Microsoft AZ-500 Answers

Page:    1 / 99   
Total 495 questions | Updated On: Apr 02, 2026
Question 1

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a hybrid configuration of Azure Active Directory (Azure AD). You have an Azure HDInsight cluster on a virtual network. You plan to allow users to authenticate to the cluster by using their on-premises Active Directory credentials. You need to configure the environment to support the planned authentication. Solution: You deploy Azure Active Directory Domain Services (Azure AD DS) to the Azure subscription. Does this meet the goal?


Answer: A
Question 2

You have an Azure subscription that contains a route table named RT1. RT1 includes a route that has the

following configurations:

• Name: RouteA

• IP address prefix: 192.168.0.0/24

• Next hop IP address: 172.16.10.10

You are evaluating whether to add the routes shown in the following table.

Which routes can you add to RT1? 


Answer: E
Question 3

You have an Azure subscription named Sub1 that has Security defaults disabled. The subscription contains

the following users:

• Five users that have owner permissions for Sub1.

• Ten users that have owner permissions for Azure resources.

None of the users have multi-factor authentication (MFA) enabled.

Sub1 has the secure score as shown in the Secure Score exhibit. (Click the Secure Score tab.)

You plan to enable MFA for the following users:

• Five users that have owner permissions for Sub1.

• Five users that have owner permissions for Azure resources.

By how many points will the secure score increase after you perform the planned changes?


Answer: C
Question 4

You have a Azure subscription.

You enable Azure Active Directory (Azure AD) Privileged identify (PIM).

Your company’s security policy for administrator accounts has the following conditions:

* The accounts must use multi-factor authentication (MFA).

* The account must use 20-character complex passwords.

* The passwords must be changed every 180 days.

* The account must be managed by using PIM.

You receive alerts about administrator who have not changed their password during the last 90 days.

You need to minimize the number of generated alerts.

Which PIM alert should you modify?


Answer: D
Question 5

You have an Azure subscription that contains a user named User1 and an Azure Container Registry named ConReg1. You enable content trust for ContReg1. You need to ensure that User1 can create trusted images in ContReg1. The solution must use the principle of least privilege. Which two roles should you assign to User1? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.


Answer: C,D
Page:    1 / 99   
Total 495 questions | Updated On: Apr 02, 2026

Quickly grab our AZ-500 product now and kickstart your exam preparation today!

Name: Microsoft Azure Security Technologies
Exam Code: AZ-500
Certification: Microsoft Azure
Vendor: Microsoft
Total Questions: 495
Last Updated: Apr 02, 2026