Courseiva
← Back to Microsoft Azure Security Engineer Associate AZ-500 questions

Scenario-based practice

Hard Difficulty Questions

Practise Microsoft Azure Security Engineer Associate AZ-500 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
AZ-500
exam code
Microsoft
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related AZ-500 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmulti select
Full question →

Which THREE capabilities are provided by Azure Storage Service Encryption (SSE) when using customer-managed keys?

Question 2hardmultiple choice
Full question →

Refer to the exhibit. You have an Azure Application Gateway WAF policy with the above JSON configuration. A user from IP address 10.1.2.3 reports they cannot access the web application. What is the most likely cause?

Exhibit

{
  "properties": {
    "format": "Json",
    "rules": [
      {
        "name": "BlockHighRiskIPs",
        "priority": 100,
        "ruleType": "MatchRule",
        "matchConditions": [
          {
            "matchVariables": [
              {
                "variableName": "RemoteAddr"
              }
            ],
            "operator": "IPMatch",
            "negationCondition": false,
            "matchValues": [
              "10.0.0.0/8",
              "172.16.0.0/12",
              "192.168.0.0/16"
            ]
          }
        ],
        "action": "Block"
      }
    ]
  }
}
Question 3hardmultiple choice
Full question →

Your organization uses Microsoft Entra ID and has a hybrid identity setup with password hash synchronization. You need to implement a solution that detects password changes on-premises and forces re-authentication for active sessions within minutes. Which feature should you enable?

Question 4hardmultiple choice
Full question →

A Conditional Access policy requiring compliant devices does not apply to Azure PowerShell access. Sign-in logs show the cloud app is excluded. What should be changed?

Question 5hardmultiple choice
Study the full multicast explanation →

Refer to the exhibit. A user is eligible for a role in PIM. When they activate the role, how long will the activation last?

Exhibit

Refer to the exhibit.

{
  "roleEligibilitySchedules": [
    {
      "principalId": "user1@contoso.com",
      "roleDefinitionId": "62e90394-69f5-4237-9190-012177145e10",
      "scheduleInfo": {
        "startDateTime": "2024-01-01T00:00:00Z",
        "expiration": {
          "type": "afterDuration",
          "duration": "PT8H"
        }
      }
    }
  ]
}
Question 6hardmultiple choice
Full question →

Your organization has Microsoft Entra ID and uses Microsoft Copilot for Microsoft 365. You need to ensure that Copilot interactions are logged and accessible for security investigations. What should you configure?

Question 7hardmultiple choice
Full question →

You are troubleshooting an issue where users are unable to access a sensitive application protected by a Conditional Access policy. The policy requires MFA from trusted locations, but users are reporting that they are prompted for MFA even when connecting from the corporate office, which is defined as a trusted location. What is the most likely cause?

Question 8hardmultiple choice
Full question →

A Sentinel analyst needs to preserve investigation notes, related entities, and ownership while escalating a case to another analyst. Which object should be updated?

Question 9hardmulti select
Full question →

A company uses Azure Firewall Premium to inspect outbound traffic. They want to deploy a web application that must comply with the Payment Card Industry Data Security Standard (PCI DSS). Which TWO capabilities should be enabled to meet PCI DSS requirements for network security?

Question 10hardmultiple choice
Full question →

A company uses Azure Key Vault to store secrets for their applications. They want to ensure that an application hosted on an Azure virtual machine can access secrets from only a specific Key Vault, and that all traffic between the VM and Key Vault remains within the Azure network and does not traverse the public internet. Which configuration should they implement?

Question 11hardmultiple choice
Study the full multicast explanation →

A company uses Azure AD Privileged Identity Management (PIM) for the Security Administrator role. They want the activation of this role to require approval from a specific group of senior security engineers before the role becomes active. They also want the approvers to receive an email notification when an activation request is submitted. Which PIM configuration must be set?

Question 12hardmultiple choice
Full question →

A company uses Azure SQL Database with Transparent Data Encryption (TDE) and wants to use a customer-managed key (CMK) stored in Azure Key Vault. The security policy requires that the Key Vault be protected by a firewall and virtual network service endpoints to restrict network access. The storage account for TDE logs is in the same Azure region. Which additional configuration is necessary in the Key Vault to allow Azure SQL Database to access the CMK for encryption operations?

Question 13hardmultiple choice
Review the full routing breakdown →

Your company has deployed Azure Virtual WAN with secured virtual hubs. You need to enforce that all traffic between on-premises sites and Azure virtual networks (VNets) passes through the Azure Firewall in the hub. You have configured routing accordingly. However, traffic from an on-premises site to a VNet is still bypassing the firewall. What is the most likely cause?

Question 14hardmultiple choice
Full question →

A company uses Azure SQL Database with Transparent Data Encryption (TDE) encrypted using a customer-managed key (CMK) stored in Azure Key Vault. The Key Vault is protected by a firewall that denies all public access. The SQL server must be able to access the key for TDE operations. Which additional configuration is necessary in the Key Vault to allow this?

Question 15hardmultiple choice
Full question →

A compliance team wants evidence that Azure resources are evaluated against the Microsoft Cloud Security Benchmark. Which Defender for Cloud area should they use?

Question 16hardmultiple choice
Full question →

A company uses Microsoft Defender for Cloud to assess the security posture of its Azure resources. The security team notices that the secure score is lower than expected because many recommendations are marked as 'Unhealthy' for resources that are not yet deployed (planned resources). How should you ensure that the secure score accurately reflects only deployed resources?

Question 17hardmultiple choice
Full question →

A company uses Azure AD Identity Protection. They want to automatically block sign-ins that have a high user risk level, but only for users in the 'Finance' department. They also want to require MFA for medium user risk level for all users (including Finance) when sign-in risk is not blocked. They have already created a Conditional Access policy for the Finance department that has a condition of 'User risk level: High' and a grant control of 'Block access'. What additional configuration is needed to also require MFA for all users with medium user risk?

Question 18hardmultiple choice
Review the full subnetting walkthrough →

Refer to the exhibit. The JSON shows an NSG rule set applied to a subnet. The subnet contains a web server that should be accessible from the internet on port 443. Users report they cannot connect. What is the most likely cause?

Exhibit

{
  "properties": {
    "rules": [
      {
        "name": "AllowVNetInbound",
        "direction": "Inbound",
        "priority": 100,
        "sourceAddressPrefixes": ["VirtualNetwork"],
        "destinationAddressPrefixes": ["VirtualNetwork"],
        "access": "Allow",
        "protocol": "*",
        "sourcePortRange": "*",
        "destinationPortRange": "*"
      },
      {
        "name": "DenyInternetInbound",
        "direction": "Inbound",
        "priority": 200,
        "sourceAddressPrefixes": ["Internet"],
        "destinationAddressPrefixes": ["*"],
        "access": "Deny",
        "protocol": "*",
        "sourcePortRange": "*",
        "destinationPortRange": "*"
      }
    ]
  }
}
Question 19hardmultiple choice
Review the full subnetting walkthrough →

A company has two Azure virtual networks, VNet-A (hub) and VNet-B (spoke), connected via VNet peering. They deployed a network virtual appliance (NVA) in a subnet in VNet-A to inspect all traffic. They configured a user-defined route (UDR) on the subnet in VNet-B that points the VNet-A address space (10.0.0.0/16) to the private IP of the NVA. However, traffic initiated from VNet-B to VNet-A still takes a direct path and bypasses the NVA. What is the most likely cause?

Question 20hardmultiple choice
Full question →

Your company is migrating from on-premises Active Directory to Microsoft Entra ID. You need to synchronize user accounts and enable self-service password reset (SSPR) for cloud users. You have set up Microsoft Entra Connect Sync. Which additional configuration is required to allow password writeback for SSPR?

These AZ-500 practice questions are part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style AZ-500 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.