Microsoft AZ-500 Online Practice
Questions and Exam Preparation
AZ-500 Exam Details
Exam Code
:AZ-500
Exam Name
:Microsoft Azure Security Technologies
Certification
:Microsoft Certifications
Vendor
:Microsoft
Total Questions
:626 Q&As
Last Updated
:Jul 12, 2026
Microsoft AZ-500 Online Questions &
Answers
Question 411:
You company has an Azure subscription named Sub1. Sub1 contains an Azure web app named WebApp1 that uses Azure Application Insights. WebApp1 requires users to authenticate by using OAuth 2.0 client secrets.
Developers at the company plan to create a multi-step web test app that preforms synthetic transactions emulating user traffic to Web App1.
You need to ensure that web tests can run unattended.
What should you do first?
A. In Microsoft Visual Studio, modify the .webtest file. B. Upload the .webtest file to Application Insights. C. Register the web test app in Azure AD. D. Add a plug-in to the web test app.
You create a virtual network that contains one subnet. On the subnet, you provision the virtual machines shown in the following table.
Currently, you have not provisioned any network security groups (NSGs).
You need to implement network security to meet the following requirements:
1. Allow traffic to VM4 from VM3 only.
2. Allow traffic from the Internet to VM1 and VM2 only.
3. Minimize the number of NSGs and network security rules.
How many NSGs and network security rules should you create? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
1) You can only assign 1 NSG to a subnet, and there is only one subnet in the description. So Box 1 is 1 2) Number of rules in NSG can be any, they are processed in sequence.
Rule 1: You can have AppGroup3 as the source and AppGroup4 as destination in one rule then allow traffic.
Rule 2: You can have Service Tag "Internet" as a source and AppGroup12 as the destination. then allow traffic.
Rule 3: YOu can have source as the subnet range and destination as subnet range then deny all traffic, so only above rules will be allowing traffic.
Not 2: You cannot specify multiple service tags or application groups) in a security rule.
You have an Azure AD tenant that contains a user named User1.
You purchase an app named App1.
User1 needs to publish App1 by using Azure AD Application Proxy.
Which role should you assign to User1?
A. Cloud application administrator B. Application administrator C. Hybrid identity administrator D. Cloud App Security Administrator
B. Application administrator
Explanation
To add an on-premises application to Azure AD, you need:
A Microsoft Azure AD premium subscription
An application administrator account
User identities must be synchronized from an on-premises directory or created directly within your Azure AD tenants. Identity synchronization allows Azure AD to pre-authenticate users before granting them access to App Proxy published applications and to have the necessary user identifier information to perform single sign-on (SSO).
You plan to create two custom roles named Role1 and Role2.
The custom roles will be used to perform the following tasks:
1. Members of Role1 will manage application security groups.
2. Members of Role2 will manage Azure Bastion.
You need to add permissions to the custom roles.
Which resource provider should you use for each role? To answer, drag the appropriate resource providers to the correct roles. Each resource provider may be used, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Select and Place:
Question 416:
You have an Azure subscription.
You create a new virtual network named VNet1.
You plan to deploy an Azure web app named App1 that will use VNet1 and will be reachable by using private IP addresses. The solution must support inbound and outbound network traffic.
What should you do?
A. Create an Azure App Service Hybrid Connection. B. Configure regional virtual network integration. C. Create an App Service Environment D. Create an Azure application gateway.
C. Create an App Service Environment
Explanation
Create an App Service Environment
An App Service Environment can host applications from only one customer, and they do so on one of their virtual networks. Customers have fine-grained control over inbound and outbound application network traffic.
There are no networking dependencies on the customer's virtual network. You can secure all inbound and outbound traffic and route outbound traffic as you want.
Note: Private virtual IP (VIP) addresses, available only in the internal VNet mode, are used to connect from within the network to API Management endpoints - gateways, the developer portal, and the management plane for direct API access. You can use them for setting up DNS records within the network.
Note 2: The App Service Environment feature is a deployment of Azure App Service into a single subnet on a virtual network. When you deploy an app into an App Service Environment, the app is exposed on the inbound address that's assigned to the App Service Environment. If your App Service Environment is deployed with an internal virtual IP (VIP) address, the inbound address for all the apps will be an address in the App Service Environment subnet. If your App Service Environment is deployed with an external VIP address, the inbound address will be an internet-addressable address, and your apps will be in a public Domain Name System.
Incorrect:
Not A: Hybrid Connections is both a service in Azure and a feature in Azure App Service. As a service, it has uses and capabilities beyond those that are used in App Service.
Within App Service, Hybrid Connections can be used to access application resources in any network that can make outbound calls to Azure over port 443.
You have a Microsoft Entra tenant named contoso.com that contains a user named User1.
You register an app named App1 in contoso.com and create an app role named Role1.
You need to assign Role1 to User1.
What should you configure on the Enterprise applications blade of App1 in the Microsoft Entra admin center?
A. API permissions B. App roles C. Users and groups D. Roles and administrators
C. Users and groups
Question 419:
HOTSPOT
You have an Azure Active Directory (Azure AD) tenant named contoso.com. The tenant contains the users shown in the following table.
You configure an access review named Review1 as shown in the following exhibit.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Box 1: User3 only
Use the Members (self) option to have the users review their own role assignments.
Box 2: User3 will receive a confirmation request
Use the Should reviewer not respond list to specify what happens for users that are not reviewed by the reviewer within the review period. This setting does not impact users who have been reviewed by the reviewers manually. If the final reviewer's decision is Deny, then the user's access will be removed.
No change - Leave user's access unchanged
Remove access - Remove user's access
Approve access - Approve user's access
Take recommendations - Take the system's recommendation on denying or approving the user's continued access
In this case, User2 can enable Azure PIM. How about user3? Yes it can because when MFA is asked the MFA state is changed to Enabled and User3 just needs to complete MFA setup before it can consent and enable PIM.
Nowadays, the certification exams become more and more important and required by more and more
enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare
for the exam in a short time with less efforts? How to get a ideal result and how to find the
most reliable resources? Here on Vcedump.com, you will find all the answers.
Vcedump.com provide not only Microsoft exam questions,
answers and explanations but also complete assistance on your exam preparation and certification
application. If you are confused on your AZ-500 exam preparations
and Microsoft certification application, do not hesitate to visit our
Vcedump.com to find your solutions here.