Practice 60 original Azure Security Engineer AZ-500 questions covering identity, platform protection, data protection, network security, security operations and governance, with detailed explanations.
Level: Azure Security Engineer AssociateDifficulty: advanced60 questions60 min
Choose a practice mode, answer each Azure Security Engineer AZ-500 question, then review the explanation. Wrong answers are saved locally for review.
Day streak: 0 daysSaved only on this device
Progress0 / 60
Time left: 00:00
No wrong answers saved yet.
No questions match your filters.
Question 1
What is Microsoft Entra ID?
Microsoft Entra ID provides identity and access management. Firewalls, storage, and DNS are different services.
Question 2
What is multi-factor authentication?
MFA requires multiple verification factors such as password and phone. One password, disabled logins, and storage are different.
Question 3
What is Conditional Access?
Conditional Access evaluates user, device, location, and risk signals. Firewall rules, storage policies, and DNS are different.
Question 4
What is Azure RBAC?
RBAC grants permissions through roles. Networks, databases, and CDNs are different.
Question 5
What is a managed identity?
Managed identities give Azure resources an identity without managing credentials. User accounts, DNS, and firewalls are different.
Question 6
What is a service principal?
Service principals represent applications. VMs, storage accounts, and NSGs are resources.
Question 7
What is a custom role?
Custom roles define specific permissions. Built-in roles, DNS records, and firewall rules are different.
Question 8
What is Privileged Identity Management?
PIM provides just-in-time privileged access. Firewalls, storage, and load balancers are different.
Question 9
What is a guest user?
Guest users are external collaborators. Administrators, VMs, and service principals are different.
Question 10
Match each identity concept to its purpose.
Entra ID is the identity service, MFA adds factors, Conditional Access evaluates policies, and RBAC grants role permissions.
Question 11
What is Microsoft Defender for Cloud?
Defender for Cloud improves posture and protects workloads. DNS, storage, and CDN are different.
Question 12
What is Azure Firewall?
Azure Firewall filters network traffic. Databases, DNS zones, and load balancers are different.
Question 13
What is Azure DDoS Protection?
DDoS Protection mitigates volumetric attacks. Backups, DNS, and alarms are different.
Question 14
What is Azure WAF?
WAF protects web applications from common attacks. VMs, storage, and databases are resources.
Question 15
What is a security baseline?
Security baselines define recommended settings. Firewall rules, DNS records, and containers are different.
Question 16
What is secure score?
Secure score measures how well an environment follows security recommendations. Routes, databases, and backups are different.
Question 17
What is just-in-time VM access?
JIT access opens ports only when needed. Always-open ports, disabled VMs, and DNS are different.
Question 18
What is adaptive application control?
Adaptive application control builds application allowlists. Firewalls, DNS, and load balancers are different.
Question 19
What is a vulnerability assessment?
Vulnerability assessments find weaknesses. Storage, DNS, and load balancing are different.
Question 20
Match each platform protection concept to its purpose.
Defender manages posture, Firewall filters traffic, DDoS Protection defends against attacks, and WAF protects web apps.
Question 21
What is Azure Key Vault?
Key Vault stores secrets, keys, and certificates. Databases, DNS, and CDNs are different.
Question 22
What is a secret in Key Vault?
Secrets are sensitive strings like passwords. Models, firewall rules, and routes are different.
Question 23
What is transparent data encryption?
TDE encrypts database files at rest. Network encryption, backups, and filtering are different.
Question 24
What is encryption at rest?
Encryption at rest protects stored data. Transit encryption, DNS, and firewalls are different.
Question 25
What is encryption in transit?
Transit encryption protects moving data, usually with TLS. At-rest encryption, backups, and filters are different.
Question 26
What is a certificate used for?
Certificates support TLS and authentication. Files, traffic filters, and reports are different.
Question 27
What is a customer-managed key?
Customer-managed keys are controlled by the customer. Microsoft-managed keys, DNS, and firewall rules are different.
Question 28
What is data masking?
Data masking hides sensitive values in results. Encryption, deletion, and backups are different.
Question 29
What is Defender for Storage?
Defender for Storage detects threats in storage accounts. DNS, load balancers, and backups are different.
Question 30
Match each data protection concept to its purpose.
Key Vault stores secrets, secrets are sensitive values, TDE encrypts databases, and customer-managed keys are owned by you.
Question 31
What is a network security group?
NSGs filter traffic with allow and deny rules. Databases, DNS zones, and load balancers are different.
Question 32
What is a private endpoint?
Private endpoints give services private IP addresses in a VNet. Public sites, DNS, and firewalls are different.
Question 33
What is Azure VPN Gateway?
VPN Gateway sends encrypted traffic over the internet. Databases, storage, and CDNs are different.
Question 34
What is ExpressRoute?
ExpressRoute provides private connectivity to Azure. Public internet, DNS records, and load balancers are different.
Question 35
What is network segmentation?
Segmentation isolates workloads to limit blast radius. Merging, deleting firewalls, and DNS are different.
Question 36
What is a service tag?
Service tags represent Azure service IP ranges. VM names, databases, and storage accounts are different.
Question 37
What is an application security group?
ASGs group VMs by application. DNS records, firewalls, and load balancers are different.
Question 38
What is Azure Bastion?
Bastion provides secure remote access without exposing public IPs. Websites, databases, and storage are different.
Question 39
What is a private DNS zone?
Private DNS zones resolve names inside a VNet. Public records, firewalls, and load balancers are different.
Question 40
Match each network security concept to its purpose.
NSGs filter traffic, private endpoints provide private access, VPN Gateway tunnels traffic, and Bastion enables secure remote access.
Question 41
What is Microsoft Sentinel?
Sentinel provides security information and event management plus orchestration. DNS, storage, and CDN are different.
Question 42
What is a detection rule in Sentinel?
Detection rules generate alerts from analytics. Firewall rules, DNS records, and load balancers are different.
Question 43
What is an incident in Sentinel?
Incidents group related alerts for investigation. Logs, VMs, and storage accounts are different.
Question 44
What is an automation rule?
Automation rules run response actions on incidents. Firewalls, DNS, and load balancers are different.
Question 45
What is a workbook in Sentinel?
Workbooks display interactive charts and dashboards. Databases, firewalls, and DNS zones are different.
Question 46
What is a data connector?
Data connectors bring logs into Sentinel. Cables, storage accounts, and DNS records are different.
Question 47
What is a playbook?
Playbooks automate responses with Logic Apps. Reports, dashboards, and firewalls are different.
Question 48
What is Azure Monitor?
Azure Monitor collects monitoring data. DNS, CDN, and storage are different.
Question 49
What is KQL?
KQL queries log data in Azure Monitor and Sentinel. Frameworks, firewalls, and DNS protocols are different.
Question 50
Match each security operations concept to its purpose.
Sentinel is SIEM/SOAR, detection rules trigger alerts, playbooks automate responses, and workbooks visualize data.
Question 51
What is Azure Policy?
Azure Policy enforces organizational rules. Databases, DNS, and load balancers are different.
Question 52
What is an initiative?
Initiatives group policies for a common goal. Single policies, storage accounts, and DNS zones are different.
Question 53
What is Azure Blueprints?
Blueprints package policies, roles, and resources. Firewalls, databases, and CDNs are different.
Question 54
What is a compliance standard?
Compliance standards are frameworks like ISO or NIST. Firewall rules, DNS records, and containers are different.
Question 55
What is Microsoft Purview?
Purview provides data governance and compliance. DNS, load balancers, and CDNs are different.
Question 56
What is a resource tag?
Tags organize resources and support cost tracking. Firewall rules, DNS records, and databases are different.
Question 57
What is a management group?
Management groups create a hierarchy for policy and governance. VMs, storage, and DNS zones are resources.
Question 58
What is an audit policy?
Audit policies monitor and log noncompliance. Deny policies block resources, and firewalls or load balancers are different.
Question 59
What is a deny policy?
Deny policies prevent noncompliant resources. Logging-only policies, DNS records, and containers are different.
Question 60
Match each governance concept to its purpose.
Azure Policy enforces rules, initiatives group policies, Blueprints package governance, and Purview governs data.