AZ-500 Exam Details

  • Exam Code
    :AZ-500
  • Exam Name
    :Microsoft Azure Security Technologies
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :626 Q&As
  • Last Updated
    :Jul 12, 2026

Microsoft AZ-500 Online Questions & Answers

  • Question 331:

    HOTSPOT

    You have an Azure key vault.

    You need to delegate administrative access to the key vault to meet the following requirements:

    1. Provide a user named User1 with the ability to set access policies for the key vault.

    2. Provide a user named User2 with the ability to add and delete certificates in the key vault.

    3. Use the principle of least privilege.

    What should you use to assign access to each user? To answer, select the appropriate options in the answer area.

    NOTE: Each correct selection is worth one point.

  • Question 332:

    You have an Azure subscription that contains an Azure SQL server named SQL1. SQL1 contains an Azure SQL database named DB1.

    You need to use Microsoft Defender for Cloud to complete a vulnerability assessment for DB1.

    What should you do first?

    A. From Advanced Threat Protection types, select SQL injection vulnerability.
    B. Configure the Send scan report to setting.
    C. Set Periodic recurring scans to ON.
    D. Enable the Microsoft Defender for SQL plan.

  • Question 333:

    SIMULATION

    You need to ensure that the rg1lod10598168n1 Azure Storage account is encrypted by using a key stored in the KeyVault10598168 Azure key vault.

    To complete this task, sign in to the Azure portal.

    A. See the explanation below.

  • Question 334:

    A support engineer plans to perform several Azure management tasks by using the Azure CLI.

    You install the CLI on a computer.

    You need to tell the support engineer which tools to use to run the CLI.

    Which two tools should you instruct the support engineer to use? Each correct answer presents a complete solution.

    NOTE: Each correct selection is worth one point.

    A. Command Prompt
    B. Azure Resource Explorer
    C. Windows PowerShell
    D. Windows Defender Firewall
    E. Network and Sharing Center

  • Question 335:

    You have an Azure subscription that contains a resource group named RG1 and the identities shown in the following table.

    You assign Group4 the Contributor role for RG1.

    Which identities can you add to Group4 as members?

    A. User1 only
    B. User1 and Group3 only
    C. User1, Group1, and Group3 only
    D. User1, Group2, and Group3 only
    E. User1, Group1, Group2, and Group3

  • Question 336:

    HOTSPOT

    You have an Azure subscription that contains an Azure Active Directory (Azure AD) tenant named contoso.com. The tenant contains the users shown in the following table.

    You create a resource group named RG1.

    Which users can modify the permissions for RG1 and which users can create virtual networks in RG1? To answer, select the appropriate options in the answer area.

    NOTE: Each correct selection is worth one point.

  • Question 337:

    You have an Azure subscription linked to an Azure AD tenant named contoso.com. Contoso.com contains a user named User1 and an Azure web app named App1.

    You plan to enable User1 to perform the following tasks:

    1. Configure contoso.com to use Microsoft Entra Verified ID.

    2. Register App1 in contoso.com.

    You need to identify which roles to assign to User1. The solution must use the principle of least privilege.

    Which two roles should you identify? Each correct answer presents part of the solution.

    NOTE: Each correct selection is worth one point.

    A. Authentication Policy Administrator
    B. Authentication Administrator
    C. Cloud App Security Administrator
    D. Application Administrator
    E. User Administrator

  • Question 338:

    HOTSPOT

    You have an on-premises server named Server1.

    You have an Azure subscription that contains a Microsoft Sentinel workspace named Sentinel 1.

    You install the Windows Firewall solution in Sentinel1.

    You need to use Microsoft Sentinel to monitor Windows Defender Firewall on Server1.

    What should you install on Server1, and what should you create in the Azure subscription? To answer, select the appropriate options in the answer area.

    NOTE: Each correct selection is worth one point.

  • Question 339:

    You need to implement the planned change for storage2. The solution must meet the technical requirements for storage encryption.

    A. Create an encryption scope in storage2.
    B. Configure storage2 to use an account encryption key.
    C. Assign an Azure role-based access control (Azure RBAC) role to storage2.
    D. Enable purge protection for storage2.

  • Question 340:

    SIMULATION

    You need to ensure that web11597200 is protected from malware by using Microsoft Antimalware for Virtual Machines and is scanned every Friday at 01:00.

    To complete this task, sign in to the Azure portal.

    A. See the explanation below.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your AZ-500 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.