Courseiva
Secure identity and access →mediumMultiple Choice

AZ-500 Secure identity and access Practice Question

Exhibit

Refer to the exhibit.

{
  "properties": {
    "displayName": "Finance App Access Package",
    "description": "Access to Finance applications for employees",
    "resources": [
      {
        "originId": "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx",
        "type": "Application"
      }
    ],
    "assignmentPolicies": [
      {
        "accessPackageId": "yyyyyyyy-yyyy-yyyy-yyyy-yyyyyyyyyyyy",
        "accessReviewSettings": null,
        "durationInDays": 30,
        "expirationRequired": true,
        "isAccessReviewEnabled": false,
        "isApprovalRequiredForAdd": false,
        "isApprovalRequiredForRemove": false,
        "requestorSettings": {
          "scopeType": "AllExistingDirectorySubjects"
        }
      }
    ]
  }
}

Refer to the exhibit. You are configuring an Entitlement Management access package. The policy allows any existing user to request access without approval, and access expires after 30 days. However, security requirements dictate that all access to Finance applications must be reviewed by the finance team manager every quarter. What should you add to the policy?

⚠ Common exam trap

It's easy for candidates to confuse 'approval at request time' with 'periodic review after access is granted' — the question explicitly says no approval is needed for the initial request, so adding approval (Option B) is incorrect, but the quarterly review (Option D) is a separate governance control that satisfies the security requirement without changing the request flow.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable access reviews and assign the finance team manager as reviewer

The security requirement mandates quarterly reviews by the finance team manager, which is exactly what an access review does in Entitlement Management. Access reviews allow you to require periodic attestation of access by a designated reviewer, ensuring ongoing compliance even though the initial request does not require approval. The policy already sets a 30-day expiration, but a quarterly review adds a separate recurring governance check that overrides the shorter duration for compliance purposes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add a connected organization for external users

    Why it's wrong here

    Connecting an organization to Microsoft Entra ID entitlement management establishes a trust relationship that makes it easier for external B2B users to request access to your resources, but it does not introduce recurring review workflows. It merely governs how external identities can be added to a connected tenant; no periodic attestation or reviewer assignment is configured. The quarterly review requirement remains unmet.

  • ✗

    Set 'isApprovalRequiredForAdd' to true

    Why it's wrong here

    Setting 'isApprovalRequiredForAdd' to true only demands that a user's access request be approved by designated approvers before they receive the entitlement. This is a one-time approval event that occurs when access is initially granted, not a recurring review. The quarterly review would still be absent, so the requirement is not satisfied.

  • ✗

    Set 'durationInDays' to 90

    Why it's wrong here

    Setting 'durationInDays' to 90 automatically revokes an entitlement after 90 days without any human review, which means an employee could continue to have access for three months regardless of whether it is still appropriate. This is an expiration policy, not a review policy: it forces users to re-request access rather than having a finance manager attest to the continuing need. The organization will not get the required quarterly review.

  • ✓

    Enable access reviews and assign the finance team manager as reviewer

    Why this is correct

    Enabling access reviews in entitlement management configures recurring attestation cycles—in this case quarterly—where access packages are periodically recertified. Assigning the finance team manager as the reviewer gives a business owner the responsibility to approve, deny, or remove access at each cycle. This exactly satisfies the compliance requirement for a periodic review.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.