AZ-500 Sample Questions

AZ-500 Sample Questions & Answers

Governance policies, Defender for Cloud posture and Sentinel threat protection carry the most weight, alongside securing compute, storage and SQL databases, network security for private and public access, and controlling identity and Entra application access.

Launch the full AZ-500 simulator →

Showing 10 of 20 free samples.

  1. Question 1

    Your company recently created an Azure subscription.

    You have been tasked with making sure that a specified user is able to implement Azure AD Privileged Identity Management (PIM).

    Which of the following is the role you should assign to the user?

    Show answer & explanation

    Correct answer: A

    Explanation:
    To start using PIM in your directory, you must first enable PIM. 1. Sign in to the Azure portal as a Global Administrator of your directory.
    You must be a Global Administrator with an organizational account (for example, ©yourdomain.com), not a Microsoft account (for example, ©outlook.com), to enable PIM for a directory.
    Scenario: Technical requirements include: Enable Azure AD Privileged Identity Management (PIM) for contoso.com Reference:
    https://docs.microsoft.com/bs-latn-ba/azure/active-directory/privileged-identity-management/pim-getting-started

  2. Question 2

    You need to consider the underlined segment to establish whether it is accurate.

    You have configured an Azure Kubernetes Service (AKS) cluster in your testing environment.

    You are currently preparing to deploy the cluster to the production environment.

    After disabling HTTP application routing, you want to replace it with an application routing solution that allows for reverse proxy and TLS termination for AKS services via a solitary IP address.

    You must create an AKS Ingress controller.

    Select “No adjustment required” if the underlined segment is accurate. If the underlined segment is inaccurate, select the accurate option.

    Show answer & explanation

    Correct answer: A

    Explanation:
    An ingress controller is a piece of software that provides reverse proxy, configurable traffic routing, and TLS termination for Kubernetes services.
    Reference:
    https://docs.microsoft.com/en-us/azure/aks/ingress-tls

  3. Question 3

    Your company makes use of Azure Active Directory (Azure AD) in a hybrid configuration. All users are making use of hybrid Azure AD joined Windows 10 computers.

    You manage an Azure SQL database that allows for Azure AD authentication.

    You need to make sure that database developers are able to connect to the SQL database via Microsoft SQL Server Management Studio (SSMS). You also need to make sure the developers use their on-premises Active Directory account for authentication. Your strategy should allow for authentication prompts to be kept to a minimum.

    Which of the following is the authentication method the developers should use?

    Show answer & explanation

    Correct answer: C

    Explanation:
    Azure AD can be the initial Azure AD managed domain. Azure AD can also be an on-premises Active Directory Domain Services that is federated with the Azure AD.
    Using an Azure AD identity to connect using SSMS or SSDT The following procedures show you how to connect to a SQL database with an Azure AD identity using SQL Server Management Studio or SQL Server Database Tools.
    Active Directory integrated authentication Use this method if you are logged in to Windows using your Azure Active Directory credentials from a federated domain.1. Start Management Studio or Data Tools and in the Connect to Server (or Connect to Database Engine) dialog box, in the Authentication box, select Active Directory - Integrated. No password is needed or can be entered because your existing credentials will be presented for the connection.

  4. Question 4

    You make use of Azure Resource Manager templates to deploy Azure virtual machines.

    You have been tasked with making sure that Windows features that are not in use, are automatically inactivated when instances of the virtual machines are provisioned.

    Which of the following actions should you take?

    Show answer & explanation

    Correct answer: B

    Explanation:
    You can use Azure Automation State Configuration to manage Azure VMs (both Classic and Resource Manager), on-premises VMs, Linux machines, AWS VMs, and on-premises physical machines.
    Note: Azure Automation State Configuration provides a DSC pull server similar to the Windows Feature DSC-Service so that target nodes automatically receive configurations, conform to the desired state, and report back on their compliance. The built-in pull server in Azure Automation eliminates the need to set up and maintain your own pull server. Azure Automation can target virtual or physical Windows or Linux machines, in the cloud or on-premises.
    Reference:
    https://docs.microsoft.com/en-us/azure/automation/automation-dsc-getti n g-sta rted

  5. Question 5

    Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.

    Your Company’s Azure subscription includes a virtual network that has a single subnet configured.

    You have created a service endpoint for the subnet, which includes an Azure virtual machine that has Ubuntu Server 18.04 installed.

    You are preparing to deploy Docker containers to the virtual machine. You need to make sure that the containers can access Azure Storage resources and Azure SQL databases via the service endpoint.

    You need to perform a task on the virtual machine prior to deploying containers.

    Solution: You create an AKS Ingress controller.

    Does the solution meet the goal?

    Show answer & explanation

    Correct answer: B

    The solution does not meet the requirements. Virtual network configuration and security implementation require specific approaches that the proposed solution cannot adequately provide for the intended use case.

  6. Question 6

    Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.

    Your company has an Azure subscription that includes an Azure key vault. You have previously created a secret in the key vault.
    After an application developer registers an application in Azure Active Directory (Azure AD), you are instructed to make sure that the application is able to use the secret you created.

    Solution: You should create a role in Azure AD.

    Does the solution meet the goal?

    Show answer & explanation

    Correct answer: A

    Explanation:
    Azure Key Vault provides a way to securely store credentials and other keys and secrets, but your code needs to authenticate to Key Vault to retrieve them.
    Managed identities for Azure resources overview make solving this problem simpler, by giving Azure services an automatically managed identity in Azure Active Directory (Azure AD). You can use this identity to authenticate to any service that supports Azure AD authentication, including Key Vault, without having any credentials in your code.
    Example: How a system-assigned managed identity works with an Azure VM After the VM has an identity, use the service principal information to grant the VM access to Azure resources. To call Azure Resource Manager, use role-based access control (RBAC) in Azure AD to assign the appropriate role to the VM service principal. To call Key Vault, grant your code access to the specific secret or key in Key Vault.
    Reference:
    https://docs.microsoft.com/en-us/azure/key-vault/quick-create-net
    https://docs.microsoft.com/en-us/azure/active-directory/managed-identities-azure-resources/overview

  7. Question 7

    You have been tasked with applying conditional access policies for your company’s current Azure Active Directory (Azure AD).

    The process involves assessing the risk events and risk levels.

    Which of the following is the risk level that should be configured for users that have leaked credentials?

    Show answer & explanation

    Correct answer: B

    Low risk level is appropriate for implementing conditional access policies for sign-in risk. This threshold allows organizations to provide additional security controls without being overly restrictive, balancing security with user experience. Higher risk levels would be too restrictive for initial implementation.

  8. Question 8

    You have been tasked with delegate administrative access to your company’s Azure key vault.

    You have to make sure that a specific user can set advanced access policies for the key vault. You also have to make sure that access is assigned based on the principle of least privilege.

    Which of the following options should you use to achieve your goal?

    Show answer & explanation

    Correct answer: B

    RBAC (Role-Based Access Control) is the correct approach for delegating administrative access to Azure Key Vault while following the principle of least privilege. RBAC allows you to assign specific permissions to users for key vault operations, including setting advanced access policies. Azure AD PIM provides additional just-in-time access controls but RBAC is the foundational access management system.

  9. Question 9

    You have been tasked with configuring an access review, which you plan to assigned to a new collection of reviews. You also have to make sure that the reviews can be reviewed by resource owners.

    You start by creating an access review program and an access review control.

    You now need to configure the Reviewers.

    Which of the following should you set Reviewers to?

    Show answer & explanation

    Correct answer: C

    Explanation:
    In the Reviewers section, select either one or more people to review all the users in scope. Or you can select to have the members review their own access. If the resource is a group, you can ask the group owners to review.Reference:
    https://docs.microsoft.com/en-us/azure/active-directory/governance/create-access-review https://docs.microsoft.com/en-us/azure/active-directory/governance/manage-programs-controls

  10. Question 10

    You have been tasked with altering a current security playbook via Azure Security Center.

    You want make sure that the playbook sends email messages to a distribution group, instead of a user.

    Which of the following options should you use to achieve your goal?

    Show answer & explanation

    Correct answer: D

    Explanation:
    You can change an existing playbook in Security Center to add an action, or conditions. To dothat you just need to click on the name of the playbook that you want to change, in the Playbooks tab, and Logic App Designer opens up.
    Reference:
    https://docs.microsoft.com/en-us/azure/security-center/security-center-playbooks

Ready for the real thing?

The full AZ-500 simulator has every exam-style question, timed mode, and instant scoring.

Go to the AZ-500 simulator →