AZ-500 Secure identity and access Practice Question
Exhibit
Refer to the exhibit.
{
"properties": {
"displayName": "Finance App Access Package",
"description": "Access to Finance applications for employees",
"resources": [
{
"originId": "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx",
"type": "Application"
}
],
"assignmentPolicies": [
{
"accessPackageId": "yyyyyyyy-yyyy-yyyy-yyyy-yyyyyyyyyyyy",
"accessReviewSettings": null,
"durationInDays": 30,
"expirationRequired": true,
"isAccessReviewEnabled": false,
"isApprovalRequiredForAdd": false,
"isApprovalRequiredForRemove": false,
"requestorSettings": {
"scopeType": "AllExistingDirectorySubjects"
}
}
]
}
}Refer to the exhibit. You are configuring an Entitlement Management access package. The policy allows any existing user to request access without approval, and access expires after 30 days. However, security requirements dictate that all access to Finance applications must be reviewed by the finance team manager every quarter. What should you add to the policy?
⚠ Common exam trap
It's easy for candidates to confuse 'approval at request time' with 'periodic review after access is granted' — the question explicitly says no approval is needed for the initial request, so adding approval (Option B) is incorrect, but the quarterly review (Option D) is a separate governance control that satisfies the security requirement without changing the request flow.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable access reviews and assign the finance team manager as reviewer
The security requirement mandates quarterly reviews by the finance team manager, which is exactly what an access review does in Entitlement Management. Access reviews allow you to require periodic attestation of access by a designated reviewer, ensuring ongoing compliance even though the initial request does not require approval. The policy already sets a 30-day expiration, but a quarterly review adds a separate recurring governance check that overrides the shorter duration for compliance purposes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add a connected organization for external users
Why it's wrong here
Connecting an organization to Microsoft Entra ID entitlement management establishes a trust relationship that makes it easier for external B2B users to request access to your resources, but it does not introduce recurring review workflows. It merely governs how external identities can be added to a connected tenant; no periodic attestation or reviewer assignment is configured. The quarterly review requirement remains unmet.
- ✗
Set 'isApprovalRequiredForAdd' to true
Why it's wrong here
Setting 'isApprovalRequiredForAdd' to true only demands that a user's access request be approved by designated approvers before they receive the entitlement. This is a one-time approval event that occurs when access is initially granted, not a recurring review. The quarterly review would still be absent, so the requirement is not satisfied.
- ✗
Set 'durationInDays' to 90
Why it's wrong here
Setting 'durationInDays' to 90 automatically revokes an entitlement after 90 days without any human review, which means an employee could continue to have access for three months regardless of whether it is still appropriate. This is an expiration policy, not a review policy: it forces users to re-request access rather than having a finance manager attest to the continuing need. The organization will not get the required quarterly review.
- ✓
Enable access reviews and assign the finance team manager as reviewer
Why this is correct
Enabling access reviews in entitlement management configures recurring attestation cycles—in this case quarterly—where access packages are periodically recertified. Assigning the finance team manager as the reviewer gives a business owner the responsibility to approve, deny, or remove access at each cycle. This exactly satisfies the compliance requirement for a periodic review.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.