Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft SC-500 Exam - Topic 3 Question 2 Discussion

You have a Microsoft Copilot Studio agent.A Microsoft Power Platform administrator configures external threat detection for the agent by using a Microsoft Entra application.You need to ensure that real-time protection is enabled during agent runtime.What should you do in the Microsoft Defender portal?
B) Connect the Microsoft 365 app connector.
A) Configure Microsoft Defender for Cloud Apps session policies.
C) Enable Global Secure Access for Agents.
D) From Microsoft Sentinel, configure the Microsoft Purview data connector.

Microsoft SC-500 Exam - Topic 3 Question 2 Discussion

Actual exam question for Microsoft's SC-500 exam
Question #: 2
Topic #: 3
[All SC-500 Questions]

You have a Microsoft Copilot Studio agent.

A Microsoft Power Platform administrator configures external threat detection for the agent by using a Microsoft Entra application.

You need to ensure that real-time protection is enabled during agent runtime.

What should you do in the Microsoft Defender portal?

Show Suggested Answer Hide Answer
Suggested Answer: B

For external threat detection and real-time agent protection to work, Defender must receive app activity through the Microsoft 365 app connector. Session policies in Defender for Cloud Apps govern user sessions, Global Secure Access controls network access, and a Sentinel connector is for log ingestion and investigation. The Microsoft 365 app connector is the required Defender portal-side integration for this runtime protection scenario. For SC-500, compute controls are evaluated by workload type: VM, Arc server, AKS, container registry, container group, Functions, Logic Apps, App Service, and AI agent runtime. The right answer uses the Microsoft control that is native to that workload. Broad Azure roles or unrelated monitoring services would either overgrant access or fail to enforce the required security state. The result is a direct exam-style implementation choice: it changes the required security behavior without relying on unrelated monitoring, manual cleanup, or excessive privilege. Official Microsoft source/topic: SC-500 Study Guide > AI workload runtime protection; Microsoft Learn > Microsoft 365 app connector and Copilot agent protection.

==============================================================


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel