Azure Security Technologies Free Sample Questions

20 free sample questions358 in the full practice test

Try simulator

AZ-500 Sample Questions

  1. Question 1

    Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.

    Your company’s Azure subscription is linked to their Azure Active Directory (Azure AD) tenant.

    After an internally developed application is registered in Azure AD, you are tasked with making sure that the application has the ability to access Azure Key Vault secrets on application the users’ behalf.

    Solution: You configure a delegated permission with admin consent.

    Does the solution meet the goal?

    Answer and explanation

    Correct answer: B

    The proposed solution does not meet the requirements. The scenario likely involves Azure AD application permissions or authentication configurations that the suggested approach cannot adequately address.

  2. Question 2

    Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.

    Your company has Azure subscription linked to their Azure Active Directory (Azure AD) tenant.

    As a Global administrator for the tenant, part of your responsibilities involves managing Azure Security Center settings.

    You are currently preparing to create a custom sensitivity label.

    Solution: You start by altering the pricing tier of the Security Center.

    Does the solution meet the goal?

    Answer and explanation

    Correct answer: B

    The proposed solution does not satisfy the requirements. Azure AD authentication and authorization configurations require specific approaches that the suggested solution cannot properly implement.

  3. Question 3

    Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.

    Your company’s Azure subscription is linked to their Azure Active Directory (Azure AD) tenant.

    After an internally developed application is registered in Azure AD, you are tasked with making sure that the application has the ability to access Azure Key Vault secrets on application the users’ behalf.

    Solution: You configure a delegated permission with no admin consent.

    Does the solution meet the goal?

    Answer and explanation

    Correct answer: A

    Explanation:
    Delegated permissions - Your client application needs to access the web API as the signed-in user, but with access limited by the selected permission. This type of permission can be granted by a user unless the permission requires administrator consent.
    Reference:
    https://docs.microsoft.com/en-us/azure/active-directory/develop/quickstart-configure-app-access-web-apis

  4. Question 4

    Your company has an Azure Container Registry.

    You have been tasked with assigning a user a role that allows for the downloading of images from the Azure Container Registry. The role assigned should not require more privileges than necessary.

    Which of the following is the role you should assign?

    Answer and explanation

    Correct answer: D

    AcrPull is the correct role for downloading container images from Azure Container Registry, following the principle of least privilege. The Reader role provides broader access than necessary, while Contributor allows modification operations, and AcrDelete specifically handles deletion operations.

  5. Question 5

    Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.
    Your company has an Azure subscription that includes an Azure key vault. You have previously created a secret in the key vault.

    After an application developer registers an application in Azure Active Directory (Azure AD), you are instructed to make sure that the application is able to use the secret you created.

    Solution: You should create a DLP policy.

    Does the solution meet the goal?

    Answer and explanation

    Correct answer: B

    The solution does not meet the requirements. The proposed configuration for Azure subscription and resource management likely has gaps that prevent it from achieving the desired security or compliance objectives.

  6. Question 6

    Your company recently created an Azure subscription.

    You have been tasked with making sure that a specified user is able to implement Azure AD Privileged Identity Management (PIM).

    Which of the following is the role you should assign to the user?

    Answer and explanation

    Correct answer: A

    Explanation:
    To start using PIM in your directory, you must first enable PIM. 1. Sign in to the Azure portal as a Global Administrator of your directory.
    You must be a Global Administrator with an organizational account (for example, ©yourdomain.com), not a Microsoft account (for example, ©outlook.com), to enable PIM for a directory.
    Scenario: Technical requirements include: Enable Azure AD Privileged Identity Management (PIM) for contoso.com Reference:
    https://docs.microsoft.com/bs-latn-ba/azure/active-directory/privileged-identity-management/pim-getting-started

  7. Question 7

    You need to consider the underlined segment to establish whether it is accurate.

    You have configured an Azure Kubernetes Service (AKS) cluster in your testing environment.

    You are currently preparing to deploy the cluster to the production environment.

    After disabling HTTP application routing, you want to replace it with an application routing solution that allows for reverse proxy and TLS termination for AKS services via a solitary IP address.

    You must create an AKS Ingress controller.

    Select “No adjustment required” if the underlined segment is accurate. If the underlined segment is inaccurate, select the accurate option.

    Answer and explanation

    Correct answer: A

    Explanation:
    An ingress controller is a piece of software that provides reverse proxy, configurable traffic routing, and TLS termination for Kubernetes services.
    Reference:
    https://docs.microsoft.com/en-us/azure/aks/ingress-tls

  8. Question 8

    Your company makes use of Azure Active Directory (Azure AD) in a hybrid configuration. All users are making use of hybrid Azure AD joined Windows 10 computers.

    You manage an Azure SQL database that allows for Azure AD authentication.

    You need to make sure that database developers are able to connect to the SQL database via Microsoft SQL Server Management Studio (SSMS). You also need to make sure the developers use their on-premises Active Directory account for authentication. Your strategy should allow for authentication prompts to be kept to a minimum.

    Which of the following is the authentication method the developers should use?

    Answer and explanation

    Correct answer: C

    Explanation:
    Azure AD can be the initial Azure AD managed domain. Azure AD can also be an on-premises Active Directory Domain Services that is federated with the Azure AD.
    Using an Azure AD identity to connect using SSMS or SSDT The following procedures show you how to connect to a SQL database with an Azure AD identity using SQL Server Management Studio or SQL Server Database Tools.
    Active Directory integrated authentication Use this method if you are logged in to Windows using your Azure Active Directory credentials from a federated domain.1. Start Management Studio or Data Tools and in the Connect to Server (or Connect to Database Engine) dialog box, in the Authentication box, select Active Directory - Integrated. No password is needed or can be entered because your existing credentials will be presented for the connection.

  9. Question 9

    You make use of Azure Resource Manager templates to deploy Azure virtual machines.

    You have been tasked with making sure that Windows features that are not in use, are automatically inactivated when instances of the virtual machines are provisioned.

    Which of the following actions should you take?

    Answer and explanation

    Correct answer: B

    Explanation:
    You can use Azure Automation State Configuration to manage Azure VMs (both Classic and Resource Manager), on-premises VMs, Linux machines, AWS VMs, and on-premises physical machines.
    Note: Azure Automation State Configuration provides a DSC pull server similar to the Windows Feature DSC-Service so that target nodes automatically receive configurations, conform to the desired state, and report back on their compliance. The built-in pull server in Azure Automation eliminates the need to set up and maintain your own pull server. Azure Automation can target virtual or physical Windows or Linux machines, in the cloud or on-premises.
    Reference:
    https://docs.microsoft.com/en-us/azure/automation/automation-dsc-getti n g-sta rted

  10. Question 10

    Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.

    Your Company’s Azure subscription includes a virtual network that has a single subnet configured.

    You have created a service endpoint for the subnet, which includes an Azure virtual machine that has Ubuntu Server 18.04 installed.

    You are preparing to deploy Docker containers to the virtual machine. You need to make sure that the containers can access Azure Storage resources and Azure SQL databases via the service endpoint.

    You need to perform a task on the virtual machine prior to deploying containers.

    Solution: You create an AKS Ingress controller.

    Does the solution meet the goal?

    Answer and explanation

    Correct answer: B

    The solution does not meet the requirements. Virtual network configuration and security implementation require specific approaches that the proposed solution cannot adequately provide for the intended use case.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 358 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon