Microsoft · Free Practice Questions · Last reviewed May 2026
30real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
24% of exam · 6 sample questions below
A company uses Azure SQL Database with Transparent Data Encryption (TDE) protected by a customer-managed key (CMK) stored in Azure Key Vault. The Key Vault has a firewall enabled that denies all public network access. The SQL server is in the same region and has a system-assigned managed identity with the 'Key Vault Crypto Service Encryption User' role assigned at the key scope. However, TDE operations fail because the SQL server cannot access the Key Vault. What additional configuration is required to allow the SQL server to access the Key Vault for TDE operations?
Configure a private endpoint for the SQL server to the Key Vault.
Enable the 'Allow trusted Microsoft services to bypass the firewall' setting on the Key Vault.
This setting allows trusted Azure services, including Azure SQL Database, to access the Key Vault even when the firewall is enabled. Since the SQL server's managed identity already has the cryptographic role, this is the missing piece to allow TDE operations.
Change the Key Vault firewall to allow all Azure services.
Create a VNet service endpoint for Microsoft.KeyVault on the SQL server's subnet.
A company stores sensitive files in Azure Files shares. They require encryption at rest using customer-managed keys (CMK) and encryption in transit using SMB 3.0 encryption. They have created a premium Azure Files share in a storage account and configured encryption at rest with a CMK. However, clients are able to connect without enforcing SMB encryption. What additional configuration is necessary to ensure that all connections to the file share are encrypted in transit?
Enable the 'Secure transfer required' property on the storage account.
Enabling the storage account's 'Secure transfer required' property rejects requests over unencrypted connections. For Azure Files, this forces clients to use SMB 3.0 with encryption (or HTTPS for REST), so sensitive data is encrypted while traversing the network. This is the proper, supported control for enforcing encryption in transit for Azure Files.
Configure a network security group (NSG) to allow only encrypted traffic.
Set the minimum SMB protocol version to 3.0 on the file share.
Create a service endpoint for the storage account.
A company uses Azure SQL Database with Transparent Data Encryption (TDE) and wants to use a customer-managed key (CMK) stored in Azure Key Vault. The security policy requires that the Key Vault be protected by a firewall and virtual network service endpoints to restrict network access. The storage account for TDE logs is in the same Azure region. Which additional configuration is necessary in the Key Vault to allow Azure SQL Database to access the CMK for encryption operations?
Add a network rule in the Key Vault firewall allowing the public IP range of the Azure SQL Database server.
Enable the 'Allow trusted Microsoft services to bypass this firewall' option in the Key Vault networking settings.
Enabling 'Allow trusted Microsoft services to bypass this firewall' is the correct solution because Azure SQL Database is a trusted Microsoft service and its managed identity can authenticate to the Key Vault using Microsoft Entra ID, then fetch the encryption key for TDE. With this setting, the Key Vault firewall remains enabled for public internet traffic, but Azure services like SQL Database are permitted to bypass the IP restrictions. This is the intended pattern for TDE with customer-managed keys, as SQL Database runs outside your virtual network and its outbound IPs cannot be reliably scoped.
Create a private endpoint for the Key Vault and connect it to the same virtual network as the Azure SQL Database.
Configure the Key Vault to use role-based access control (RBAC) and assign the 'Key Vault Crypto Service Encryption User' role to the SQL Database server's managed identity.
A company uses Azure Disk Encryption (ADE) on Windows virtual machines. They use a key encryption key (KEK) stored in Azure Key Vault to wrap the disk encryption key. The security policy requires that the KEK be automatically rotated every 90 days. They need to ensure that after rotation, the OS and data disks of running VMs automatically get re-wrapped with the new KEK version. Which configuration should they implement?
Enable soft-delete and purge protection on the Key Vault.
Use Key Vault key auto-rotation with a 90-day rotation period, and configure the disk encryption set to use the latest key version (empty string).
Key Vault key auto-rotation creates new key versions on schedule. By setting the key version to empty in the disk encryption set, the VMs automatically re-wrap their disks with the latest key version after rotation.
Create a new KEK every 90 days and modify the disk encryption set to point to the new key version.
Use Azure Policy to enforce automatic key rotation.
An Azure Storage account is configured with server-side encryption (SSE) using a customer-managed key stored in Azure Key Vault. The security team requires that the storage account's identity be used to authenticate to the key vault for key access. Additionally, they want the identity to be automatically deleted when the storage account is deleted. Which type of identity should they assign to the storage account?
System-assigned managed identity
A system-assigned managed identity is created directly on the storage account and shares its lifecycle: when enabled, Microsoft Entra ID automatically provisions a corresponding service principal for the account, and when the storage account is deleted, the identity is removed automatically. It requires no application ID, client secret, or certificate rotation, so it meets both requirements of credential-free authentication and automatic cleanup. The storage account can use this identity to authenticate to Azure Key Vault for customer-managed key operations.
User-assigned managed identity
Service principal
Microsoft Entra ID user account
A company uses Azure SQL Database with Transparent Data Encryption (TDE) using a customer-managed key (CMK) stored in Azure Key Vault. The Key Vault has a firewall enabled that denies all public network access. The SQL server has a system-assigned managed identity assigned the 'Key Vault Crypto Service Encryption User' role. However, TDE operations are failing because the SQL server cannot access the Key Vault. What additional configuration is needed?
Enable the Key Vault firewall to allow trusted Microsoft services
Azure SQL Database TDE with customer-managed keys requires SQL to access Key Vault for key wrap and unwrap operations. The Key Vault firewall blocks public access, but the 'Allow trusted Microsoft services' exception lets Azure SQL's underlying service bypass the firewall for these cryptographic operations, using the SQL server's managed identity. This is the only network change needed while keeping public access blocked.
Create a private endpoint for the SQL server to access the Key Vault
Enable public network access on the Key Vault
Assign the SQL server's managed identity the 'Reader' role on the Key Vault
Want more Secure compute, storage, and databases practice?
Practice this domain34% of exam · 6 sample questions below
A company uses Microsoft Defender for Cloud to manage the security posture of multiple Azure subscriptions. The security team wants to ensure that all subscriptions are covered by the same Microsoft Defender for Cloud policy initiative, but one subscription is not showing compliance data. The subscription is in the same Microsoft Entra ID tenant and has the same tags. What is the most likely cause?
The user does not have Security Admin permissions on the subscription.
The subscription does not have any tags applied.
The subscription does not have the default policy initiative assigned.
The subscription is not registered with the Microsoft.Security resource provider.
For Defender for Cloud to assess a subscription, the Microsoft.Security resource provider must be registered at the subscription level, as this registration is what allows the service to query Azure Resource Manager for resource metadata and configuration. When the provider is unregistered, Defender for Cloud cannot perform any resource discovery, so no security recommendations, regulatory compliance controls, or secure score data are generated for that subscription. Registration is typically performed automatically when a user first opens Defender for Cloud in the portal, but it can also be done programmatically via Azure CLI (`az provider register --namespace Microsoft.Security`) or PowerShell. An unregistered provider explains both the absence of data and why the user perceives that security posture is completely missing.
Your company uses Microsoft Sentinel to monitor security events. You need to detect brute-force attacks against Azure VMs that are not yet onboarded to Sentinel. What should you do?
Use the Office 365 connector to collect sign-in logs.
Use the Windows Security Events connector via Azure Monitor Agent.
The Windows Security Events connector using the Azure Monitor Agent (AMA) is the correct choice because it collects Windows Event Log entries, including security events such as successful and failed logon attempts (Event IDs 4624, 4625) from Azure VMs. AMA is configured with a data collection rule (DCR) that specifies which event IDs to send to the Log Analytics workspace where Microsoft Sentinel can analyze them. This is exactly the native, supported path for OS-level sign-in monitoring on Windows virtual machines.
Use the Common Event Format connector to forward syslog.
Use the Azure Activity connector to collect sign-in logs.
A security team uses Microsoft Defender for Cloud's regulatory compliance dashboard to track compliance with PCI DSS. They notice that some controls are marked as 'N/A' even though they have relevant resources. What is the most likely reason?
The resources do not have the required custom assessment.
The compliance dashboard requires a Microsoft Purview Compliance Manager license.
The resources are in a subscription that is not included in the scope of the compliance standard.
In Defender for Cloud, each regulatory compliance standard is assigned to a specific scope, such as a subscription or management group, when you enable it. Only resources within that assigned scope are evaluated and reported in the compliance dashboard, and resources in unassigned subscriptions are completely ignored. If the subscription containing the resources is not part of the standard's assignment, those resources will not appear in the compliance view.
The resources have not been manually claimed as compliant.
You are configuring Microsoft Sentinel to ingest logs from Microsoft Entra ID. Which two data connectors are necessary to collect sign-in logs and audit logs?
Azure Activity and Microsoft Entra ID Audit logs
Office 365 and Microsoft Entra ID Sign-in logs
Microsoft Entra ID Sign-in logs and Microsoft Entra ID Audit logs
Microsoft Entra ID Sign-in Logs ingest authentication and authorization events, such as successful and failed user sign-ins, conditional access results, and MFA challenges. Microsoft Entra ID Audit Logs capture all directory-management activities, including user creation, group membership changes, password resets, and application role assignments. These two complementary connectors provide the full AAD security telemetry needed to monitor both user access and administrative changes in Microsoft Sentinel.
Security Events and Microsoft Entra ID Sign-in logs
Refer to the exhibit. A security analyst runs this KQL query in Microsoft Sentinel. What is the purpose of this query?
To list all alerts with severity 'High' in the last 7 days.
To list the top 10 most frequent alert names along with their severity over the last 7 days.
The query groups alert records by AlertName and Severity using summarize, counts the occurrences in each combination, and applies top to rank those combinations descending by count. This returns the ten most frequent alert-name/severity pairs over the rolling 7-day window, which precisely matches the stated purpose. The inclusion of both fields in the grouping key is essential to the output.
To list all alerts generated in the last 7 days.
To list the count of alerts per severity for the last 7 days.
Refer to the exhibit. This is an excerpt from an Azure Policy assignment. What is the effect of the 'notScopes' property?
The policy will apply only to the VM-Sensitive virtual machine.
The policy will apply to all resources in RG-Prod except the entire resource group.
The policy will apply to all resources in RG-Prod except the VM-Sensitive virtual machine.
The assignment's scope is RG-Prod, making every contained resource subject to policy evaluation. The notScopes array specifies the VM-Sensitive virtual machine resource ID, so that VM alone is excluded from compliance evaluation. All other resources, regardless of type, remain within the assignment's scope and are evaluated.
The policy will apply to the subscription but not to RG-Prod.
Want more Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel practice?
Practice this domain9% of exam · 6 sample questions below
Your organization uses Microsoft Entra ID for identity management. You need to ensure that users can sign in using a one-time passcode sent to their mobile device, without requiring any additional app or software installation. Which authentication method should you enable?
One-time passcode (OTP)
One-time passcode (OTP) is a built-in Microsoft Entra ID authentication method that sends a verification code to a user's verified email or phone number via SMS or email. It requires no additional app installation, hardware token, or certificate infrastructure, making it the simplest way to authenticate a user without a password. The code is time-limited and used once, providing a low-friction option for temporary or initial sign-in scenarios.
Microsoft Authenticator app
FIDO2 security keys
Certificate-based authentication
You are configuring a conditional access policy to block access from untrusted locations. The policy should apply to all cloud apps except Microsoft Entra ID Administration. How should you configure the policy?
Include 'All cloud apps' and set 'Block access'
Include 'Select apps' and choose all apps except admin
Include 'All cloud apps' and exclude 'Microsoft Entra ID Administration'
Conditional access evaluates include and exclude scopes, with exclusions taking precedence. Selecting 'All cloud apps' as the include and excluding 'Microsoft Entra ID Administration' satisfies the requirement to block untrusted locations everywhere except administrative access, avoiding the need to enumerate every individual app.
Include 'All cloud apps' and exclude 'Office 365'
Your organization uses Microsoft Entra ID to manage access for employees and partners. You need to implement a solution that allows partners to self-service request access to specific applications, with approval from their manager, and access expires after 30 days. Which feature should you use?
Entitlement Management access packages
Entitlement Management access packages are the correct choice because they are specifically designed to govern end-user access to resources such as groups, applications, and SharePoint sites. These packages bundle resources with configurable policies for request approval, recurring access reviews, expiration, and automatic revocation when the policy ends. This enables self-service access requests while maintaining an auditable lifecycle for both internal and external users.
Microsoft Entra B2B collaboration
Privileged Identity Management (PIM)
Conditional Access with session restrictions
You are troubleshooting why a user cannot sign in to a custom line-of-business application that is federated with Microsoft Entra ID. The user reports that they are repeatedly prompted for credentials and then receive an error. The application is configured for SAML-based SSO. What is the most likely cause?
The user's browser cookies are disabled
The application is not registered in the app gallery
The SAML certificate has expired or the configuration has a mismatch
SAML certificates are used to sign the SAML response; the service provider uses the certificate's public key to validate the signature. If the certificate has expired or the configured certificate doesn't match the one trusted by the application, the SP will discard the assertion and deny sign-in. Likewise, a mismatch in the SAML configuration (e.g., Entity ID, Reply URL, or signing algorithm) will cause authentication failures even when the certificate is valid.
The user does not have a license for Microsoft Entra ID
Which TWO of the following are valid configurations for Microsoft Entra ID Conditional Access policies?
Include all users and exclude specific groups
This is a valid user-and-group assignment in a Conditional Access policy. Selecting All users scopes the policy to every account in the tenant, while the Exclude tab lets you remove specific security groups such as break-glass emergency access accounts. This is the standard way to blanket-apply a policy while preserving administrative exceptions.
Force password change on next sign-in
Target a specific cloud application
Targeting a specific cloud application is a valid Conditional Access assignment. In the Target resources step you can select single applications such as Exchange Online, SharePoint, or an Entra ID-integrated SaaS app, which restricts the policy to sign-ins for those apps only. This is one of the core assignment groups: users, cloud apps, and conditions.
Block access for users without MFA registered
Assign licenses to users based on location
Which TWO of the following are authentication methods supported by Microsoft Entra ID?
Certificate-based authentication (CBA)
Certificate-based authentication (CBA) leverages X.509 digital certificates issued by a trusted certification authority to verify a user's identity. In Microsoft Entra ID, this method is supported for federated domains, where the certificate is used to authenticate against the identity provider instead of a password. It offers strong, phishing-resistant protection and is distinct from the physical smart card interaction, which is not natively supported.
Security questions
Smart card with PIN
OAuth 2.0 authorization code flow
SMS-based one-time passcode
SMS-based one-time passcode (OTP) is a supported authentication method in Microsoft Entra ID, where a short-lived verification code is sent by text message to a registered phone number and must be entered during sign-in. It can satisfy multi-factor authentication or act as a passwordless option in certain configurations. SMS OTP is convenient but less secure than certificate-based methods due to risks of SMS interception or SIM swapping.
Want more Secure identity and access practice?
Practice this domain9% of exam · 6 sample questions below
A company uses Microsoft Entra ID Protection. They want to automatically block sign-ins that have a high user risk level, but only for users in the 'Finance' department. They also want to require MFA for medium user risk level for all users (including Finance) when sign-in risk is not blocked. They have already created a Conditional Access policy for the Finance department that has a condition of 'User risk level: High' and a grant control of 'Block access'. What additional configuration is needed to also require MFA for all users with medium user risk?
Create a second Conditional Access policy targeting all users with condition 'User risk level: Medium' and grant control 'Require multi-factor authentication'
A separate policy for medium user risk applied to all users will require MFA when medium risk is detected. The existing policy will continue to block Finance users with high risk. Policy evaluation is not mutually exclusive; the block takes precedence for high risk, and the MFA requirement applies for medium risk.
Modify the existing policy to include 'User risk level: Medium' and change the grant control to 'Require multi-factor authentication'
Use Identity Protection's 'User risk policy' instead of Conditional Access
Create a new Conditional Access policy with condition 'User risk level: Medium' and grant control 'Block access'
A company uses Microsoft Entra Privileged Identity Management (PIM) to manage access to Microsoft Entra ID roles. They want to require that users who activate the Global Administrator role must get approval from their manager before activation, and that the approval must be time-bound (maximum 8 hours). Which two PIM configurations should they set?
Set the activation maximum duration to 8 hours.
Setting the activation maximum duration to 8 hours in Microsoft Entra PIM enforces a strict time-bound on any privileged role activation. This ensures that a user cannot remain in the role indefinitely; after the configured duration, the role assignment automatically expires and reverts to eligible state. Since 8 hours is the maximum allowed activation duration for Microsoft Entra ID roles, this directly satisfies the requirement that privileged access be temporary and bounded by a specific time limit.
Enable approval workflow by adding the manager as an approver.
Enabling the approval workflow and configuring the user's manager as an approver requires every activation request to be explicitly reviewed and approved by that manager before the role becomes active. This satisfies the approval requirement by adding a mandatory human control point, ensuring that privileged access is granted on-demand only after proper authorization. The approver can evaluate the request context, including the provided justification, before granting access.
Require multi-factor authentication on activation.
Require justification on activation.
A company uses Microsoft Entra Privileged Identity Management (PIM) to manage the Global Administrator role. They want to require that when a user activates the role, they must be using a device that is compliant with Intune policies (e.g., compliant device) and must provide a justification. The company already has Conditional Access policies in place for regular access. How should they enforce the device compliance requirement specifically during PIM activation?
Configure a Conditional Access policy that targets the 'Microsoft Entra Privileged Identity Management' cloud app, requiring compliant device.
In PIM settings for the Global Administrator role, enable 'Require Multi-Factor Authentication on activation'.
In PIM settings for the Global Administrator role, enable 'Require Microsoft Entra Conditional Access authentication context' and create a Conditional Access policy that requires compliant device when that authentication context is used.
This is the correct approach because PIM supports emitting an Microsoft Entra Conditional Access authentication context during role activation. When you enable 'Require Microsoft Entra Conditional Access authentication context' in PIM settings, Microsoft Entra ID sends that context as a signal to Conditional Access for the activation request. A separate Conditional Access policy can then target that authentication context and apply the 'Require device to be marked as compliant' grant control. This is the documented integration pattern for combining PIM with device-compliance policies, and it satisfies the requirement without relying on unsupported targets like the PIM app itself.
Use Microsoft Entra ID Protection's user risk policy to require device compliance when a high-risk user activates the role.
A company has a partner organization in another Microsoft Entra ID tenant. They want to allow users from the partner tenant to access their Azure resources through Microsoft Entra B2B collaboration. They also want the partner's Multi-Factor Authentication (MFA) claims to be trusted when partner users access their resources, so that they do not need to perform MFA again. Which configuration in cross-tenant access settings should they enable?
Trust multi-factor authentication from the partner tenant (inbound trust).
This setting, located in the partner tenant's cross-tenant access settings under 'Inbound access' > 'Trust settings', instructs your Microsoft Entra ID to accept the multi-factor authentication (MFA) claims already performed in the partner tenant. When enabled, B2B collaboration users from that tenant are not prompted for MFA again in your tenant, provided their home tenant has satisfied MFA. This is the correct mechanism to avoid redundant authentication prompts.
Trust device compliance from the partner tenant.
Enable a Conditional Access policy that grants access to the partner tenant.
Configure identity synchronization with the partner tenant.
A company has an on-premises web application that they want to expose to external users over the internet without requiring a VPN. External users must authenticate with Modern Authentication (e.g., using Azure Multi-Factor Authentication) and access policies must be enforced via Conditional Access. The application does not support SAML or OAuth. Which Azure service should they use to publish this application securely?
Azure AD B2C (Business-to-Consumer).
Azure Application Gateway with Web Application Firewall (WAF).
Microsoft Entra application proxy.
Microsoft Entra application proxy is the appropriate service here because it is purpose-built to publish on-premises HTTP/HTTPS apps to external users through Microsoft Entra ID. A lightweight connector installed on the corporate network establishes an outbound connection to the Microsoft Entra application proxy service, eliminating the need for inbound firewall ports or a VPN; the external endpoint is an Microsoft Entra ID URL that performs full Microsoft Entra ID pre-authentication, including MFA and Conditional Access, before passing the authenticated request back through the connector to the internal web application. It effectively acts as an HTTPS reverse proxy bridged by an outbound-only tunnel, which is exactly what is required to securely expose an on-premises web app without making it publicly reachable.
Azure Front Door.
A company uses Microsoft Entra ID Protection and Conditional Access. A user is detected with a 'High' user risk level due to suspicious activity. The security team wants to automatically block sign-ins for this user, but only when the sign-in originates from a location that is not in the company's list of trusted IPs. They have created a Conditional Access policy targeting all users. Which configuration should they add to the policy to achieve this?
Add a condition for 'User risk' set to 'High', and a condition for 'Sign-in risk' set to 'High', then grant 'Block access'.
Add a condition for 'User risk' set to 'High' and exclude 'All trusted locations' under the 'Locations' condition, then grant 'Block access'.
This is correct because it combines the specific condition—User risk High—with a location exclusion for all trusted IP ranges, ensuring the block only applies to sign-ins that originate from untrusted locations. Conditional Access evaluates the user risk condition and the location condition together, and with the grant control set to Block access, any matching sign-in is denied. This matches the requirement precisely: only high user risk accounts attempting sign-in from outside the corporate network are blocked.
Add a condition for 'User risk' set to 'High', and under 'Grant', select 'Require multi-factor authentication' and 'Block access'.
Add a condition for 'Locations' set to 'Any location' and under 'Grant', select 'Block access' for all users.
Want more Manage identity and access practice?
Practice this domainYour company has an Azure subscription with a hub-spoke network topology. The hub contains an Azure Firewall and a VPN gateway for on-premises connectivity. The spoke virtual network hosts a critical application. You need to ensure that all outbound traffic from the spoke to the internet and on-premises networks flows through the Azure Firewall. You configure a user-defined route (UDR) on the spoke subnet with the default route (0.0.0.0/0) pointing to the Azure Firewall private IP. However, traffic to on-premises still bypasses the firewall. What is the most likely cause?
The on-premises traffic uses a more specific route learned via BGP from the VPN gateway, which overrides the UDR
BGP-learned routes for on-premises networks are more specific than 0.0.0.0/0. They will be used even if a UDR for 0.0.0.0/0 exists. To force through firewall, you must either disable BGP route propagation or create specific UDRs for on-premises ranges.
The UDR must be applied to the subnet that hosts the Azure Firewall
The spoke subnet does not have 'GatewaySubnet' route propagation enabled
The Azure Firewall is not configured with a route to the on-premises network
A company has a hub-spoke network topology with Azure Firewall deployed in the hub virtual network. Spoke virtual networks are peered to the hub. The security team needs to ensure that all outbound internet traffic from virtual machines in a spoke subnet goes through the Azure Firewall. They have configured a route table on the spoke subnet with a default route (0.0.0.0/0) pointing to the Azure Firewall private IP address. However, traffic from spoke VMs is still bypassing the firewall and going directly to the internet. What is the most likely reason?
The route table is not associated with the spoke subnet.
A route table only takes effect when it is explicitly associated with a subnet. In this hub-spoke topology, the spoke subnet still has the default system routes, so traffic destined for the internet follows the default route and bypasses Azure Firewall. You must associate the custom route table—with a UDR that uses the firewall's private IP as the next hop and next hop type 'VirtualAppliance'—to the spoke subnet for forced tunneling to work.
Azure Firewall is not configured with DNAT rules for outbound traffic.
The spoke VNet peering does not allow gateway transit.
The route table has a higher priority than system routes.
A company has two Azure virtual networks, VNet-A and VNet-B, connected via VNet peering. They want all traffic between the VNets to be inspected by a network virtual appliance (NVA) deployed in a subnet in VNet-A. They have configured a user-defined route (UDR) on the subnet in VNet-B that points the destination address space of VNet-A to the private IP of the NVA. However, traffic between the VNets is still not passing through the NVA. What is the most likely cause?
The UDR is not associated with the subnet in VNet-B.
The NVA's network interface (NIC) does not have IP forwarding enabled.
IP forwarding must be explicitly enabled on the network interface (NIC) of the NVA before Azure will deliver packets whose destination IP is not assigned to that NIC. Without it, the Azure fabric drops packets that are addressed to other IPs, so even if the NVA's operating system is configured to route traffic, the packets never reach it. This is the most common omission when deploying NVAs with UDRs, and it precisely explains why traffic flows end-to-end via peering but not through the NVA — the NVA silently discards (or never receives) the forwarded packets.
The VNet peering connection is not in a 'Connected' state.
The NVA is deployed in the same subnet as the source VMs.
A company is designing a hub-spoke network topology with Azure Firewall in the hub virtual network. Spoke virtual networks are peered to the hub. They want to ensure that all outbound internet traffic from virtual machines in a spoke subnet goes through the Azure Firewall. They have configured a route table on the spoke subnet with a default route (0.0.0.0/0) pointing to the Azure Firewall's private IP address as the next hop. However, traffic is still bypassing the firewall. What is the most likely cause?
The Azure Firewall is in a different region than the spoke VNet.
The route table is not associated to the spoke subnet.
A user-defined route table only takes effect when it is explicitly associated with a subnet; simply creating a route table and adding a route to the firewall's private IP does nothing otherwise. Without that association, the subnet uses Azure's default system routes, which send traffic between peered VNets directly, bypassing the firewall entirely. This is the classic cause of 'spoke traffic isn't going through the firewall' when the routes appear to be configured correctly.
The Azure Firewall does not have the correct network and application rules configured.
The spoke VNet has the 'Use remote virtual network gateways' setting disabled.
A company has an Azure virtual network with a subnet that hosts a web application. They need to allow inbound HTTP (port 80) and HTTPS (port 443) traffic from a specific source IP range (203.0.113.0/24) to the web servers. Additionally, they need to allow inbound RDP (port 3389) traffic from a management subnet (10.0.1.0/24). They want to block all other inbound traffic. They are using a network security group (NSG) associated with the subnet. What is the minimum number of inbound security rules required?
3
You need exactly three inbound allow rules: one for HTTP (destination port 80), one for HTTPS (destination port 443), and one for RDP (destination port 3389), each scoped to the appropriate source address prefix. Azure NSGs include a default inbound deny rule, so any traffic not explicitly allowed by these three rules is automatically blocked. This satisfies the requirement with the minimum number of rules while preserving least privilege.
4
5
2
A company has an Azure SQL Database with a private endpoint connection. The database is accessed from on-premises via ExpressRoute and from other Azure virtual networks (VNets) via VNet peering. The security team wants to ensure that all queries from both on-premises and peered VNets go through the private endpoint and NEVER use the public endpoint, even as a fallback. Which additional configuration is required to enforce this?
Configure a Network Security Group (NSG) on the subnet hosting the private endpoint to deny outbound traffic to the public endpoint's IP addresses.
Enable Azure SQL Auditing and configure a log analytics workspace to monitor for public endpoint calls, then manually block them.
Disable public network access on the Azure SQL server.
Correct. Disabling public network access on the SQL server blocks all traffic from the public internet, leaving only the private endpoint as the entry point. This ensures all traffic from on-premises and peered VNets must use the private endpoint.
Configure a service endpoint for Azure SQL on the VNet and associate a firewall rule allowing only the VNet traffic.
Want more Secure networking practice?
Practice this domainThe AZ-500 exam has 50 questions and must be completed in 120 minutes. The passing score is 700/1000.
Security scenario questions covering Microsoft Entra ID, Defender for Cloud, Azure Key Vault, and application and data security. Some questions are performance-based (PBQs), asking you to complete tasks in a simulated environment.
The exam covers 5 domains: Secure compute, storage, and databases, Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel, Secure identity and access, Manage identity and access, Secure networking. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Microsoft AZ-500 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.