Sample questions
Microsoft Azure Security Engineer Associate AZ-500 practice questions
Which THREE capabilities are provided by Azure Storage Service Encryption (SSE) when using customer-managed keys?
A team wants to automatically deploy Defender for Cloud settings across new subscriptions under a management group. Which Azure capability should they use?
Refer to the exhibit. You have an Azure Application Gateway WAF policy with the above JSON configuration. A user from IP address 10.1.2.3 reports they cannot access the web applica…
Which TWO of the following are valid authentication methods in Microsoft Entra ID?
A storage account should be reachable only from a specific subnet over the Microsoft backbone, while keeping the public endpoint firewall restricted. Which feature should be used?
A company uses Azure SQL Database for a critical application. Security policy requires that all client connections to the database use at least TLS 1.2 encryption. What configurati…
You are deploying a web application that stores user-uploaded files in Azure Blob Storage. You need to ensure that only authenticated users can upload files, and that uploaded file…
Which TWO actions should you take to implement a zero-trust identity model using Microsoft Entra ID? (Choose two.)
A company uses Microsoft Sentinel as its SIEM. The security team wants to automatically respond to phishing emails detected by Microsoft Defender XDR. They want to create a playboo…
Secure Azure using Microsoft Defender for Cloud and Microsoft SentinelmediumSee the answer and why each option is right or wrong →You are designing a privileged identity management strategy for Microsoft Entra ID. You need to ensure that eligible role assignments require approval from a designated group befor…
A security analyst uses Microsoft Defender for Cloud. They need to assess their Azure environment's compliance against the Payment Card Industry Data Security Standard (PCI DSS). W…
Which TWO actions should you take to secure a virtual network in Azure? (Choose two.)
A company wants to ensure that users can only access Microsoft 365 services (e.g., Exchange Online, SharePoint Online) from devices that are confirmed to be compliant with corporat…
A Conditional Access policy requiring compliant devices does not apply to Azure PowerShell access. Sign-in logs show the cloud app is excluded. What should be changed?
A Defender for Cloud secure score recommendation says storage accounts allow public blob access. What remediation best addresses the root issue?
Which TWO of the following are valid configurations for Microsoft Entra ID Conditional Access policies?
You are reviewing an Azure Resource Manager template for a storage account. The exhibit shows a snippet of the template. Which statement about the template is true?
You are designing a backup strategy for Azure virtual machines. You need to ensure that backups are encrypted at rest and can be restored in a different Azure region in case of a r…
A company deploys Azure Firewall to inspect and control outbound traffic from a virtual network. The security team wants to allow outbound HTTPS traffic only to specific FQDNs such…
A company has two application tiers: web servers and application servers. They want to allow traffic from the web servers to the application servers on port 8080, but only for a sp…
An organization is required to comply with the Health Insurance Portability and Accountability Act (HIPAA). They use Microsoft Defender for Cloud to manage their Azure security pos…
You need to ensure that external users who are invited to your Microsoft Entra ID tenant via B2B collaboration can only access a specific SaaS application. What should you configur…
Your organization uses Microsoft Entra ID for identity management. You need to ensure that users can sign in using a one-time passcode sent to their mobile device, without requirin…
You are configuring a conditional access policy to block access from untrusted locations. The policy should apply to all cloud apps except Microsoft Entra ID Administration. How sh…