Free Practice Questions for Microsoft Azure Security Engineer Associate (AZ-500) Certification

    🔄 Last checked for updates February 17th, 2026

    Study with 359 exam-style practice questions designed to help you prepare for the Microsoft Azure Security Engineer Associate (AZ-500). All questions are aligned with the latest exam guide and include detailed explanations to help you master the material.

    Start Practicing

    Random Questions

    Practice with randomly mixed questions from all topics

    Question MixAll Topics
    FormatRandom Order

    Domain Mode

    Practice questions from a specific topic area

    Exam Information

    Exam Details

    Key information about Microsoft Azure Security Engineer Associate (AZ-500)

    Official study guide:

    View

    level:

    associate (intermediate)

    prerequisites:

    Practical experience in administration of Microsoft Azure and hybrid environments; strong familiarity with Microsoft Entra ID, compute, network, and storage in Azure.

    target audience:

    Azure security engineer

    Exam Topics & Skills Assessed

    Skills measured (from the official study guide)

    Domain 1: Secure identity and access

    Subdomain 1.1: Manage security controls for identity and access

    - Manage Azure built-in role assignments - Manage custom roles, including Azure roles and Microsoft Entra roles - Plan and manage Azure resources in Microsoft Entra Privileged Identity Management, including settings and assignments - Implement multi-factor authentication (MFA) for access to Azure resources - Implement Conditional Access policies for cloud resources in Azure

    Subdomain 1.2: Manage Microsoft Entra application access and managed identities

    - Manage access to enterprise applications in Microsoft Entra ID, including OAuth permission grants - Manage Microsoft Entra app registrations - Configure app registration permission scopes - Manage app registration permission consent - Manage and use service principals - Manage managed identities

    Domain 2: Secure networking

    Subdomain 2.1: Plan and implement security for virtual networks

    - Plan and implement Network Security Groups (NSGs) and Application Security Groups (ASGs) - Manage virtual networks by using Azure Virtual Network Manager - Plan and implement user-defined routes (UDRs) - Plan and implement Virtual Network peering or VPN gateway - Plan and implement Virtual WAN, including secured virtual hub - Secure VPN connectivity, including point-to-site and site-to-site - Implement encryption over ExpressRoute - Configure firewall settings on Azure resources - Monitor network security by using Network Watcher

    Subdomain 2.2: Plan and implement security for private access to Azure resources

    - Plan and implement virtual network Service Endpoints - Plan and implement Private Endpoints - Plan and implement Private Link services - Plan and implement network integration for Azure App Service and Azure Functions - Plan and implement network security configurations for an App Service Environment (ASE) - Plan and implement network security configurations for an Azure SQL Managed Instance

    Subdomain 2.3: Plan and implement security for public access to Azure resources

    - Plan and implement Transport Layer Security (TLS) to applications, including Azure App Service and API Management - Plan, implement, and manage an Azure Firewall, including Azure Firewall Manager and firewall policies - Plan and implement an Azure Application Gateway - Plan and implement an Azure Front Door, including Content Delivery Network (CDN) - Plan and implement a Web Application Firewall (WAF) - Recommend when to use Azure DDoS Protection Standard

    Domain 3: Secure compute, storage, and databases

    Subdomain 3.1: Plan and implement advanced security for compute

    - Plan and implement remote access to virtual machines, including Azure Bastion and just-in-time (JIT) VM access - Configure network isolation for Azure Kubernetes Service (AKS) - Secure and monitor AKS - Configure authentication for AKS - Configure security monitoring for Azure Container Instances (ACIs) - Configure security monitoring for Azure Container Apps (ACAs) - Manage access to Azure Container Registry (ACR) - Configure disk encryption, including Azure Disk Encryption (ADE), encryption at host, and confidential disk encryption - Recommend security configurations for Azure API Management

    Subdomain 3.2: Plan and implement security for storage

    - Configure access control for storage accounts - Manage storage account access keys - Select and configure an appropriate method for access to Azure Files - Select and configure an appropriate method for access to Azure Blob Storage - Select and configure appropriate methods for protecting against data security threats, including soft delete, backups, versioning, and immutable storage - Configure Bring your own key (BYOK) - Enable double encryption at the Azure Storage infrastructure level

    Subdomain 3.3: Plan and implement security for Azure SQL Database and Azure SQL Managed Instance

    - Enable Microsoft Entra database authentication - Enable database auditing - Plan and implement dynamic masking - Implement Transparent Data Encryption (TDE) - Recommend when to use Azure SQL Database Always Encrypted

    Domain 4: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

    Subdomain 4.1: Implement and manage enforcement of cloud governance policies

    - Create, assign, and interpret policies and initiatives in Azure Policy - Configure Azure Key Vault network settings - Configure access to Key Vault, including vault access policies and Azure Role Based Access Control - Manage certificates, secrets, and keys - Configure key rotation - Perform backup and recovery of certificates, secrets, and keys - Implement security controls to protect backups - Implement security controls for asset management

    Subdomain 4.2: Manage security posture by using Microsoft Defender for Cloud

    - Identify and remediate security risks by using the Microsoft Defender for Cloud Secure Score and Inventory - Assess compliance against security frameworks by using Microsoft Defender for Cloud - Manage compliance standards in Microsoft Defender for Cloud - Add custom standards to Microsoft Defender for Cloud - Connect hybrid cloud and multi-cloud environments to Microsoft Defender for Cloud, including Amazon Web Services (AWS) and Google Cloud Platform (GCP) - Implement and use Microsoft Defender External Attack Surface Management (EASM)

    Subdomain 4.3: Configure and manage threat protection by using Microsoft Defender for Cloud

    - Enable cloud workload protection plans in Microsoft Defender for Cloud - Configure Microsoft Defender for Servers, Microsoft Defender for Databases, and Microsoft Defender for Storage - Implement and manage agentless scanning for virtual machines in Microsoft Defender for Servers - Implement and manage Microsoft Defender Vulnerability Management for Azure virtual machines - Connect to and configure settings in Microsoft Defender for Cloud Devops Security, including GitHub, Azure DevOps, and GitLab

    Subdomain 4.4: Configure and manage security monitoring and automation solutions

    - Manage and respond to security alerts in Microsoft Defender for Cloud - Configure workflow automation by using Microsoft Defender for Cloud - Monitor network security events and performance data by configuring data collection rules (DCRs) in Azure Monitor - Configure data connectors in Microsoft Sentinel - Enable analytics rules in Microsoft Sentinel - Configure automation in Microsoft Sentinel

    Techniques & products

    Azure built-in role assignments
    Custom roles
    Microsoft Entra roles
    Microsoft Entra Privileged Identity Management (PIM)
    Multi-factor authentication (MFA)
    Conditional Access policies
    Enterprise applications
    OAuth permission grants
    Microsoft Entra app registrations
    Permission scopes
    Service principals
    Managed identities
    Network Security Groups (NSGs)
    Application Security Groups (ASGs)
    Azure Virtual Network Manager
    User-defined routes (UDRs)
    Virtual Network peering
    VPN gateway
    Virtual WAN
    Secured virtual hub
    VPN connectivity (point-to-site, site-to-site)
    ExpressRoute encryption
    Azure Firewall
    Network Watcher
    Virtual network Service Endpoints
    Private Endpoints
    Private Link services
    Azure App Service
    Azure Functions
    App Service Environment (ASE)
    Azure SQL Managed Instance
    Transport Layer Security (TLS)
    API Management
    Azure Firewall Manager
    Firewall policies
    Azure Application Gateway
    Azure Front Door
    Content Delivery Network (CDN)
    Web Application Firewall (WAF)
    Azure DDoS Protection Standard
    Azure Bastion
    Just-in-time (JIT) VM access
    Azure Kubernetes Service (AKS)
    Azure Container Instances (ACIs)
    Azure Container Apps (ACAs)
    Azure Container Registry (ACR)
    Azure Disk Encryption (ADE)
    Encryption at host
    Confidential disk encryption
    Storage accounts access control
    Storage account access keys
    Azure Files
    Azure Blob Storage
    Soft delete
    Backups
    Versioning
    Immutable storage
    Bring your own key (BYOK)
    Double encryption
    Azure SQL Database
    Microsoft Entra database authentication
    Database auditing
    Dynamic masking
    Transparent Data Encryption (TDE)
    Azure SQL Database Always Encrypted
    Azure Policy
    Azure Key Vault
    Vault access policies
    Azure Role Based Access Control
    Certificates
    Secrets
    Keys
    Key rotation
    Microsoft Defender for Cloud
    Secure Score
    Inventory
    Compliance standards
    Amazon Web Services (AWS)
    Google Cloud Platform (GCP)
    Microsoft Defender External Attack Surface Management (EASM)
    Cloud workload protection plans
    Microsoft Defender for Servers
    Microsoft Defender for Databases
    Microsoft Defender for Storage
    Agentless scanning
    Microsoft Defender Vulnerability Management
    Microsoft Defender for Cloud Devops Security
    GitHub
    Azure DevOps
    GitLab
    Security alerts
    Workflow automation
    Azure Monitor
    Data collection rules (DCRs)
    Microsoft Sentinel
    Data connectors
    Analytics rules
    Microsoft Cloud Security Benchmark (MCSB)

    CertSafari is not affiliated with, endorsed by, or officially connected to Microsoft Corporation. Full disclaimer