
A Defender for Cloud plan that raises threat alerts for Azure OpenAI and Foundry model deployments.
DSPM for AI
A Microsoft Purview solution that discovers AI usage, sensitive data in prompts and responses, and oversharing risks.
Oversharing
Content accessible to far more people than need it, which Copilot can surface to any of them.
Data risk assessment
A DSPM for AI report that finds overshared SharePoint sites and files and suggests remediation.
Sensitivity label
A Purview classification that can encrypt and mark content and that Copilot honors when accessing or generating data.
AI gateway
The set of Azure API Management capabilities for governing and securing access to AI model endpoints.
authentication-managed-identity
An APIM policy that obtains an Entra token using APIM's managed identity to call a backend.
llm-token-limit
An APIM policy that enforces tokens-per-minute rates and token quotas per key, returning 429 when exceeded.
Token metrics
Prompt, completion and total token counts emitted by APIM to Application Insights for monitoring and chargeback.
Microsoft Entra Agent ID
Entra capabilities that give AI agents their own directory identities for inventory, access control and protection.
Agent identity
A directory identity representing a specific AI agent, distinct from users and ordinary app service principals.
Agent identity blueprint
A template from which agent identities are created, defining shared configuration and permissions.
Sponsor
The human accountable for an agent's purpose, access and life cycle.
Server-side encryption
Always-on AES-256 encryption of managed disks at rest in Azure Storage, with platform or customer-managed keys.
Disk encryption set
A resource linking managed disks to a customer-managed key in Key Vault or Managed HSM through a managed identity.
Encryption at host
Encryption performed on the VM's physical host so temp disks and caches are encrypted before reaching storage.
Azure Disk Encryption
Legacy guest-based encryption using BitLocker or DM-Crypt with keys in Key Vault, scheduled for retirement.
Trusted launch
An Azure security type for Gen2 VMs combining Secure Boot, vTPM and boot integrity monitoring.
Secure Boot
A UEFI feature that loads only boot components signed by trusted publishers.
vTPM
A virtual TPM 2.0 that stores keys and records measured boot values for the VM.
Boot integrity monitoring
Remote attestation of a VM's boot measurements, reported as health status in Defender for Cloud.
Measured boot
Recording hashes of each boot stage into the TPM so the startup chain can be verified later.
Azure Bastion
A managed service providing browser or native-client RDP and SSH to VMs over TLS without public IPs on the VMs.
AzureBastionSubnet
The dedicated subnet name required for deploying Azure Bastion.
Just-in-time VM access
A Defender for Servers Plan 2 feature that keeps management ports closed and opens them temporarily for approved requests.
Management port
A port for remote administration such as 3389 (RDP) or 22 (SSH).
Defender for Servers Plan 1
Server protection centered on Microsoft Defender for Endpoint integration and core vulnerability management.
Defender for Servers Plan 2
Adds agentless scanning, JIT access, file integrity monitoring, premium vulnerability management and more.
Azure Arc-enabled server
A non-Azure machine running the Connected Machine agent so it can be managed as an Azure resource.
Azure Update Manager
A service that assesses and schedules OS patching for Azure VMs and Arc-enabled servers.
Agentless scanning
Analysis of VM disk snapshots for vulnerabilities, secrets and malware without an installed agent.
AKS-managed Entra integration
Configuration where users sign in to the Kubernetes API with Entra identities instead of local certificates.
Azure RBAC for Kubernetes
Using Azure role assignments, at cluster or namespace scope, to authorize Kubernetes API actions.
Private cluster
An AKS cluster whose API server is reachable only through a private IP in the virtual network.
Network policy
A Kubernetes resource that restricts traffic between pods based on labels, namespaces and ports.
Azure Policy add-on
An AKS add-on using OPA Gatekeeper to audit or deny non-compliant Kubernetes resources.
Admin user
A shared registry credential with full push and pull rights that should remain disabled.
AcrPull
An Azure role that allows pulling images from a registry.
AcrPush
An Azure role that allows pushing and pulling images.
Scope map and token
Registry features granting repository-specific permissions to non-Entra clients.
Key Vault reference
An app setting value of the form @Microsoft.KeyVault(...) that the platform resolves using the app's managed identity.
Access restrictions
Priority-ordered allow and deny rules that filter inbound traffic to an App Service or Function app.
HTTPS Only
A setting that redirects all HTTP requests to HTTPS.
Easy Auth
App Service built-in authentication that signs users in through identity providers before requests reach the code.
VNet integration
A feature that lets an app make outbound calls into a virtual network to reach private resources.

Domain 4: Manage and monitor security posture (24%)

Exam tips

Key terms

CSPM
Cloud security posture management: continuous assessment of configuration against best practices.
Foundational CSPM
The free Defender for Cloud tier providing recommendations, secure score, inventory and MCSB compliance.
Defender CSPM
The paid posture plan adding attack paths, cloud security explorer, agentless scanning, governance and data-aware posture.
Secure score
A percentage based on security controls, earned when all resources in a control are healthy.
Security control
A group of related recommendations whose points count toward secure score.
Cloud security graph
The Defender CSPM database of resources, exposures, identities and relationships used for context-aware analysis.
Attack path analysis
Automatic discovery of exploitable chains from an entry point to a critical asset, with remediations to break them.
Cloud security explorer
A query builder for searching the security graph for risky combinations of conditions.
Governance rule
A rule that assigns owners and due dates to matching recommendations and tracks remediation.
Choke point
A resource through which many attack paths pass, making it a high-value fix.
Microsoft cloud security benchmark
Microsoft's default security standard in Defender for Cloud, covering Azure and multicloud best practices.
Regulatory compliance dashboard
The Defender for Cloud view that maps assessments to the controls of selected standards.
Standard
A set of compliance controls, such as PCI DSS or ISO 27001, assigned to a scope in Defender for Cloud.
Custom standard
A user-defined set of recommendations grouped as a standard for tracking.
Cloud workload protection
Runtime threat detection for specific resource types delivered through Defender for Cloud plans.
Security alert
A detection of suspicious activity with severity, evidence, MITRE tactics and response guidance.
Suppression rule
A rule that automatically dismisses alerts matching defined conditions, used for known benign activity.
Sample alerts
Test alerts generated on demand to validate notifications and automation.
Multicloud connector
A Defender for Cloud resource that onboards an AWS account or GCP project for posture assessment and protection.
CloudFormation template
The AWS deployment template generated by Defender for Cloud to create the IAM roles the connector needs.
Workflow automation
A Defender for Cloud feature that triggers Logic Apps from alerts, recommendations or compliance changes.
Auto-provisioning of Arc
Connector-driven installation of the Azure Arc agent on AWS or GCP VMs for Defender for Servers.
Log Analytics workspace
The data store underlying Microsoft Sentinel, queried with KQL.
Azure Monitor Agent
The current agent for collecting logs from Windows and Linux machines, configured by data collection rules.
Data collection rule
A configuration defining what data AMA collects, optional KQL transformations and the destination.
CEF
Common Event Format, a standardized Syslog message format used by many security appliances, stored in CommonSecurityLog.
Log forwarder
A Linux VM with AMA that receives Syslog or CEF from devices and sends it to the workspace.
Scheduled query rule
An analytics rule that runs KQL on a schedule over a lookback window and raises alerts when a threshold is met.
NRT rule
A near-real-time analytics rule that runs every minute for fast detection of simple conditions.
Microsoft security rule
A rule that creates Sentinel incidents from alerts produced by other Microsoft security products.
Anomaly rule
A built-in machine learning rule that records deviations from baselines in the Anomalies table.
Entity mapping
Linking query columns to entity types like Account, Host and IP so incidents can be investigated and automated.
Automation rule
A no-code Sentinel rule that runs on incident or alert events to assign, tag, change status, add tasks or run playbooks.
Playbook
A Logic Apps workflow triggered by Sentinel to perform multistep response and enrichment actions.
Workbook
An interactive KQL-driven dashboard for visualizing Sentinel data.
Hunting query
A KQL query run proactively to search for threats not caught by analytics rules.
Watchlist
A CSV-based lookup table in Sentinel referenced in queries with _GetWatchlist.
Analytics tier
The full-featured log tier supporting all KQL, analytics rules and fast queries, at the highest ingestion cost.
Sentinel data lake
A low-cost lake tier for long-term security data, queried asynchronously and used to feed summarized results to Analytics.
Long-term retention
Low-cost retention up to 12 years, accessed through search jobs or restore.
Custom table
A table for non-standard data, named with the _CL suffix, created via the Logs Ingestion API or AMA custom logs.
summarize
A KQL operator that aggregates rows, such as counting events by user.
Security Compute Unit
The unit of provisioned capacity that determines how much processing Security Copilot can perform.
Copilot owner
The Security Copilot role that manages settings, plugins and capacity.
Plugin
A connector that gives Security Copilot data and skills from a Microsoft or third-party product.
Promptbook
A saved, reusable sequence of prompts for a common security task.
Embedded experience
Security Copilot features surfaced inside products like Defender XDR, Entra or Intune.
Unified audit log
The central Microsoft 365 record of user and admin activities across services, searched through Purview Audit.
Audit (Premium)
The advanced tier adding longer retention, custom retention policies, higher API bandwidth and intelligent insight events such as SearchQueryInitiatedExchange.
MailItemsAccessed
An audit event recording access to mailbox items, used to scope email compromise; originally Premium-only, now also logged for Audit (Standard).
Audit log retention policy
A Premium policy that sets how long specific audit records are kept.
Study SC-500 for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the SC-500 study plan