AZ-500 Exam Prep Free practice test →

Free AZ-500 Practice Questions

10 free, exam-style Microsoft Certified: Azure Security Engineer Associate (AZ-500) (AZ-500) practice questions with answers and explanations. No signup required. Work through them below, then take the full free AZ-500 practice test to study every exam domain.

The AZ-500 exam has 60 questions and runs 1 hour 40 minutes.

These 10 free AZ-500 questions are organized by exam domain, so you can see how each part of the Microsoft Certified: Azure Security Engineer Associate (AZ-500) blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Secure identity and access (15-20%)

Question 1

An Azure Function must read a database connection string stored as a secret in Azure Key Vault. Company policy forbids storing any credential in application settings or code. Which approach meets the requirement with the LEAST privilege?

  1. Enable a system-assigned managed identity on the Function and grant it the Key Vault Secrets User role
  2. Register an application, generate a client secret, and store that secret in the Function's app configuration
  3. Grant the Function's managed identity the Key Vault Administrator role over the vault
  4. Create a user delegation SAS for the secret and reference the SAS from the Function
Show answer & explanation

Correct answer: A - Enable a system-assigned managed identity on the Function and grant it the Key Vault Secrets User role

Question 2

In Microsoft Entra Privileged Identity Management (PIM), a user is given an ELIGIBLE assignment to the Contributor role for a subscription. What must the user do before they can use the role's permissions?

  1. Wait for an administrator to convert the eligible assignment to an active one
  2. Sign out and back in so the new permissions appear in their token
  3. Activate the role, satisfying any configured MFA, justification, or approval
  4. Nothing; an eligible assignment already grants standing access
Show answer & explanation

Correct answer: C - Activate the role, satisfying any configured MFA, justification, or approval

Question 3

Microsoft Entra ID Protection flags a single sign-in as high risk because it came from an anonymous IP address, although the account shows no other signs of compromise. Which control BEST lets the legitimate user prove their identity and clear the risk in real time?

  1. A user risk policy requiring a secure password change
  2. A sign-in risk policy requiring multifactor authentication
  3. A policy that blocks the account until an administrator investigates
  4. An access review of the user's group memberships
Show answer & explanation

Correct answer: B - A sign-in risk policy requiring multifactor authentication

Question 4

A user needs to fully manage every resource in a resource group but must NOT be able to grant other people access to those resources. Which built-in role follows the principle of least privilege?

  1. Contributor
  2. Owner
  3. User Access Administrator
  4. Reader
Show answer & explanation

Correct answer: A - Contributor

Domain 2: Secure networking (20-25%)

Question 5

Administrators must be able to RDP to virtual machines that have no public IP address, without opening inbound port 3389 to the internet. Which service is purpose-built for this requirement?

  1. A public load balancer with an inbound NAT rule to each VM
  2. Azure Bastion
  3. A site-to-site VPN gateway between on-premises and the VNet
  4. A just-in-time VM access request in Microsoft Defender for Cloud
Show answer & explanation

Correct answer: B - Azure Bastion

Question 6

A storage account must be reachable ONLY through a private IP address inside a virtual network, and its public endpoint must be disabled entirely. Which feature satisfies this requirement?

  1. A service endpoint added to the subnet
  2. A network security group that allows only the VNet
  3. A private endpoint for the storage account
  4. A storage firewall rule that lists the VNet
Show answer & explanation

Correct answer: C - A private endpoint for the storage account

Question 7

A public-facing web application hosted on Azure must be protected against SQL injection and cross-site scripting. Which control is designed for this purpose?

  1. A network security group with tightened inbound port rules
  2. A web application firewall on Application Gateway or Front Door
  3. Azure DDoS Protection on the virtual network
  4. Azure Firewall deployed in the hub virtual network
Show answer & explanation

Correct answer: B - A web application firewall on Application Gateway or Front Door

Question 8

Two rules in a network security group could match an inbound packet: a rule at priority 200 that ALLOWS it and a rule at priority 300 that DENIES it. What does the NSG do with the packet?

  1. Allows it, because the lower priority number is evaluated first and matching stops
  2. Denies it, because an explicit deny rule always overrides a conflicting allow rule
  3. Denies it, because the default DenyAllInbound rule takes precedence
  4. Evaluates both rules and applies the more restrictive of the two
Show answer & explanation

Correct answer: A - Allows it, because the lower priority number is evaluated first and matching stops

Question 9

In an Azure Firewall policy, an administrator configures DNAT rules, network rules, and application rules. Ignoring threat intelligence-based filtering, in which order does the firewall process these rule types?

  1. Application rules, then network rules, then DNAT rules
  2. Network rules, then DNAT rules, then application rules
  3. Strictly by priority number, regardless of the rule type
  4. DNAT rules, then network rules, then application rules
Show answer & explanation

Correct answer: D - DNAT rules, then network rules, then application rules

Domain 3: Secure compute, storage, and databases (20-25%)

Question 10

An application stores national ID numbers in a column of an Azure SQL database. The requirement states that even database administrators must never see the plaintext values, and the encryption keys must stay under the application owner's control. Which feature meets this requirement?

  1. Transparent Data Encryption (TDE)
  2. Dynamic Data Masking
  3. Always Encrypted
  4. Database auditing to a Log Analytics workspace
Show answer & explanation

Correct answer: C - Always Encrypted

The rest of the AZ-500 blueprint

The AZ-500 exam also covers these domains. Drill them in the full free practice test:

Ready for the real thing?

Practice hundreds more AZ-500 questions with instant scoring, weak-area drills, and full exam simulations.

Start the free practice test See pricing