AZ-500 Exam Details

  • Exam Code
    :AZ-500
  • Exam Name
    :Microsoft Azure Security Technologies
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :626 Q&As
  • Last Updated
    :Jul 12, 2026

Microsoft AZ-500 Online Questions & Answers

  • Question 371:

    HOTSPOT

    You have an azure active Directory (Azure AD) tenant that contains the resources shown in the following table.

    User2 is the owner of Group2.

    The user and group settings for App1 are configured as shown in the following exhibit.

    You enable self-service application access for App1 as shown in the following exhibit.

    User3 is configured to approve access to App1.

    After you enable self-service application access for App1, who will be configured as the Group2 owner and who will be configured as the App1 users? To answer, select the appropriate options in the answer area.

    NOTE: Each correct selection is worth one point.

  • Question 372:

    You have an Azure subscription that contains an Azure SQL Database logic server named SQL1 and an Azure virtual machine named VM1. VM1 uses a private IP address only.

    The Firewall and virtual networks settings for SQL1 are shown in the following exhibit.

    You need to ensure that VM1 can connect to SQL1. The solution must use the principle of least privilege.

    What should you do?

    A. Add an existing virtual network.
    B. Set Connection Policy to Proxy.
    C. Create a new firewall rule.
    D. Set Allow Azure services and resources to access this server to Yes.

  • Question 373:

    DRAG DROP

    You have an Azure subscription that contains the following resources:

    1. A network virtual appliance (NVA) that runs non-Microsoft firewall software and routes all outbound traffic from the virtual machines to the internet

    2. An Azure function that contains a script to manage the firewall rules of the NVA

    3. Azure Security Center standard tier enabled for all virtual machines

    4. An Azure Sentinel workspace

    5. 30 virtual machines

    You need to ensure that when a high-priority alert is generated in Security Center for a virtual machine, an incident is created in Azure Sentinel and then a script is initiated to configure a firewall rule for the NVA.

    How should you configure Azure Sentinel to meet the requirements? To answer, drag the appropriate components to the correct requirements. Each component may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

    NOTE: Each correct selection is worth one point.

    Select and Place:

  • Question 374:

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

    You have a hybrid configuration of Azure Active Directory (Azure AD).

    You have an Azure HDInsight cluster on a virtual network.

    You plan to allow users to authenticate to the cluster by using their on-premises Active Directory credentials.

    You need to configure the environment to support the planned authentication.

    Solution: You create a site-to-site VPN between the virtual network and the on-premises network.

    Does this meet the goal?

    A. Yes
    B. No

  • Question 375:

    HOTSPOT

    You have an Azure subscription that contains an Azure key vault named Vault1.

    On January 1, 2019, Vault1 stores the following secrets.

    Which can each secret be used by an application? To answer, select the appropriate options in the answer area.

    NOTE: Each correct selection is worth one point.

  • Question 376:

    You have an Azure subscription.

    You plan to use Microsoft Defender for Cloud to provide AI security posture management capabilities.

    You need to recommend a Defender for Cloud plan that supports the deployment requirements. The solution must minimize costs.

    What should you recommend?

    A. Microsoft Defender for App Service
    B. Microsoft Defender for APIs
    C. Foundational Cloud Security Posture Management (CSPM)
    D. Defender Cloud Security Posture Management (CSPM)

  • Question 377:

    SIMULATION

    You need to ensure that a user named Danny1234578 can sign in to any SQL database on a Microsoft SQL server named web1234578 by using SQL Server

    Management Studio (SSMS) and Azure Active Directory (Azure AD) credentials.

    To complete this task, sign in to the Azure portal.

    A. See the explanation below.
    B. PlaceHolder
    C. PlaceHolder
    D. PlaceHolder

  • Question 378:

    You have an Azure subscription that is linked to an Azure Active Directory (Azure AD) tenant.

    From the Azure portal, you register an enterprise application.

    Which additional resource will be created in Azure AD?

    A. a service principal
    B. an X.509 certificate
    C. a managed identity
    D. a user account

  • Question 379:

    From the Azure portal, you are configuring an Azure policy.

    You plan to assign policies that use the DeployIfNotExist, AuditIfNotExist, Append, and Deny effects.

    Which effect requires a managed identity for the assignment?

    A. AuditIfNotExist
    B. Append
    C. DeployIfNotExist
    D. Deny

  • Question 380:

    HOTSPOT

    You have an Azure subscription that contains the resources shown in the following table.

    User1 is a member of Group1. Group1 and User2 are assigned the Key Vault Contributor role for Vault1.

    On January 1, 2019, you create a secret in Vault1. The secret is configured as shown in the exhibit. (Click the Exhibit tab.)

    User2 is assigned an access policy to Vault1. The policy has the following configurations:

    Key Management Operations: Get, List, and Restore Cryptographic Operations: Decrypt and Unwrap Key Secret Management Operations: Get, List, and Restore

    Group1 is assigned an access to Vault1. The policy has the following configurations:

    Key Management Operations: Get and Recover

    Secret Management Operations: List, Backup, and Recover

    For each of the following statements, select Yes if the statement is true. Otherwise, select No.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your AZ-500 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.