Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Microsoft AZ-500 Practice Exam with Questions & Answers

Questions 1

You have an app that uses an Azure SQL database.

You need to be notified if a SQL injection attack is launched against the database.

What should you do?

Options:
A.

Modify the Diagnostics settings for the database.

B.

Deploy the SQL Health Check solution in Azure Monitor.

C.

Enable Azure Defender for SQL for the database.

D.

Enable server-level auditing for the database.

Microsoft AZ-500 Premium Access
Questions 2

Your network contains an on-premises Active Directory domain named corp.contoso.com.

You have an Azure subscription named Sub1 that is associated to an Azure Active Directory (Azure AD) tenant named contoso.com.

You sync all on-premises identities to Azure AD.

You need to prevent users who have a givenName attribute that starts with TEST from being synced to Azure AD. The solution must minimize administrative effort.

What should you use?

Options:
A.

Synchronization Rules Editor

B.

Web Service Configuration Tool

C.

the Azure AD Connect wizard

D.

Active Directory Users and Computers

Questions 3

You implement the planned changes for ASG1 and ASG2.

In which NSGs can you use ASG1. and the network interfaces of which virtual machines can you assign to ASG2?

AZ-500 Question 3

Options:
Questions 4

You have an Azure Container Registry named Registry1.

You add role assignment for Registry1 as shown in the following table.

AZ-500 Question 4

Which users can upload images to Registry1 and download images from Registry1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-500 Question 4

Options:
Questions 5

You have an Azure subscription that contains the custom roles shown in the following table.

AZ-500 Question 5

In the Azure portal, you plan to create new custom roles by cloning existing roles. The new roles will be configured as shown in the following table.

AZ-500 Question 5

Which roles can you clone to create each new role? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-500 Question 5

Options:
Questions 6

You have an Azure subscription that contains an Azure key vault named KeyVault1 and the virtual machines shown in the following table.

AZ-500 Question 6

You set the Key Vault access policy to Enable access to Azure Disk Encryption for volume encryption.

KeyVault1 is configured as shown in the following exhibit.

AZ-500 Question 6

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

AZ-500 Question 6

Options:
Questions 7

You have an Azure subscription that contains an Azure Active Directory (Azure AD) tenant and a user named User1.

The App registrations settings for the tenant are configured as shown in the following exhibit.

AZ-500 Question 7

You plan to deploy an app named App1.

You need to ensure that User1 can register App1 in Azure AD. The solution must use the principle of least privilege.

Which role should you assign to User1?

Options:
A.

App Configuration Data Owner for the subscription

B.

Managed Application Contributor for the subscription

C.

Cloud application administrator in Azure AD

D.

Application developer in Azure AD.

Questions 8

You have an Azure subscription.

You plan to deploy a new Conditional Access policy named CAPolicy1.

You need to use the What If tool to evaluate how CAPolicy1 will affect uter1. The solution must minimize the impact of CAPolicy1 on the users.

To what should you set the Enable policy setting for CAPolicy1?

Options:
A.

Oft

B.

On

C.

Report only

Questions 9

You are configuring an Azure Kubernetes Service (AKS) cluster that will connect to an Azure Container Registry.

You need to use the auto-generated service principal to authenticate to the Azure Container Registry.

What should you create?

Options:
A.

an Azure Active Directory (Azure AD) group

B.

an Azure Active Directory (Azure AD) role assignment

C.

an Azure Active Directory (Azure AD) user

D.

a secret in Azure Key Vault

Questions 10

You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table.

AZ-500 Question 10

The tenant contains the named locations shown in the following table.

AZ-500 Question 10

You create the conditional access policies for a cloud app named App1 as shown in the following table.

AZ-500 Question 10

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

AZ-500 Question 10

Options:
Exam Code: AZ-500
Certification Provider: Microsoft
Exam Name: Microsoft Azure Security Technologies
Last Update: Jul 10, 2025
Questions: 460