AZ-500Free Study Guide

Microsoft Azure Security Engineer Associate AZ-500The Complete Beginner's Guide

Complete AZ-500 study guide — identity, compute, storage, networking security, and security operations on Azure.

103 chapters
~43 hours total read
Free — no signup required

How to use this guide

This guide works best as a loop: read a chapter, test yourself with practice questions, look up unfamiliar terms in the glossary, then move to the next chapter.

① Read a chapter② Answer practice questions③ Review missed answers④ Repeat
Study Chapters

103 chapters covering every exam objective. Each chapter includes key concepts, exam tips, common traps, comparison tables, and a 5-question quiz at the end.

Start Chapter 1
Practice Questions

Free timed and untimed practice with instant feedback and full explanations. Pick 10–120 questions per session. Filter by domain to drill your weak areas.

Go to practice test
Glossary

Every AZ-500term defined and searchable. Use it when a chapter mentions a concept you haven't seen before or want a quick refresher on.

Browse glossary
Exam Overview

Exam blueprint, domain weights, passing score, duration, cost, and registration links. Start here if you're new to this certification.

View exam guide

Manage Identity and Access (25–30%)

22 chapters

Domain overview
1

Securing Microsoft Entra ID

Objective 1.1 · Identity Access

25m
2

Privileged Identity Management (PIM)

Objective 1.2 · Identity Access

25m
3

Managed Identities for Azure Resources

Objective 1.3 · Identity Access

25m
4

Conditional Access Policies

Objective 1.4 · Identity Access

25m
17

Just-In-Time (JIT) VM Access

Objective 1.2 · Identity Access

25m
36

Managed Identities vs Service Principals

Objective 1.3 · Identity Access

25m
37

Privileged Identity Management for AZ-500

Objective 1.2 · Identity Access

25m
38

Access Reviews and Governance

Objective 1.4 · Identity Access

25m
40

Zero Trust Architecture in Azure

Objective 1.4 · Identity Access

25m
41

Microsoft Entra Identity Protection

Objective 1.4 · Identity Access

25m
42

Workload Identity and Federated Credentials

Objective 1.3 · Identity Access

25m
43

App Registrations and Service Principals

Objective 1.3 · Identity Access

25m
83

Subscription Security and Management Group Policy

Objective 1.4 · Identity Access

25m
84

Entra ID Named Locations and Conditional Access

Objective 1.4 · Identity Access

25m
87

Azure Lighthouse for Managed Security Services

Objective 1.2 · Identity Access

25m
88

Guest User Policies and External Collaboration

Objective 1.1 · Identity Access

25m
89

Entra ID Built-In Directory Roles

Objective 1.1 · Identity Access

25m
91

Azure RBAC Role Assignments at Scale

Objective 1.1 · Identity Access

25m
92

Custom RBAC Roles in Azure

Objective 1.1 · Identity Access

25m
95

Microsoft Entra External ID Security

Objective 1.1 · Identity Access

25m
100

OAuth 2.0 and OpenID Connect in Azure

Objective 1.1 · Identity Access

25m
103

Microsoft Entra Identity Secure Score

Objective 1.4 · Identity Access

25m

Secure Compute, Storage, and Databases (20–25%)

25 chapters

Domain overview
5

Azure VM Security

Objective 2.1 · Compute Security

25m
6

Container Registry and AKS Security

Objective 2.2 · Compute Security

25m
7

Azure Storage Security

Objective 2.4 · Compute Security

25m
8

Azure SQL Database Security

Objective 2.5 · Compute Security

25m
16

Azure Key Vault

Objective 2.3 · Compute Security

25m
24

Encryption at Rest in Azure

Objective 2.3 · Compute Security

25m
25

Encryption in Transit: TLS and HTTPS

Objective 2.3 · Compute Security

25m
32

Shared Access Signatures (SAS) for Storage

Objective 2.4 · Compute Security

25m
33

Azure SQL Auditing and Advanced Threat Protection

Objective 2.5 · Compute Security

25m
39

Customer-Managed Keys (CMK) in Key Vault

Objective 2.3 · Compute Security

25m
44

Azure Disk Encryption with Azure Key Vault

Objective 2.1 · Compute Security

25m
48

Azure Container Security Best Practices

Objective 2.2 · Compute Security

25m
49

AKS Security: RBAC, Network Policies, Pod Identity

Objective 2.2 · Compute Security

25m
50

App Service Security and Authentication

Objective 2.1 · Compute Security

25m
51

Cognitive Services and AI Security

Objective 2.5 · Compute Security

25m
52

Azure SQL Advanced Threat Protection

Objective 2.5 · Compute Security

25m
53

Dynamic and Static Data Masking in Azure SQL

Objective 2.5 · Compute Security

25m
54

TDE with Customer-Managed Keys in Key Vault

Objective 2.3 · Compute Security

25m
55

Key Vault Access Policies vs RBAC

Objective 2.3 · Compute Security

25m
56

Key Vault Soft Delete and Purge Protection

Objective 2.3 · Compute Security

25m
57

Key Vault Firewall and Private Endpoint

Objective 2.3 · Compute Security

25m
73

Container Registry Security Scanning

Objective 2.2 · Compute Security

25m
75

Azure Managed HSM vs Key Vault Standard

Objective 2.3 · Compute Security

25m
80

Storage Threat Detection and Defender for Storage

Objective 2.4 · Compute Security

25m
101

Azure Functions Security

Objective 2.1 · Compute Security

25m

Secure Networking (15–20%)

17 chapters

Domain overview

Manage Security Operations (25–30%)

39 chapters

Domain overview
12

Microsoft Defender for Cloud

Objective 4.1 · Security Operations

25m
13

Microsoft Sentinel SIEM

Objective 4.2 · Security Operations

25m
14

Security Policies and Benchmarks

Objective 4.3 · Security Operations

25m
15

Incident Response in Azure

Objective 4.4 · Security Operations

25m
18

Azure Policy for Security Compliance

Objective 4.3 · Security Operations

25m
19

Azure Blueprints for Regulatory Compliance

Objective 4.3 · Security Operations

25m
26

Microsoft Defender for Servers

Objective 4.1 · Security Operations

25m
27

Microsoft Defender for SQL

Objective 4.1 · Security Operations

25m
28

Microsoft Defender for Containers and AKS

Objective 4.1 · Security Operations

25m
29

Log Analytics Workspace for Security

Objective 4.2 · Security Operations

25m
30

Microsoft Cloud Security Benchmark

Objective 4.3 · Security Operations

25m
31

Regulatory Compliance Dashboard in Defender

Objective 4.3 · Security Operations

25m
45

Microsoft Defender for Endpoint Integration

Objective 4.1 · Security Operations

25m
46

Microsoft Defender for Identity

Objective 4.1 · Security Operations

25m
47

Microsoft Defender for Cloud Apps (MCAS)

Objective 4.1 · Security Operations

25m
61

Sentinel Analytics Rules and Incidents

Objective 4.2 · Security Operations

25m
62

Sentinel Playbooks and Logic Apps Automation

Objective 4.2 · Security Operations

25m
63

KQL Queries for Security Operations

Objective 4.2 · Security Operations

25m
64

UEBA in Microsoft Sentinel

Objective 4.2 · Security Operations

25m
65

Threat Hunting in Microsoft Sentinel

Objective 4.2 · Security Operations

25m
66

MITRE ATT&CK Mapping in Defender

Objective 4.2 · Security Operations

25m
67

Security Alerts and Smart Alert Groups

Objective 4.1 · Security Operations

25m
68

Microsoft Defender for DevOps

Objective 4.1 · Security Operations

25m
69

Securing GitHub Actions Pipelines

Objective 4.1 · Security Operations

25m
70

Azure DevOps Security Controls

Objective 4.1 · Security Operations

25m
71

Azure Policy Exemptions and Compliance Scoring

Objective 4.3 · Security Operations

25m
72

Defender for APIs

Objective 4.1 · Security Operations

25m
74

Software Supply Chain Security on Azure

Objective 4.1 · Security Operations

25m
78

Azure Policy Effects: Deny, Audit, DeployIfNotExists

Objective 4.3 · Security Operations

25m
79

Microsoft Secure Score Strategy

Objective 4.3 · Security Operations

25m
81

Sentinel Security Workbooks and Dashboards

Objective 4.2 · Security Operations

25m
82

Log Analytics Workspace Design for Security

Objective 4.2 · Security Operations

25m
85

NIST, CIS, PCI-DSS Compliance in Azure

Objective 4.3 · Security Operations

25m
86

Defender for Cloud Attack Path Analysis

Objective 4.1 · Security Operations

25m
90

Entra ID Audit Logs and Sign-In Logs

Objective 4.2 · Security Operations

25m
93

Defender for Cloud Alert Rules and Suppression

Objective 4.1 · Security Operations

25m
97

Sentinel Threat Maps and Security Dashboards

Objective 4.2 · Security Operations

25m
99

Policy as Code with Bicep and Terraform

Objective 4.3 · Security Operations

25m
102

Azure Monitor Diagnostic Settings for Security

Objective 4.2 · Security Operations

25m

Ready to test your knowledge?

Free AZ-500 practice questions with full explanations. Test what you learn chapter by chapter.

AZ-500 Practice Questions