Courseiva
← Back to Microsoft Azure Security Engineer Associate AZ-500 questions

Scenario-based practice

Refer to the Exhibit Practice Questions

Practise Microsoft Azure Security Engineer Associate AZ-500 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

15
scenario questions
AZ-500
exam code
Microsoft
vendor

Scenario guide

How to approach refer to the exhibit practice questions

Practise exhibit-style questions that ask you to read a topology, table, command output or diagram before choosing the best answer.

Quick answer

Exhibit-style questions test whether you can read a topology, command output, diagram or table before choosing the best answer.

How to extract the relevant detail from an exhibit.

How topology, command output or routing information affects the answer.

How to avoid answering from memory before reading the evidence.

How to map the exhibit back to the exam objective.

Related practice questions

Related AZ-500 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

Refer to the exhibit. You have an Azure Application Gateway WAF policy with the above JSON configuration. A user from IP address 10.1.2.3 reports they cannot access the web application. What is the most likely cause?

Exhibit

{
  "properties": {
    "format": "Json",
    "rules": [
      {
        "name": "BlockHighRiskIPs",
        "priority": 100,
        "ruleType": "MatchRule",
        "matchConditions": [
          {
            "matchVariables": [
              {
                "variableName": "RemoteAddr"
              }
            ],
            "operator": "IPMatch",
            "negationCondition": false,
            "matchValues": [
              "10.0.0.0/8",
              "172.16.0.0/12",
              "192.168.0.0/16"
            ]
          }
        ],
        "action": "Block"
      }
    ]
  }
}
Question 2mediummultiple choice
Full question →

You are reviewing an Azure Resource Manager template for a storage account. The exhibit shows a snippet of the template. Which statement about the template is true?

Exhibit

Refer to the exhibit.
{
  "properties": {
    "encryption": {
      "services": {
        "blob": {
          "enabled": true
        },
        "file": {
          "enabled": true
        }
      },
      "keySource": "Microsoft.Storage"
    }
  }
}
Question 3mediummultiple choice
Review the full subnetting walkthrough →

A company is designing a hub-spoke network topology with Azure Firewall in the hub virtual network. Spoke virtual networks are peered to the hub. They want to ensure that all outbound internet traffic from virtual machines in a spoke subnet goes through the Azure Firewall. They have configured a route table on the spoke subnet with a default route (0.0.0.0/0) pointing to the Azure Firewall's private IP address as the next hop. However, traffic is still bypassing the firewall. What is the most likely cause?

Question 4mediummultiple choice
Full question →

You have configured the Conditional Access policy shown in the exhibit. Users report that they can still access Exchange Online using legacy authentication protocols. What is the most likely reason?

Exhibit

Refer to the exhibit.

{
  "policy": {
    "displayName": "Block legacy authentication",
    "state": "enabledForReportingButNotEnforced",
    "conditions": {
      "clientAppTypes": ["exchangeActiveSync", "otherClients"],
      "applications": {
        "includeApplications": ["Office365"]
      }
    },
    "grantControls": {
      "builtInControls": ["block"]
    }
  }
}
Question 5mediummultiple choice
Review the full subnetting walkthrough →

You are reviewing an NSG rule as shown in the exhibit. This rule is applied to a subnet containing web servers. What is the security implication of this rule?

Exhibit

Refer to the exhibit.

```json
{
  "properties": {
    "protocol": "Any",
    "sourceAddresses": ["*"],
    "destinationAddresses": ["*"],
    "destinationPorts": ["*"],
    "sourcePorts": ["*"],
    "access": "Allow",
    "priority": 100,
    "direction": "Inbound",
    "ruleType": "BasicRule"
  }
}
```
Question 6mediummultiple choice
Review the full subnetting walkthrough →

You are an Azure security engineer. Your team has assigned the Azure Policy shown in the exhibit. A developer creates a new virtual network with a subnet that does not have a Network Security Group (NSG) associated. What will happen when the policy is evaluated?

Exhibit

Refer to the exhibit.

```json
{
  "properties": {
    "policyRule": {
      "if": {
        "field": "type",
        "equals": "Microsoft.Network/virtualNetworks"
      },
      "then": {
        "effect": "deny",
        "details": {
          "field": "Microsoft.Network/virtualNetworks/subnets",
          "existenceCondition": {
            "field": "Microsoft.Network/virtualNetworks/subnets/networkSecurityGroup",
            "exists": "false"
          }
        }
      }
    },
    "parameters": {}
  }
}
```
Question 7mediummultiple choice
Full question →

A company uses Azure Firewall to inspect traffic between a spoke VNet hosting a web application and a hub VNet hosting a SQL database. The web application fails to connect to the database after a recent network topology change. You verify that the Azure Firewall rules allow the traffic. Which Azure Network Watcher feature should you use to identify the root cause?

Question 8mediummultiple choice
Review the full subnetting walkthrough →

Refer to the exhibit. You are reviewing an NSG rule configuration for a subnet. The source subnet is 10.0.0.0/24 and the destination subnet is 10.0.1.0/24. What is the effect of this rule?

Exhibit

{
  "name": "AllowSSHOnly",
  "properties": {
    "protocol": "Tcp",
    "sourcePortRange": "*",
    "destinationPortRange": "22",
    "sourceAddressPrefix": "10.0.0.0/24",
    "destinationAddressPrefix": "10.0.1.0/24",
    "access": "Allow",
    "priority": 100,
    "direction": "Inbound"
  }
}
Question 9easymultiple choice
Full question →

You are designing a hub-spoke network topology in Azure. You need to ensure that all traffic between spokes is inspected by a network virtual appliance (NVA) deployed in the hub. What should you configure?

Question 10hardmultiple choice
Review the full subnetting walkthrough →

You are a security engineer for Contoso. The company uses Azure Firewall for all inbound and outbound traffic. To prevent misconfiguration, you assign the Azure Policy shown in the exhibit at the management group scope. After assignment, a network administrator reports that they cannot create a new subnet in an existing virtual network. The subnet creation fails with a 'deny' policy error. You need to allow subnet creation while still blocking NSG rule changes. What should you do?

Exhibit

Refer to the exhibit.
```json
{
    "properties": {
        "policyRule": {
            "if": {
                "anyOf": [
                    {
                        "field": "type",
                        "equals": "Microsoft.Network/networkSecurityGroups/securityRules"
                    },
                    {
                        "field": "type",
                        "equals": "Microsoft.Network/virtualNetworks/subnets"
                    }
                ]
            },
            "then": {
                "effect": "deny"
            }
        },
        "parameters": {},
        "displayName": "Block NSG rules and subnet changes"
    }
}
```
Question 11hardmultiple choice
Full question →

You are deploying an Azure SQL Database with a security alert policy as shown in the exhibit. Which statement is true?

Exhibit

Refer to the exhibit.
{
  "type": "Microsoft.Sql/servers/databases/securityAlertPolicies",
  "apiVersion": "2023-08-01-preview",
  "properties": {
    "state": "Enabled",
    "emailAccountAdmins": true,
    "emailAddresses": ["admin@contoso.com"],
    "disabledAlerts": [],
    "retentionDays": 30
  }
}
Question 12easymultiple choice
Full question →

You run the PowerShell cmdlet shown in the exhibit for an Azure SQL Database. What is the security implication?

Exhibit

Refer to the exhibit.

```
PS Azure:\> Get-AzSqlDatabaseAdvancedThreatProtectionSetting -ResourceGroupName RG1 -ServerName sqlsrv1 -DatabaseName db1

ResourceGroupName : RG1
ServerName        : sqlsrv1
DatabaseName      : db1
State             : Disabled
```
Question 13mediummultiple choice
Full question →

Refer to the exhibit. You are deploying an Azure Storage account with the ARM template snippet shown. The deployment fails with an error about the encryption configuration. What is the most likely cause?

Exhibit

{
  "properties": {
    "encryption": {
      "keySource": "Microsoft.Keyvault",
      "keyvaultproperties": {
        "keyvaulturi": "https://mykeyvault.vault.azure.net/",
        "keyname": "myencryptionkey",
        "keyversion": "1234567890abcdef"
      }
    }
  }
}
Question 14mediummultiple choice
Full question →

Refer to the exhibit. You are reviewing the Microsoft Defender for Cloud settings for a subscription. The JSON shows that 'autoProvision' is set to true. What does this mean?

Exhibit

{
  "properties": {
    "pricingTier": "Standard",
    "autoProvision": true
  }
}
Question 15mediummultiple choice
Full question →

Refer to the exhibit. A security analyst runs this KQL query in Microsoft Sentinel. What is the purpose of this query?

Exhibit

SecurityAlert
| where TimeGenerated > ago(7d)
| summarize Count = count() by AlertName, AlertSeverity
| top 10 by Count desc

These AZ-500 practice questions are part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style AZ-500 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.