DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free Microsoft AZ-500 Practice Questions & Answers 2026 Part2 | Microsoft Azure Security Technologies

Are you preparing for the Microsoft AZ-500 certification exam? SPOTO offers the Microsoft AZ-500 Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
You have been tasked with making sure that you are able to modify the operating system security configurations via Azure Security Center.To achieve your goal, you need to have the correct pricing tier for Azure Security Center in place.Which of the following is the pricing tier required?
A. Advanced
B. Premium
C. Standard
D. Free
View answer
Correct Answer: C

View The Updated AZ-500 Exam Questions

SPOTO Provides 100% Real AZ-500 Exam Questions for You to Pass Your AZ-500 Exam!

Question #2
You have an Azure Container Registry named ContReg1 that contains a container image named image1.You enable content trust for ContReg1.After content trust is enabled, you push two images to ContReg1 as shown in the following table.Which images are trusted images?
A. image1 and image2 only
B. image2 only
C. image1, image2, and image3
View answer
Correct Answer: B
Question #3
Your network contains an Active Directory forest named contoso.com. You have an Azure Active Directory (Azure AD) tenant named contoso.com.You plan to configure synchronization by using the Express Settings installation option in Azure AD Connect.You need to identify which roles and groups are required to perform the planned configuration. The solution must use the principle of least privilege.Which two roles and groups should you identify? Each correct answer presents part of the solution.NOTE: Each correct selection is worth one point.
A. the Domain Admins group in Active Directory
B. the Security administrator role in Azure AD
C. the Global administrator role in Azure AD
D. the User administrator role in Azure AD
E. the Enterprise Admins group in Active Directory
View answer
Correct Answer: CE
Question #4
You have been tasked with enabling Advanced Threat Protection for an Azure SQL Database server.Advanced Threat Protection must be configured to identify all types of threat detection.Which of the following will happen if when a faulty SQL statement is generate in the database by an application?
A. A Potential SQL injection alert is triggered
B. A Vulnerability to SQL injection alert is triggered
C. An Access from a potentially harmful application alert is triggered
D. A Brute force SQL credentials alert is triggered
View answer
Correct Answer: B
Question #5
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.Your company has Azure subscription linked to their Azure Active Directory (Azure AD) tenant.As a Global administrator for the tenant, part of your responsibilities involves managing Azure Security Center settings.You are currently preparing to create a custom sensitivity label.Solution: You start by creating a custom sensitive information type.Does the solution meet the goal?
A. Yes
B. No
View answer
Correct Answer: A
Question #6
Your company has an Azure Container Registry.You have been tasked with assigning a user a role that allows for the downloading of images from the Azure Container Registry. The role assigned should not require more privileges than necessary.Which of the following is the role you should assign?
A. Reader
B. Contributor
C. AcrDelete
D. AcrPull
View answer
Correct Answer: D
Question #7
You have been tasked with creating an Azure key vault using PowerShell. You have been informed that objects deleted from the key vault must be kept for a set period of 90 days.Which two of the following parameters must be used in conjunction to meet the requirement? (Choose two.)
A. EnabledForDeployment
B. EnablePurgeProtection
C. EnabledForTemplateDeployment
D. EnableSoftDelete
View answer
Correct Answer: BD
Question #8
You have an on-premises network and an Azure subscription.You have the Microsoft SQL Server instances shown in the following table.You plan to implement Microsoft Defender for SQL.Which SQL Server instances will be protected by Microsoft Defender for SQL?
A. sql1 and sql2 only
B. sql1, sql2, andsql3 only
C. sql1 sql2 and so
D. sql1, sql2, sql3, and sql4
View answer
Correct Answer: D
Question #9
You have been tasked with applying conditional access policies for your company's current Azure Active Directory (Azure AD).The process involves assessing the risk events and risk levels.Which of the following is the risk level that should be configured for sign ins that originate from IP addresses with dubious activity?
A. one
B. ow
C. edium
D. igh
View answer
Correct Answer: C
Question #10
Which Azure Service is the centralized spot for all Activity Logs, Metrics, Alerts, and Diagnostics for all resources across your subscription?
A. Azure Stream Analytics
B. Event Hub
C. Azure Log Analytics
D. Azure Monitor
View answer
Correct Answer: D
Question #11
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.You are in the process of creating an Azure Kubernetes Service (AKS) cluster. The Azure Kubernetes Service (AKS) cluster must be able to connect to an AzureContainer Registry.You want to make sure that Azure Kubernetes Service (AKS) cluster authenticates to the Azure Container Registry by making use of the auto-generated service principal.Solution: You create an Azure Active Directory (Azure AD) role assignment.Does the solution meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #12
You have an Azure subscription that contains an Azure SQL server named sqlsrv1 and an Azure SQL database named DB1. Sqlsrv1 is configured for Microsoft Entra authentication only.You have the Microsoft Entra identities shown in the following table.Which users can create scoped credentials for DB1?
A. User1 only
B. User1 and User2 only
C. User1, User2, and User3
View answer
Correct Answer: C
Question #13
You have been tasked with configuring an access review, which you plan to assigned to a new collection of reviews. You also have to make sure that the reviews can be reviewed by resource owners.You start by creating an access review program and an access review control.You now need to configure the Reviewers.Which of the following should you set Reviewers to?
A. elected users
B. embers (Self)
C. roup Owners
D. nyone
View answer
Correct Answer: C
Question #14
You have an Azure subscription that contains the virtual machines shown in the following table.
A. Computer2 only
B. Computer1 and Computer2 only
C. Computer2 and Computer3 only
D. Computer1, Computer2, and Computer3
View answer
Correct Answer: D
Question #15
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.Your Company's Azure subscription includes a virtual network that has a single subnet configured.You have created a service endpoint for the subnet, which includes an Azure virtual machine that has Ubuntu Server 18.04 installed.You are preparing to deploy Docker containers to the virtual machine. You need to make sure that the containers can access Azure Storage resources and AzureSQL databases via the service endpoint.You need to perform a task on the virtual machine prior to deploying containers.Solution: You create an AKS Ingress controller.Does the solution meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #16
You have been tasked with configuring an access review, which you plan to assigned to a new collection of reviews. You also have to make sure that the reviews can be reviewed by resource owners.You start by creating an access review program and an access review control.You now need to configure the Reviewers.Which of the following should you set Reviewers to?
A. Selected users
B. Members (Self)
C. Group Owners
D. Anyone
View answer
Correct Answer: C
Question #17
Your company's Azure subscription includes a hundred virtual machines that have Azure Diagnostics enabled.You have been tasked with retrieving the identity of the user that removed a virtual machine fifteen days ago. You have already accessed Azure Monitor.Which of the following options should you use?
A. Application Log
B. Metrics
C. Activity Log
D. Logs
View answer
Correct Answer: C
Question #18
You have an Azure subscription that is associated with an Azure Active Directory (Azure AD) tenant.When a developer attempts to register an app named App1 in the tenant, the developer receives the error message shown in the following exhibit.You need to ensure that the developer can register App1 in the tenant.What should you do for the tenant?
A. Modify the Directory properties
B. Set Enable Security defaults to Yes
C. Configure the Consent and permissions settings for enterprise applications
D. Modify the User settings
View answer
Correct Answer: D
Question #19
Your company makes use of Azure Active Directory (Azure AD) in a hybrid configuration. All users are making use of hybrid Azure AD joined Windows 10 computers.You manage an Azure SQL database that allows for Azure AD authentication.You need to make sure that database developers are able to connect to the SQL database via Microsoft SQL Server Management Studio (SSMS). You also need to make sure the developers use their on-premises Active Directory account for authentication. Your strategy should allow for authentication prompts to be kept to a minimum.Which of the following is the authentication method the developers should use?
A. Azure AD token
B. Azure Multi-Factor authentication
C. Active Directory integrated authentication
View answer
Correct Answer: C
Question #20
You have been tasked with delegate administrative access to your company's Azure key vault.You have to make sure that a specific user is able to add and delete certificates in the key vault. You also have to make sure that access is assigned based on the principle of least privilege.Which of the following options should you use to achieve your goal?
A. A key vault access policy
B. Azure policy
C. Azure AD Privileged Identity Management (PIM)
D. Azure DevOps
View answer
Correct Answer: A
Question #21
You have an Azure virtual machine that runs Ubuntu 16.04-DAILY-LTS.You plan to deploy and configure an Azure Key vault, and enable Azure Disk Encryption for the virtual machine.Which of the following is TRUE with regards to Azure Disk Encryption for a Linux VM?
A. It is NOT supported for basic tier VMs
B. It is NOT supported for standard tier VMs
C. OS drive encryption for Linux virtual machine scale sets is supported
D. Custom image encryption is supported
View answer
Correct Answer: A
Question #22
Your company has configured an Azure Policy when it comes to governance for their Azure virtual machines. They want to deploy this policy via the use of Microsoft Defender for Cloud. Which of the following must they create for this requirement?
A. An initiative
B. A Conditional Access Policy
C. A Management Group
D. A Custom RBAC role
View answer
Correct Answer: A
Question #23
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
A. Yes
B. No
View answer
Correct Answer: B
Question #24
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.Your company has an Active Directory forest with a single domain, named weylandindustries.com. They also have an Azure Active Directory (Azure AD) tenant with the same name.You have been tasked with integrating Active Directory and the Azure AD tenant. You intend to deploy Azure AD Connect.Your strategy for the integration must make sure that password policies and user logon limitations affect user accounts that are synced to the Azure AD tenant, and that the amount of necessary servers are reduced.Solution: You recommend the use of pass-through authentication and seamless SSO with password hash synchronization.Does the solution meet the goal?
A. es
B. o
View answer
Correct Answer: A
Question #25
Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish ifthe solution satisfies the requirements.Your company has an Active Directory forest with a single domain, named weylandindustries.com. They also have an Azure Active Directory (Azure AD) tenantwith the same name.You have been tasked with integrating Active Directory and the Azure AD tenant. You intend to deploy Azure AD Connect.Your strategy for the integration must make sure that password policies and user logon limitations affect user accounts that are synced to the Azure AD tenant,and that the amount of necessary servers are reduced.Solution: You recommend the use of federation with Active Directory Federation Services (AD FS).Does the solution meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #26
You have an Azure subscription. You create a new virtual network named VNet1. You plan to deploy an Azure web app named App1 that will use VNet1 and will be reachable by using private IP addresses. The solution must support inbound and outbound network traffic. What should you do?
A. Create an Azure App Service Hybrid Connection
B. Configure regional virtual network integration
C. Create an App Service Environment
D. Create an Azure application gateway
View answer
Correct Answer: C
Question #27
You need to meet the identity and access requirements for Group1. What should you do?
A. Add a membership rule to Group1
B. Delete Group1
C. Modify the membership rule of Group1
D. Change the membership type of Group1 to Assigned
View answer
Correct Answer: D
Question #28
You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains a user named User1.You plan to publish several apps in the tenant.You need to ensure that User1 can grant admin consent for the published apps.Which two possible user roles can you assign to User1 to achieve this goal? Each correct answer presents a complete solution.NOTE: Each correct selection is worth one point.
A. Security administrator
B. Cloud application administrator
C. Application administrator
D. User administrator
E. Application developer
View answer
Correct Answer: BC
Question #29
Your company plans to create separate subscriptions for each department. Each subscription will be associated to the same Azure Active Directory (Azure AD) tenant.You need to configure each subscription to have the same role assignments.What should you use?
A. Azure Security Center
B. Azure Policy
C. Azure AD Privileged Identity Management (PIM)
D. Azure Blueprints
View answer
Correct Answer: D
Question #30
You need to meet the technical requirements for VNetwork1.What should you do first?
A. reate a new subnet on VNetwork1
B. emove the NSGs from Subnet11 and Subnet13
C. ssociate an NSG to Subnet12
D. onfigure DDoS protection for VNetwork1
View answer
Correct Answer: A
Question #31
You have been tasked with delegate administrative access to your company's Azure key vault.You have to make sure that a specific user can set advanced access policies for the key vault. You also have to make sure that access is assigned based on the principle of least privilege.Which of the following options should you use to achieve your goal?
A. Azure Information Protection
B. RBAC
C. Azure AD Privileged Identity Management (PIM)
D. Azure DevOps
View answer
Correct Answer: B
Question #32
After creating a new Azure subscription, you are tasked with making sure that custom alert rules can be created in Azure Security Center.You have created an Azure Storage account.Which of the following is the action you should take?
A. You should make sure that Azure Active Directory (Azure AD) Identity Protection is removed
B. You should create a DLP policy
C. You should create an Azure Log Analytics workspace
D. You should make sure that Security Center has the necessary tier configured
View answer
Correct Answer: C
Question #33
In the context of alerts, you can create an Action Group. Which of the following is not an Action Type that can exist inside an Action Group?
A. E-mail
B. Voice
C. Push notification
D. SMS text message
E. Facebook Messenger message
View answer
Correct Answer: E
Question #34
Your company recently created an Azure subscription. You have, subsequently, been tasked with making sure that you are able to secure Azure AD roles bymaking use of Azure Active Directory (Azure AD) Privileged Identity Management (PIM).Which of the following actions should you take FIRST?
A. You should sign up Azure Active Directory (Azure AD) Privileged Identity Management (PIM) for Azure AD roles
B. You should consent to Azure Active Directory (Azure AD) Privileged Identity Management (PIM)
C. You should discover privileged roles
D. You should discover resources
View answer
Correct Answer: C
Question #35
You have an Azure subscription. You plan to create a custom role-based access control (RBAC) role that will provide permission to read the Azure Storage account. Which property of the RBAC role definition should you configure? To 'Read a storage account', ie. list the blobs in the storage account, you need an 'Action' permission. To read the data in a storage account, ie. open a blob, you need a 'DataAction' permission. https://docs.microsoft.com/en-us/azure/role-based-access-control/role-definitions
A. NotActions []
B. DataActions []
C. AssignableScopes []
D. Actions []
View answer
Correct Answer: D
Question #36
You have been tasked with applying conditional access policies for your company's current Azure Active Directory (Azure AD).The process involves assessing the risk events and risk levels.Which of the following is the risk level that should be configured for sign ins that originate from IP addresses with dubious activity?
A. None
B. Low
C. Medium
D. High
View answer
Correct Answer: C
Question #37
You need to ensure that users can access VM0. The solution must meet the platform protection requirements.What should you do?
A. ove VM0 to Subnet1
B. n Firewall, configure a network traffic filtering rule
C. ssign RT1 to AzureFirewallSubnet
D. n Firewall, configure a DNAT rule
View answer
Correct Answer: A
Question #38
You need to consider the underlined segment to establish whether it is accurate.You have been tasked with creating a different subscription for each of your company's divisions. However, the subscriptions will be linked to a single Azure ActiveDirectory (Azure AD) tenant.You want to make sure that each subscription has identical role assignments.You make use of Azure AD Privileged Identity Management (PIM).Select `No adjustment required` if the underlined segment is accurate. If the underlined segment is inaccurate, select the accurate option.
A. No adjustment required
B. Azure Blueprints
C. Conditional access policies
D. Azure DevOps
View answer
Correct Answer: B
Question #39
You have an Azure subscription that contains an instance of Azure Firewall Standard named AzFWL You need to identify whether you can use the following features with AzFW1: * TLS inspection * Threat intelligence * The network intrusion detection and prevention systems (IDPS) What can you use?
A. ATLS inspection only
B. Bthreat intelligence only
C. CTLS inspection and the IDPS only
D. Dthreat intelligence and the IDPS only
E. ETLS inspection, threat intelligence, and the IDPS
View answer
Correct Answer: A

View The Updated Microsoft Exam Questions

SPOTO Provides 100% Real Microsoft Exam Questions for You to Pass Your Microsoft Exam!

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us