Practice Free AZ-500 Exam Online Questions
HOTSPOT
You need to create an Azure key vault. The solution must ensure that any object deleted from the key vault be retained for 90 days.
How should you complete the command? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You have an Azure Active Directory (Azure AD) tenant that contains a user named Admin1. Admin1 is assigned the Application developer role.
You purchase a cloud app named App1 and register App1 in Azure AD.
Admin1 reports that the option to enable token encryption for App1 is unavailable.
You need to ensure that Admin1 can enable token encryption for App1 in the Azure portal.
What should you do?
- A . Upload a certificate for App1.
- B . Modify the API permissions of App1.
- C . Add App1 as an enterprise application.
- D . Assign Admin1 the Cloud application administrator role.
You are configuring an Azure Kubernetes Service (AKS) cluster that will connect to an Azure Container Registry.
You need to use the auto-generated service principal to authenticate to the Azure Container Registry.
What should you create?
- A . an Azure Active Directory (Azure AD) group
- B . an Azure Active Directory (Azure AD) role assignment
- C . an Azure Active Directory (Azure AD) user
- D . a secret in Azure Key Vault
You need to implement the planned change for SQLdb1.
Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
- A . Create a compliance policy.
- B . Configure Microsoft Entra authentication for SQLServer1.
- C . Create a Conditional Access policy.
- D . Configure a user-assigned managed identity for SQLdb1.
- E . Configure Federated client identity for SQLdb1.
You need to implement the planned change for SQLdb1.
Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
- A . Create a compliance policy.
- B . Configure Microsoft Entra authentication for SQLServer1.
- C . Create a Conditional Access policy.
- D . Configure a user-assigned managed identity for SQLdb1.
- E . Configure Federated client identity for SQLdb1.
SIMULATION
Lab Task
Task 2
You need to ensure that the events in the NetworkSecurityGroupRuleCounter log of the VNETOI-Subnet0-NSG network security group (NSG) are stored in the Iogs31330471 Azure Storage account for 30 days.
You have an Azure subscription that contains an Azure web app named 1 and a virtual machine named VM1. VM1 runs Microsoft SQL Server and is connected to a virtual network named VNet1. App1, VM1, and Vent are in the US Central Azure region.
You need to ensure that App1 can connect to VM1. The solution must minimize costs.
- A . NAT gateway integration
- B . Azure Front Door
- C . regional virtual network integration
- D . gateway-required virtual network integration
- E . Azure Application Gateway integration
Your network contains an on-premises Active Directory domain named adatum.com that syncs to Azure Active Directory (Azure AD). Azure AD Connect is installed on a domain member server named Server1.
You need to ensure that a domain administrator for the adatum.com domain can modify the synchronization options. The solution must use the principle of least privilege.
Which Azure AD role should you assign to the domain administrator?
- A . Security administrator
- B . Global administrator
- C . User administrator
You have an Azure subscription that uses Microsoft Defender for Cloud.
You have accounts for the following cloud services:
• Alibaba Cloud
• Amazon Web Services (AWS)
• Google Cloud Platform (GCP)
What can you add to Defender for Cloud?
- A . AWS only
- B . Alibaba Cloud and AWS only
- C . Alibaba Good and GCP only
- D . AWS and GCP only
- E . Alibaba Cloud, AWS. and GCP
HOTSPOT
On Monday, you configure an email notification in Microsoft Defender for Cloud to notify user1 @contoso.com about alerts that have a severity level of Low, Medium, or High.
On Tuesday, Microsoft Defender for Cloud generates the security alerts shown in the following table.

How many email notifications will user1 @contoso.com receive on Tuesday? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.


