GregLab | Exam Prep

Secure compute

Server and Virtual Machine Security

Core

Protect virtual machines and servers with encryption, controlled administration, time-bound exposure, hybrid management, Defender coverage, agentless discovery, trusted launch, and configuration enforcement.

Aligned to the live SC-500 guide, which publishes no skills-measured date; guide and product behavior verified September 23, 2026.

Why this matters

Server protection spans boot integrity, disks, network administration, operating-system configuration, endpoint telemetry, vulnerability assessment, and multicloud inventory. Each control observes or enforces a different layer.

Must Know

  • Azure Disk Storage server-side encryption protects managed disks by default; disk encryption sets and customer-managed keys add key-control requirements, while guest-level options address different needs.
  • Azure Bastion provides browser or native-client RDP and SSH connectivity through a managed service so VMs do not require public IP addresses for administration.
  • JIT VM access keeps selected management ports closed and creates a time-limited inbound rule only after an authorized request.
  • Azure Arc projects supported non-Azure servers into Azure management. Defender for Servers adds workload protection and can cover Azure, Arc-enabled, AWS, and GCP machines according to plan and onboarding.
  • Defender for Servers plan settings determine components such as endpoint detection and response and vulnerability assessment; coverage must be verified at the correct subscription or connector.
  • Agentless scanning examines supported VM disks and configuration without deploying an in-guest agent; it complements rather than replaces EDR telemetry and response.
  • Trusted launch combines secure boot and vTPM for supported generation 2 VMs; integrity monitoring supplies evidence about boot trust.
  • Azure Machine Configuration audits or enforces guest settings through policy assignments and machine configuration packages.

Compare and Distinguish

  • Bastion supplies an administrative connection path; JIT controls when selected inbound management ports may open.
  • Agentless scanning discovers vulnerabilities or secrets from snapshots; EDR observes and responds to runtime endpoint behavior.
  • Secure boot and vTPM protect boot trust; disk encryption protects stored disk data; Machine Configuration governs guest state.

Scenario examples

  • Scenario: Administrators need RDP without public VM addresses. Think: deploy Bastion with the required subnet and permissions.
  • Scenario: Security needs vulnerability inventory without installing another agent. Think: enable agentless scanning but retain EDR for runtime detection.
  • Scenario: A policy requires trusted boot plus encrypted disks. Think: configure supported trusted-launch features and the appropriate disk encryption control.

Exam traps

  • Bastion does not grant operating-system credentials or Azure VM login roles.
  • JIT is not a persistent allow rule and does not replace patching or strong authentication.
  • Arc onboarding alone does not enable every Defender for Servers component.
  • Agentless scanning cannot perform live endpoint containment.

Key takeaways

  • Minimize direct management exposure and use time-bound access.
  • Verify Defender component coverage rather than assuming onboarding implies protection.
  • Combine boot trust, encryption, runtime telemetry, vulnerability discovery, and guest configuration.
How it works
  • Azure platform controls protect VM disks and boot while network services constrain administration paths.
  • Arc and Defender connect server inventory, posture, vulnerability, EDR, and agentless evidence into cloud security operations.
Objects and administrative surfaces
  • VM disk encryption, disk encryption sets, Key Vault permissions, security type, secure boot, vTPM, and integrity monitoring.
  • Azure Bastion host, virtual network and subnet, JIT policies, NSG rules, and request history.
  • Azure Arc machine inventory, Defender for Servers plan components, vulnerability findings, EDR onboarding, agentless scanning, and Machine Configuration assignments.
When to use it
  • Use Bastion for private administrative access and JIT where time-bound port opening remains necessary.
  • Use Machine Configuration when policy must inspect or enforce operating-system settings across Azure-managed servers.
Security and governance implications
  • Protect disk keys, Bastion access, JIT approval, Arc onboarding credentials, Defender plan changes, and policy exemptions.
  • Track machines without EDR, vulnerability assessment, agentless coverage, trusted launch, or compliant guest configuration.
Troubleshooting signals
  • For Bastion failure, check subnet, routing, NSG, target VM state, credentials, and user authorization.
  • For missing Defender results, check plan scope, connector or Arc state, component provisioning, platform support, and scan recency.
More detail
  • Choose and configure disk encryption and key ownership.
  • Deploy Bastion and JIT according to the administration path.
  • Onboard Arc and Defender for Servers across cloud boundaries and verify EDR, vulnerability, and agentless components.
  • Configure trusted launch and Machine Configuration for platform and guest security.

Ready for the quiz?

  • When do Bastion and JIT solve different requirements?
  • Why does agentless scanning not replace EDR?
  • Which features establish trusted launch for a supported VM?

Related objectives

  • D3.2.S1 — Implement and configure disk encryption
  • D3.2.S2 — Plan and implement Azure Bastion
  • D3.2.S3 — Enable and enforce use of just-in-time (JIT) VM access
  • D3.2.S4 — Extend security controls to hybrid and multicloud servers by using Azure Arc
  • D3.2.S5 — Onboard servers to Defender for Servers in Defender for Cloud, including hybrid and multicloud scenarios
  • D3.2.S6 — Configure Defender for Servers settings, including vulnerability scanning, and endpoint detection and response (EDR)
  • D3.2.S7 — Implement and manage agentless scanning for VMs in Defender for Servers
  • D3.2.S8 — Configure security features on a VM, including secure boot, virtual Trusted Platform Module (vTPM), integrity monitoring, and security type
  • D3.2.S9 — Enforce security configuration of Azure-managed servers by using Azure Machine Configuration

Learn more

Free Microsoft Certified: Cloud and AI Security Engineer Associate prep

Build focused SC-500 quizzes from skill areas, topics, and product references.

Practice with exam-style multiple-choice and multiple-response questions, score breakdowns, explanations, and a compact reference for this lane's official exam domains.

Read Topics Build a quiz

Exam Weights

Exam snapshot

SC-500 at a glance

Level
Intermediate / Associate
Duration
120 minutes
Questions
No fixed live question count published
Formats
No guaranteed question-type mix; the proctored exam may include interactive components
Scoring
Scaled score; 700 minimum passing score

Quiz builder

Choose your practice set

Mode

Exam fidelity: Microsoft does not publish a fixed live question count or guarantee a question-type mix for SC-500. This lane contains multiple-choice and multiple-response exam-style practice. Practice percentages do not reproduce Microsoft's scaled scoring, and difficulty labels describe this site's Intermediate Associate-level cloud and AI security-engineering complexity rather than a Microsoft-published question rating.

Reference

SC-500 topics and reference map

Study links

SC-500 resources