Skip to content

AZ-500 Practice Questions

Prepare for AZ-500 with more than an answer.

358 questions in the full set20 sample questionsUpdated Jan 24, 2026
Exam fee
$165 USD
Level
Associate
Valid for
1 year
Domains covered on the exam 4
  1. Secure identity and access17.5%
  2. Secure networking22.5%
  3. Secure compute, storage, and databases22.5%
  4. Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel32.5%
  1. 1

    Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.

    Your Company’s Azure subscription includes a virtual network that has a single subnet configured.

    You have created a service endpoint for the subnet, which includes an Azure virtual machine that has Ubuntu Server 18.04 installed.

    You are preparing to deploy Docker containers to the virtual machine. You need to make sure that the containers can access Azure Storage resources and Azure SQL databases via the service endpoint.

    You need to perform a task on the virtual machine prior to deploying containers.

    Solution: You create an application security group.

    Does the solution meet the goal?

    Show answer details

    Correct answer: B

    The proposed solution does not meet the requirements. Virtual network configuration and security settings likely require specific implementations that the suggested approach cannot adequately provide.

  2. 2

    Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.

    Your company has an Active Directory forest with a single domain, named weylandindustries.com. They also have an Azure Active Directory (Azure AD) tenant with the same name.

    You have been tasked with integrating Active Directory and the Azure AD tenant. You intend to deploy Azure AD Connect.

    Your strategy for the integration must make sure that password policies and user logon limitations affect user accounts that are synced to the Azure AD tenant, and that the amount of necessary servers are reduced.

    Solution: You recommend the use of federation with Active Directory Federation Services (AD FS).

    Does the solution meet the goal?

    Show answer details

    Correct answer: B

    Explanation:
    A federated authentication system relies on an external trusted system to authenticate users. Some companies want to reuse their existing federated system investment with their Azure AD hybrid identity solution. The maintenance and management of the federated system falls outside the control of Azure AD. It's up to the organization by using the federated system to make sure it's deployed securely and can handle the authentication load.
    Reference:
    https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta

  3. 3

    Your company has an Azure Container Registry.

    You have been tasked with assigning a user a role that allows for the uploading of images to the Azure Container Registry. The role assigned should not require more privileges than necessary.

    Which of the following is the role you should assign?

    Show answer details

    Correct answer: C

    AcrPush is the correct role for uploading container images to Azure Container Registry, following the principle of least privilege. This role provides push access for uploading images without granting unnecessary permissions. Owner and Contributor roles provide broader access than needed, while AcrPull only allows downloading images.

  4. 4

    Your company’s Azure subscription includes a hundred virtual machines that have Azure Diagnostics enabled.

    You have been tasked with retrieving the identity of the user that removed a virtual machine fifteen days ago. You have already accessed Azure Monitor.

    Which of the following options should you use?

    Show answer details

    Correct answer: C

    Explanation:
    Azure activity logs provide insight into the operations that were performed on resources in your subscription. Activity logs were previously known as “audit logs” or “operational logs,” because they report control-plane events for your subscriptions.
    Reference:
    https://docs.microsoft.com/en-us/azure/security/azure-log-audit

  5. 5

    A security architect is designing a network topology for a new application. The design requires a central hub VNet containing shared services like Azure Firewall and a domain controller. Multiple spoke VNets will host different application tiers. The architect wants to ensure that all traffic between the spoke VNets is inspected by the Azure Firewall in the hub. Which of the following is essential to implement this traffic flow?

    graph TD subgraph Hub_VNet Firewall[Azure Firewall] Gateway[VPN Gateway] end subgraph Spoke_A_VNet AppVMs[App VMs] end subgraph Spoke_B_VNet DataVMs[Data VMs] end Internet --> Gateway Spoke_A_VNet -- VNet Peering --> Hub_VNet Spoke_B_VNet -- VNet Peering --> Hub_VNet AppVMs -- "Traffic to DataVMs" --> Firewall Firewall -- "Inspected Traffic" --> DataVMs
    Show answer details

    Correct answer: B

    By default, VNet peering allows direct communication between peered networks. To force traffic through a central firewall (a Network Virtual Appliance or Azure Firewall), you must override the default system routes. This is achieved by creating a Route Table with a User Defined Route (UDR) that points to the firewall's IP address for traffic destined for the other spoke VNet's address space. This UDR must be associated with the subnets in each spoke.

  6. 6

    Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.

    Your company’s Azure subscription is linked to their Azure Active Directory (Azure AD) tenant.

    After an internally developed application is registered in Azure AD, you are tasked with making sure that the application has the ability to access Azure Key Vault secrets on application the users’ behalf.

    Solution: You configure a delegated permission with admin consent.

    Does the solution meet the goal?

    Show answer details

    Correct answer: B

    The proposed solution does not meet the requirements. The scenario likely involves Azure AD application permissions or authentication configurations that the suggested approach cannot adequately address.

  7. 7

    Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.

    Your company has Azure subscription linked to their Azure Active Directory (Azure AD) tenant.

    As a Global administrator for the tenant, part of your responsibilities involves managing Azure Security Center settings.

    You are currently preparing to create a custom sensitivity label.

    Solution: You start by altering the pricing tier of the Security Center.

    Does the solution meet the goal?

    Show answer details

    Correct answer: B

    The proposed solution does not satisfy the requirements. Azure AD authentication and authorization configurations require specific approaches that the suggested solution cannot properly implement.

  8. 8

    Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.

    Your company’s Azure subscription is linked to their Azure Active Directory (Azure AD) tenant.

    After an internally developed application is registered in Azure AD, you are tasked with making sure that the application has the ability to access Azure Key Vault secrets on application the users’ behalf.

    Solution: You configure a delegated permission with no admin consent.

    Does the solution meet the goal?

    Show answer details

    Correct answer: A

    Explanation:
    Delegated permissions - Your client application needs to access the web API as the signed-in user, but with access limited by the selected permission. This type of permission can be granted by a user unless the permission requires administrator consent.
    Reference:
    https://docs.microsoft.com/en-us/azure/active-directory/develop/quickstart-configure-app-access-web-apis

  9. 9

    Your company has an Azure Container Registry.

    You have been tasked with assigning a user a role that allows for the downloading of images from the Azure Container Registry. The role assigned should not require more privileges than necessary.

    Which of the following is the role you should assign?

    Show answer details

    Correct answer: D

    AcrPull is the correct role for downloading container images from Azure Container Registry, following the principle of least privilege. The Reader role provides broader access than necessary, while Contributor allows modification operations, and AcrDelete specifically handles deletion operations.

  10. 10

    Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.
    Your company has an Azure subscription that includes an Azure key vault. You have previously created a secret in the key vault.

    After an application developer registers an application in Azure Active Directory (Azure AD), you are instructed to make sure that the application is able to use the secret you created.

    Solution: You should create a DLP policy.

    Does the solution meet the goal?

    Show answer details

    Correct answer: B

    The solution does not meet the requirements. The proposed configuration for Azure subscription and resource management likely has gaps that prevent it from achieving the desired security or compliance objectives.

Create an account to continue.