DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free Microsoft AZ-500 Practice Questions & Answers 2026 Part1 | Microsoft Azure Security Technologies

Are you preparing for the Microsoft AZ-500 certification exam? SPOTO offers the Microsoft AZ-500 Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
Your company uses Azure DevOps with branch policies configured.Which of the following is TRUE with regards to branch policies? (Choose all that apply.)
A. It enforces your team's change management standards
B. It controls who can read and update the code in a branch
C. It enforces your team's code quality
D. It places a branch into a read-only state
View answer
Correct Answer: AC

View The Updated AZ-500 Exam Questions

SPOTO Provides 100% Real AZ-500 Exam Questions for You to Pass Your AZ-500 Exam!

Question #2
Your company's Azure subscription includes Windows Server 2016 Azure virtual machines.You are informed that every virtual machine must have a custom antimalware virtual machine extension installed. You are writing the necessary code for a policy that will help you achieve this.Which of the following is an effect that must be included in your code?
A. Disabled
B. Modify
C. AuditIfNotExists
D. DeployIfNotExists
View answer
Correct Answer: D
Question #3
Your company has an Active Directory forest with a single domain, named weylandindustries.com. They also have an Azure Active Directory (Azure AD) tenant with the same name.After syncing all on-premises identities to Azure AD, you are informed that users with a givenName attribute starting with LAB should not be allowed to sync toAzure AD.Which of the following actions should you take?
A. ou should make use of the Synchronization Rules Editor to create an attribute-based filtering rule
B. ou should configure a DNAT rule on the Firewall
C. ou should configure a network traffic filtering rule on the Firewall
D. ou should make use of Active Directory Users and Computers to create an attribute-based filtering rule
View answer
Correct Answer: A
Question #4
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a hybrid configuration of Azure Active Directory (Azure AD).You have an Azure HDInsight cluster on a virtual network.You plan to allow users to authenticate to the cluster by using their on-premises Active Directory credentials.You need to configure the environment to support the planned authentication.Solution: You deploy Azure Active Directory Domain Services (Azure AD DS) to the Azure subscription.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: A
Question #5
You have an Azure Active Directory (Azure AD) tenant named contoso.onmicrosoft.com.The User administrator role is assigned to a user named Admin1.An external partner has a Microsoft account that uses the user1@outlook.com sign in.Admin1 attempts to invite the external partner to sign in to the Azure AD tenant and receives the following error message: `Unable to invite user user1@outlook.com Generic authorization exception.`You need to ensure that Admin1 can invite the external partner to sign in to the Azure AD tenant.What should you do?
A. From the Roles and administrators blade, assign the Security administrator role to Admin1
B. From the Organizational relationships blade, add an identity provider
C. From the Custom domain names blade, add a custom domain
D. From the Users blade, modify the External collaboration settings
View answer
Correct Answer: D
Question #6
You have been tasked with applying conditional access policies for your company's current Azure Active Directory (Azure AD).The process involves assessing the risk events and risk levels.Which of the following is the risk level that should be configured for users that have leaked credentials?
A. None
B. Low
C. Medium
D. High
View answer
Correct Answer: D
Question #7
Your company's Azure subscription includes an Azure Log Analytics workspace.Your company has a hundred on-premises servers that run either Windows Server 2012 R2 or Windows Server 2016, and is linked to the Azure Log Analytics workspace. The Azure Log Analytics workspace is set up to gather performance counters associated with security from these linked servers.You have been tasked with configuring alerts according to the information gathered by the Azure Log Analytics workspace.You have to make sure that alert rules allow for dimensions, and that alert creation time should be kept to a minimum. Furthermore, a single alert notification must be created when the alert is created and when the alert is sorted out.You need to make use of the necessary signal type when creating the alert rules.Which of the following is the option you should use?
A. You should make use of the Activity log signal type
B. You should make use of the Application Log signal type
C. You should make use of the Metric signal type
D. You should make use of the Audit Log signal type
View answer
Correct Answer: C
Question #8
Your company has an Azure subscription that includes two virtual machines, named VirMac1 and VirMac2, which both have a status of Stopped (Deallocated).The virtual machines belong to different resource groups, named ResGroup1 and ResGroup2.You have also created two Azure policies that are both configured with the virtualMachines resource type. The policy configured for ResGroup1 has a policy definition of Not allowed resource types, while the policy configured for ResGroup2 has a policy definition of Allowed resource types.You then create a Read-only resource lock on VirMac1, as well as a Read-only resource lock on ResGroup2.Which of the following is TRUE with regards to the scenario? (Choose all that apply.)
A. You will be able to start VirMac1
B. You will NOT be able to start VirMac1
C. You will be able to create a virtual machine in ResGroup2
D. You will NOT be able to create a virtual machine in ResGroup2
View answer
Correct Answer: BD
Question #9
You have an Azure subscription that is linked to an Azure Active Directory (Azure AD) tenant.From the Azure portal, you register an enterprise application.Which additional resource will be created in Azure AD?
A. user account
B. managed identity
C. service principal
D. n X
View answer
Correct Answer: C
Question #10
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.Your company has an Active Directory forest with a single domain, named weylandindustries.com. They also have an Azure Active Directory (Azure AD) tenant with the same name.You have been tasked with integrating Active Directory and the Azure AD tenant. You intend to deploy Azure AD Connect.Your strategy for the integration must make sure that password policies and user logon limitations affect user accounts that are synced to the Azure AD tenant, and that the amount of necessary servers are reduced.Solution: You recommend the use of password hash synchronization and seamless SSO.Does the solution meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #11
You have an Azure subscription that contains an Azure Active Directory (Azure AD) tenant and a user named User1.The App registrations settings for the tenant are configured as shown in the following exhibit.You plan to deploy an app named App1.You need to ensure that User1 can register App1 in Azure AD. The solution must use the principle of least privilege.Which role should you assign to User1?
A. App Configuration Data Owner for the subscription
B. Managed Application Contributor for the subscription
C. Cloud application administrator in Azure AD
D. Application developer in Azure AD
View answer
Correct Answer: D
Question #12
You need to consider the underlined segment to establish whether it is accurate.You have configured an Azure Kubernetes Service (AKS) cluster in your testing environment.You are currently preparing to deploy the cluster to the production environment.After disabling HTTP application routing, you want to replace it with an application routing solution that allows for reverse proxy and TLS termination for AKS services via a solitary IP address.You must create an AKS Ingress controller.Select `No adjustment required` if the underlined segment is accurate. If the underlined segment is inaccurate, select the accurate option.
A. No adjustment required
B. a network security group
C. an application security group
D. an Azure Basic Load Balancer
View answer
Correct Answer: A
Question #13
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have an Azure subscription named Sub1.You have an Azure Storage account named sa1 in a resource group named RG1.Users and applications access the blob service and the file service in sa1 by using several shared access signatures (SASs) and stored access policies.You discover that unauthorized users accessed both the file service and the blob service.You need to revoke all access to sa1.Solution: You regenerate the Azure storage account access keys.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: A
Question #14
Your company has an Azure Container Registry.You have been tasked with assigning a user a role that allows for the uploading of images to the Azure Container Registry. The role assigned should not require more privileges than necessary.Which of the following is the role you should assign?
A. Owner
B. Contributor
C. AcrPush
D. AcrPull
View answer
Correct Answer: C
Question #15
While configuring Azure Application Gateway for your company, you want to ensure that the user experiences no performance degradation even during peak times. Which of the following setting would you configure?
A. Health probes
B. Autoscaling
C. Manual scaling
D. Protocol
View answer
Correct Answer: B
Question #16
Being the network engineer at your company, you need to ensure that communications with Azure Storage pass through the Service Endpoint. How would you ensure it?
A. By adding one Inbound rule and one Outbound rule
B. You don't need to make a specific configuration or add any rule, it is automatically configured
C. By adding an Inbound rule to allow access to the storage
D. By adding an Outbound rule to allow access to the storage
View answer
Correct Answer: D
Question #17
You have an Azure subscription that contains an Azure SQL database named SQL1 and an Azure key vault named KeyVault1. KeyVault1 stores the keys shown in the following table.You reed to configure Transparent Data Encryption (TDE). TDE will use a customer-managed key for SQL1?
A. Key1
B. Key1 only
C. Key2 only
D. Key1 and key2 only
E. Key2 and Key3 only
View answer
Correct Answer: E
Question #18
From Azure Security Center, you need to deploy SecPol1.What should you do first?
A. nable Azure Defender
B. reate an Azure Management group
C. reate an initiative
D. onfigure continuous export
View answer
Correct Answer: C
Question #19
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
A. Yes
B. No
View answer
Correct Answer: B
Question #20
You have been tasked with configuring an access review, which you plan to assigned to a new collection of reviews. You also have to make sure that the reviewscan be reviewed by resource owners.You start by creating an access review program and an access review control.You now need to configure the Reviewers.Which of the following should you set Reviewers to?
A. Selected users
B. Members (Self)
C. Group Owners
D. Anyone
View answer
Correct Answer: C
Question #21
You have an Azure subscription that contains a storage account and an Azure web app named App1.App1 connects to an Azure Cosmos DB database named Cosmos1 that uses a private endpoint named Endpoint1. Endpoint1 has the default settings.You need to validate the name resolution to Cosmos1.Which DNS zone should you use?
A. ndpoint1
B. ndpoint1
C. ndpoint1
D. ndpoint1
View answer
Correct Answer: B
Question #22
You need to consider the underlined segment to establish whether it is accurate.Your Azure Active Directory Azure (Azure AD) tenant has an Azure subscription linked to it.Your developer has created a mobile application that obtains Azure AD access tokens using the OAuth 2 implicit grant type.The mobile application must be registered in Azure AD.You require a redirect URI from the developer for registration purposes.Select `No adjustment required` if the underlined segment is accurate. If the underlined segment is inaccurate, select the accurate option.
A. No adjustment required
B. a secret
C. a login hint
D. a client ID
View answer
Correct Answer: A
Question #23
You plan to use Azure Resource Manager templates to perform multiple deployments of identically configured Azure virtual machines. The password for the administrator account of each deployment is stored as a secret in different Azure key vaults.You need to identify a method to dynamically construct a resource ID that will designate the key vault containing the appropriate secret during each deployment.The name of the key vault and the name of the secret will be provided as inline parameters.What should you use to construct the resource ID?
A. a key vault access policy
B. a linked template
C. a parameters file
D. an automation account
View answer
Correct Answer: B
Question #24
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have an Azure subscription named Sub1.You have an Azure Storage account named sa1 in a resource group named RG1.Users and applications access the blob service and the file service in sa1 by using several shared access signatures (SASs) and stored access policies.You discover that unauthorized users accessed both the file service and the blob service.You need to revoke all access to sa1.Solution: You generate new SASs.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #25
Your company's Azure subscription includes a hundred virtual machines that have Azure Diagnostics enabled.You have been tasked with analyzing the security events of a Windows Server 2016 virtual machine. You have already accessed Azure Monitor.Which of the following options should you use?
A. Application Log
B. Metrics
C. Activity Log
D. Logs
View answer
Correct Answer: D
Question #26
You are in the process of configuring an Azure policy via the Azure portal.Your policy will include an effect that will need a managed identity for it to be assigned.Which of the following is the effect in question?
A. AuditIfNotExist
B. Disabled
C. DeployIfNotExist
D. EnforceOPAConstraint
View answer
Correct Answer: C
Question #27
You have an Azure subscription named Sub1. Sub1 contains a virtual network named VNet1 that contains one subnet named Subnet1.
A. Create an application security group and a network security group (NSG)
B. Edit the docker-compose
C. Install the container network interface (CNI) plug-in
View answer
Correct Answer: C
Question #28
You need to ensure that users can access VM0. The solution must meet the platform protection requirements. What should you do?
A. Move VM0 to Subnet1
B. On Firewall, configure a network traffic filtering rule
C. Assign RT1 to AzureFirewallSubnet
D. On Firewall, configure a DNAT rule
View answer
Correct Answer: D
Question #29
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a hybrid configuration of Azure Active Directory (Azure AD).You have an Azure HDInsight cluster on a virtual network.You plan to allow users to authenticate to the cluster by using their on-premises Active Directory credentials.You need to configure the environment to support the planned authentication.Solution: You deploy an Azure AD Application Proxy.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #30
Your company recently created an Azure subscription. You have, subsequently, been tasked with making sure that you are able to secure Azure AD roles by making use of Azure Active Directory (Azure AD) Privileged Identity Management (PIM).Which of the following actions should you take FIRST?
A. ou should sign up Azure Active Directory (Azure AD) Privileged Identity Management (PIM) for Azure AD roles
B. ou should consent to Azure Active Directory (Azure AD) Privileged Identity Management (PIM)
C. ou should discover privileged roles
D. ou should discover resources
View answer
Correct Answer: C
Question #31
You have an Azure subscription that contains a virtual machine named VM1. You create an Azure key vault that has the following configurations: Name: Vault5 Region: West US Resource group: RG1 You need to use Vault5 to enable Azure Disk Encryption on VM1. The solution must support backing up VM1 by using Azure Backup. Which key vault settings should you configure?
A. AAccess policies
B. BSecrets
C. CKeys
D. DLocks
View answer
Correct Answer: A
Question #32
Your company has an Active Directory forest with a single domain, named weylandindustries.com. They also have an Azure Active Directory (Azure AD) tenant with the same name.After syncing all on-premises identities to Azure AD, you are informed that users with a givenName attribute starting with LAB should not be allowed to sync toAzure AD.Which of the following actions should you take?
A. You should make use of the Synchronization Rules Editor to create an attribute-based filtering rule
B. You should configure a DNAT rule on the Firewall
C. You should configure a network traffic filtering rule on the Firewall
D. You should make use of Active Directory Users and Computers to create an attribute-based filtering rule
View answer
Correct Answer: A
Question #33
You have an Azure subscription.You configure the subscription to use a different Azure Active Directory (Azure AD) tenant.What are two possible effects of the change? Each correct answer presents a complete solution.NOTE: Each correct selection is worth one point.
A. Role assignments at the subscription level are lost
B. Virtual machine managed identities are lost
C. Virtual machine disk snapshots are lost
D. Existing Azure resources are deleted
View answer
Correct Answer: AB
Question #34
You have been tasked with applying conditional access policies for your company's current Azure Active Directory (Azure AD).The process involves assessing the risk events and risk levels.Which of the following is the risk level that should be configured for sign ins that originate from IP addresses with dubious activity?
A. None
B. Low
C. Medium
D. High
View answer
Correct Answer: C
Question #35
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a hybrid configuration of Azure Active Directory (Azure AD). You have an Azure HDInsight cluster on a virtual network. You plan to allow users to authenticate to the cluster by using their on-premises Active Directory credentials. You need to configure the environment to support the planned authentication. Solution: You deploy an Azure AD Application Proxy. Does this meet the goal?
A. AYes
B. BNo
View answer
Correct Answer: B
Question #36
Your company recently created an Azure subscription.You have been tasked with making sure that a specified user is able to implement Azure AD Privileged Identity Management (PIM).Which of the following is the role you should assign to the user?
A. he Global administrator role
B. he Security administrator role
C. he Password administrator role
D. he Compliance administrator role
View answer
Correct Answer: A
Question #37
You have a hybrid configuration of Azure Active Directory (Azure AD) that has Single Sign-On (SSO) enabled. You have an Azure SQL Database instance that is configured to support Azure AD authentication.Database developers must connect to the database instance from the domain joined device and authenticate by using their on-premises Active Directory account.You need to ensure that developers can connect to the instance by using Microsoft SQL Server Management Studio. The solution must minimize authentication prompts.Which authentication method should you recommend?
A. Active Directory - Password
B. Active Directory - Universal with MFA support
C. SQL Server Authentication
D. Active Directory - Integrated
View answer
Correct Answer: D
Question #38
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a hybrid configuration of Azure Active Directory (Azure AD).You have an Azure HDInsight cluster on a virtual network.You plan to allow users to authenticate to the cluster by using their on-premises Active Directory credentials.You need to configure the environment to support the planned authentication.Solution: You deploy the On-premises data gateway to the on-premises network.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #39
You have an Azure virtual machine that runs Windows Server R2.You plan to deploy and configure an Azure Key vault, and enable Azure Disk Encryption for the virtual machine.Which of the following is TRUE with regards to Azure Disk Encryption for a Windows VM?
A. It is supported for basic tier VMs
B. It is supported for standard tier VMs
C. It is supported for VMs configured with software-based RAID systems
D. It is supported for VMs configured with Storage Spaces Direct (S2D)
View answer
Correct Answer: B
Question #40
Your company recently created an Azure subscription.You have been tasked with making sure that a specified user is able to implement Azure AD Privileged Identity Management (PIM).Which of the following is the role you should assign to the user?
A. The Global administrator role
B. The Security administrator role
C. The Password administrator role
D. The Compliance administrator role
View answer
Correct Answer: A

View The Updated Microsoft Exam Questions

SPOTO Provides 100% Real Microsoft Exam Questions for You to Pass Your Microsoft Exam!

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us