Microsoft · Practice Exam · Associate · Updated for 2026

AZ-500: Azure Security Engineer Associate Practice Exam

Cover every domain on Microsoft’s current AZ-500 outline — identity and access, networking, compute/storage/databases, and the now-heaviest Defender for Cloud and Sentinel domain — with scenario-based questions, source-linked explanations to Microsoft Learn, and full timed simulation in Exam mode.

Start 24-hour free trial →

⚠ AZ-500 retires August 31, 2026 — successor is SC-500

Microsoft has announced that AZ-500 will retire on August 31, 2026 (11:59 PM CST). Its successor is SC-500: Cloud and AI Security Engineer, in beta since May 2026, which carries most of the AZ-500 content forward and adds AI-workload security. Most of what you study for AZ-500 transfers directly to SC-500.

If you can pass AZ-500 before the retirement date, the credential stays valid for a year and renews through the usual free online assessment. If your realistic test date is after August 31, plan around SC-500 instead. Always confirm the latest status on Microsoft’s certification page.

780+
Practice questions
4
Objective domains
2
Study modes
24h
Free trial

AZ-500 exam at a glance

Vendor
Microsoft
Exam code
AZ-500
Certification
Microsoft Certified: Azure Security Engineer Associate
Level
Associate (role-based)
Status
Retires August 31, 2026 — successor is SC-500 (Cloud and AI Security Engineer)
Blueprint
Skills Measured outline as of January 22, 2026 (four domains); verify current edition before publish
Format
40–60 questions; multiple choice, multiple response, drag-and-drop, hot area, case studies, occasional labs
Duration
Approximately 100 minutes seat time
Passing score
700 of 1000 (scaled)
Delivery
Pearson VUE test center or online proctored (OnVUE)
Prerequisites
None enforced. Microsoft recommends Azure administration experience (AZ-104 level) and strong familiarity with Microsoft Entra ID, compute, networking, and storage.
Cost (USD)
$165 USD (regional pricing varies)
Validity
1 year; renew free via an online assessment on Microsoft Learn

Sources: Microsoft — Azure Security Engineer Associate certification · AZ-500 Study Guide (Skills measured as of January 22, 2026; retirement notice). Verify current details with Microsoft before scheduling.

About the AZ-500 Azure Security Engineer Associate certification

AZ-500 earns the Microsoft Certified: Azure Security Engineer Associate badge — the role-based credential for engineers who implement, manage, and monitor security across Azure, hybrid, and multi-cloud environments. It is written from the operator’s seat: you secure identity with Microsoft Entra ID, lock down networking, harden compute and data, and run security operations with Microsoft Defender for Cloud and Microsoft Sentinel. Questions are scenario-driven, and the wrong answer is usually a service that almost works.

Two things to plan around. First, AZ-500 retires on August 31, 2026 and is replaced by SC-500 (Cloud and AI Security Engineer) — if your test date is past that, study for SC-500 instead, though most content carries over. Second, the current outline is weighted very differently from older study material: the Defender for Cloud and Sentinel domain is now the single heaviest at 30–35%, while identity and access dropped to 15–20% (the lightest domain, though still foundational because everything else depends on it). If your prep treats identity as the biggest area, it is out of date.

Every PowerKram practice question maps to one of the four current domains and links to the specific Microsoft Learn page it was derived from, so your weak spots become a reading list rather than a guess. For broader context on the security concepts AZ-500 tests, see our enterprise security practices guide in the Learning Hub.

AZ-500 exam domains and weights (January 2026 outline)

Four domains, with Defender for Cloud and Sentinel now the single heaviest area. The ranges are Microsoft’s; actual exam composition varies within the bands. Plan your study time roughly in proportion to these weights — and note that identity, though lightest, underpins the other three.

Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Cloud governance and Key Vault (Azure Policy, certificates/secrets/keys, key rotation, asset management); security posture with Defender for Cloud (Secure Score, compliance standards, multi-cloud connectors for AWS/GCP, EASM); threat protection (Defender for Servers/Databases/Storage, agentless scanning, DevOps Security); and monitoring/automation with Azure Monitor and Microsoft Sentinel (data connectors, analytics rules, playbooks).

30–35%Heaviest domain
Secure compute, storage, and databases

Advanced compute security (Azure Bastion, JIT VM access, AKS isolation and monitoring, container security, disk encryption); storage security (access control, keys, soft delete, versioning, immutable storage, BYOK); and database security for Azure SQL (Entra authentication, auditing, dynamic masking, TDE, Always Encrypted).

20–25%
Secure networking

Virtual-network security (NSGs/ASGs, Virtual Network Manager, UDRs, peering/VPN, secured virtual hub, ExpressRoute encryption); private access (Service Endpoints, Private Endpoints, Private Link); and public access (TLS, Azure Firewall and Firewall Manager, Application Gateway, Front Door/CDN, WAF, DDoS Protection).

20–25%
Secure identity and access

Identity and access controls (Azure built-in and custom roles, Entra Privileged Identity Management, MFA, Conditional Access); and Microsoft Entra application access and managed identities (enterprise app access and OAuth grants, app registrations and permission scopes, service principals, managed identities).

15–20%Lightest — but foundational

Source: Microsoft AZ-500 Study Guide — skills measured as of January 22, 2026. Relative to older outlines, the Defender for Cloud and Sentinel domain is now the single heaviest (30–35%) and absorbed Key Vault and Azure Policy governance, while identity and access eased to 15–20%.

Who AZ-500 is for

AZ-500 is aimed at security engineers who already know how Azure works — Microsoft expects Azure administration experience and strong Microsoft Entra ID familiarity going in:

  • Azure security engineers implementing and monitoring security controls across Azure, hybrid, and multi-cloud.
  • Cloud security analysts and SOC engineers running Defender for Cloud and Microsoft Sentinel for detection and response.
  • Azure administrators specializing into security who already hold or are ready for AZ-104-level skills.
  • DevSecOps engineers integrating security scanning and policy into pipelines and cloud posture management.

Because the exam assumes you already speak Azure, most candidates hold AZ-104 Azure Administrator first, and often pair AZ-500 with AZ-700 for networking depth. For the roles AZ-500 (and its successor SC-500) carries genuine resume value in — including salary ranges and progression paths — see our cybersecurity specialist career paths in the Career Hub.

What this AZ-500 practice exam delivers

Learn mode

Get the correct answer, the reasoning, and a direct link to the exact Microsoft Learn page each question was derived from — immediately after each question. Weighted toward the Defender for Cloud and Sentinel domain, where scenario nuance (and implicit KQL) drives the correct answer.

Exam mode

Scenario-based questions on a timer that mirrors the real 100-minute AZ-500 format. Build the pacing for multi-constraint security scenarios where two answers look plausible and one meaningful detail decides it.

Source-linked explanations

Every answer cites the exact Microsoft Learn page (learn.microsoft.com/entra, /azure/sentinel, /azure/defender-for-cloud…) it was built from — so you can verify and dig deeper, not just memorize.

Score by AZ-500 domain

Results break down by the four current domains — Defender/Sentinel, Compute/Storage/DB, Networking, and Identity — so practice tells you exactly which area to revisit.

Sample AZ-500 practice questions

Ten free questions across the four current AZ-500 domains, with full explanations and source links to the Microsoft Learn pages each is derived from. The complete bank is available with the 24-hour trial.

Question 1 · Secure identity and access (15–20%)

A company needs to require MFA for all administrator access to the Azure portal while allowing standard users passwordless access from compliant devices. Which identity feature should be configured?

  1. Conditional Access policies with separate rules for admin and standard user groups
  2. Azure AD Password Protection only
  3. Disable MFA and use IP restrictions only
  4. A single blanket MFA policy for all users
Show answer & explanation

Correct: A — Conditional Access with differentiated policies. Conditional Access can require MFA for admins while granting compliant standard-user devices passwordless access, because policies target by group, role, and device state.

Why not the others: a blanket MFA policy (D) cannot differentiate admin from standard requirements; IP restrictions alone (C) don’t enforce authentication strength; Password Protection (B) prevents weak passwords but does not enforce MFA.

Source: Microsoft Learn — Conditional Access overview → Further reading: PowerKram — identity & access control →
Question 2 · Secure identity and access (15–20%)

An Azure-hosted web app needs to read secrets from Key Vault and blobs from a storage account. Security requires that no credential or connection string be stored in the app’s code or configuration. Which approach should be used?

  1. Store a service principal client secret in the app’s configuration and rotate it quarterly
  2. Assign a managed identity to the app and grant it RBAC access to Key Vault and Storage
  3. Embed a shared access signature (SAS) token in the application settings
  4. Use the storage account access key retrieved from an environment variable at startup
Show answer & explanation

Correct: B — a managed identity with RBAC. A managed identity lets the app authenticate to Key Vault and Storage with no stored credential; Azure handles the token lifecycle, and access is granted by role assignment.

Why not the others: a stored client secret (A), an embedded SAS token (C), or a retrieved access key (D) are all long-lived secrets that live in config and can leak or expire — exactly what the requirement forbids.

Source: Microsoft Learn — managed identities & access →
Question 3 · Secure identity and access (15–20%)

A company discovers former employees still have Azure access two weeks after leaving. They need automatic deprovisioning triggered by HR events. Which solution automates access removal upon employee departure?

  1. Forced password expiration every 30 days requiring all users to create new credentials
  2. Quarterly access certification campaigns sending email reminders to resource owners
  3. Entra ID lifecycle workflows triggered by HR system termination events for automated offboarding
  4. Monthly manual access reviews conducted by each department manager in a spreadsheet
Show answer & explanation

Correct: C — Entra ID lifecycle workflows. Lifecycle workflows integrated with HR data automatically disable accounts, revoke sessions, and remove group memberships on termination events.

Why not the others: monthly manual reviews (D) leave up to 30-day gaps; quarterly campaigns (B) are far too infrequent; password expiry (A) forces credential changes but doesn’t disable accounts or revoke resource access.

Source: Microsoft Learn — lifecycle workflows →
Question 4 · Secure identity and access (15–20%)

An organization needs to grant a third-party auditor read-only access to specific resources for 30 days with no standing access. Which access approach should be used?

  1. Create a permanent Guest account with the Reader role and no expiration date
  2. Configure PIM with a time-bound eligible assignment that automatically expires after 30 days
  3. Establish a VPN tunnel granting the auditor full network-level connectivity to Azure resources
  4. Share an existing administrator account with the auditor for the duration of the engagement
Show answer & explanation

Correct: B — PIM with a time-bound eligible assignment. Privileged Identity Management grants just-in-time, time-bound access that auto-expires with no manual cleanup, satisfying least privilege and no-standing-access.

Why not the others: a permanent guest with Reader (A) risks lingering access; sharing an admin account (D) breaks individual accountability; a VPN (C) grants network connectivity but not resource-level authorization.

Source: Microsoft Learn — Privileged Identity Management →
Question 5 · Defender for Cloud & Sentinel (30–35%)

A SOC team needs to detect and investigate multi-stage attacks across endpoints, email, identity, and cloud workloads from a single dashboard. Which Microsoft security solution provides this unified detection?

  1. Microsoft Purview compliance portal managing data classification and retention policies
  2. Microsoft Defender XDR correlating alerts across endpoints, email, identity, and cloud apps
  3. Azure Firewall diagnostic logs providing network-level traffic inspection and analysis
  4. Azure Network Watcher providing connectivity diagnostics and packet capture capabilities
Show answer & explanation

Correct: B — Microsoft Defender XDR. Defender XDR correlates signals across endpoints, email, identity, and cloud apps to detect multi-stage attacks with automated incident grouping in one investigation experience.

Why not the others: Firewall logs (C) show network events only; Network Watcher (D) diagnoses connectivity; Purview (A) handles data governance and compliance, not threat detection.

Source: Microsoft Learn — Microsoft Defender XDR → Further reading: PowerKram — security operations roles →
Question 6 · Defender for Cloud & Sentinel (30–35%)

A security analyst needs custom detection rules that query log data from multiple sources to find suspicious sign-in patterns. Which tool and language should the analyst use?

  1. Azure Advisor security recommendations providing periodic best-practice compliance checks
  2. Azure Policy audit-effect definitions evaluating resource configuration against standards
  3. Azure Monitor metric alert rules configured with numeric threshold conditions on counters
  4. Microsoft Sentinel scheduled analytics rules built with Kusto Query Language log queries
Show answer & explanation

Correct: D — Sentinel analytics rules with KQL. Sentinel scheduled analytics rules use Kusto Query Language to query connected log sources, enabling complex pattern detection across time windows and data types.

Why not the others: metric alerts (C) evaluate numeric thresholds, not log patterns; Advisor (A) gives periodic recommendations, not detections; Policy (B) evaluates resource-configuration compliance, not security event patterns.

Source: Microsoft Learn — Sentinel analytics rules → Further reading: PowerKram — threat detection with KQL →
Question 7 · Defender for Cloud & Sentinel (30–35%)

A company wants to automatically isolate compromised VMs and notify the security team when high-severity incidents are detected. Which Sentinel feature enables this automated response?

  1. Sentinel workbooks providing interactive data visualization dashboards for analysts
  2. Entity behavior analytics detecting anomalous patterns in user and device activity
  3. Playbooks built on Logic Apps and triggered automatically by analytics rule incidents
  4. Hunting notebooks providing interactive Jupyter-based threat investigation environments
Show answer & explanation

Correct: C — playbooks on Logic Apps. Playbooks automate response actions such as VM network isolation and team notification, triggered automatically by analytics rule incidents.

Why not the others: workbooks (A) visualize data but don’t act; notebooks (D) support manual investigation; entity behavior analytics (B) detects anomalies but doesn’t execute containment.

Source: Microsoft Learn — Sentinel playbooks →
Question 8 · Secure networking (20–25%)

A company needs to inspect and filter outbound internet traffic from Azure VMs, blocking access to known malicious domains. Which service should be deployed?

  1. Network Security Groups with outbound IP address and port-based filtering rules
  2. Azure DDoS Protection Standard providing volumetric attack mitigation at the network edge
  3. Azure Private Link establishing private connectivity between VNets and Azure PaaS services
  4. Azure Firewall with FQDN application rules and integrated threat intelligence feeds
Show answer & explanation

Correct: D — Azure Firewall with FQDN application rules. Azure Firewall filters outbound traffic by fully qualified domain name and uses threat intelligence to block known malicious destinations.

Why not the others: NSGs (A) filter by IP and port, not domain name; DDoS Protection (B) handles inbound volumetric attacks; Private Link (C) provides private PaaS connectivity but doesn’t inspect internet-bound traffic.

Source: Microsoft Learn — Azure Firewall features → Further reading: PowerKram — network security controls →
Question 9 · Secure networking (20–25%)

A database team needs Azure SQL Database accessible only from specific VNets and never exposed to the public internet. Which configuration achieves this?

  1. Configure a Private Endpoint for Azure SQL and disable the public network access setting
  2. Deploy SQL Server on a virtual machine behind an internal Azure Load Balancer instance
  3. Enable Azure DDoS Protection Standard on the virtual network hosting the database
  4. Enable the public endpoint with IP firewall rules restricting access to known addresses
Show answer & explanation

Correct: A — Private Endpoint with public access disabled. A Private Endpoint assigns the SQL instance a private IP from the VNet, and disabling public access ensures it is reachable only over private connectivity.

Why not the others: IP firewall rules (D) still use the internet-exposed public endpoint; DDoS Protection (C) mitigates volumetric attacks but doesn’t restrict access paths; SQL on a VM (B) adds management overhead versus the PaaS Private Endpoint approach.

Source: Microsoft Learn — Private Endpoint overview →
Question 10 · Secure compute, storage, and databases (20–25%)

A company stores sensitive financial data in Blob Storage. They need encryption with customer-controlled keys and the ability to revoke access by revoking the key. Which encryption configuration should be implemented?

  1. Customer-managed keys stored in Azure Key Vault with access controlled by the customer
  2. Default Microsoft-managed encryption keys handled entirely by the Azure Storage platform
  3. Client-side encryption using keys embedded directly within the application source code
  4. No encryption applied to the storage account with network-level security isolation only
Show answer & explanation

Correct: A — customer-managed keys in Key Vault. CMK gives the customer full key control, including revoking data access by disabling or deleting the key, and centralized rotation and lifecycle management.

Why not the others: Microsoft-managed keys (B) don’t allow customer-controlled revocation; keys embedded in source code (C) are a severe vulnerability if the code leaks; no encryption (D) leaves data readable to anyone with storage access regardless of network controls.

Source: Microsoft Learn — customer-managed keys → Further reading: PowerKram — data encryption & key management →

Keep going: Learning & Career resources

AZ-500 sits at the intersection of two paths — hands-on Azure security engineering, and broader cybersecurity careers. Both PowerKram hubs back this exam (and its successor, SC-500).

Related Microsoft Azure exams

Deep dive: AZ-500 format, scoring, the SC-500 transition, and what the current outline emphasizes

Exam format and scoring

AZ-500 delivers roughly 40–60 questions in about 100 minutes, in multiple choice, multiple response, drag-and-drop, hot area, and case-study formats, with occasional lab-based questions at the end (not revisitable). It is scored on a 1000-point scale with 700 to pass. Expect scenario questions where two answers are plausible and one meaningful detail — “only from managed devices,” “no standing access,” “never public” — decides the correct one. Read the security practices guide →

The SC-500 transition

AZ-500 retires August 31, 2026, and SC-500 (Cloud and AI Security Engineer) becomes the successor — in beta since May 2026. SC-500 carries forward the core AZ-500 content (identity, networking, workload protection, Defender for Cloud, Sentinel) and adds a distinct AI-security discipline: Copilot risk, Entra Agent ID, Defender for AI, and Purview DSPM. If you already hold AZ-500, your annual renewal keeps working; if you’re studying now and will test after August, plan for SC-500 instead. Most of your AZ-500 preparation transfers. Read the security career path →

What the current outline emphasizes

On the January 2026 outline the Defender for Cloud and Sentinel domain is the single heaviest at 30–35% — it also absorbed Key Vault and Azure Policy governance — so security-operations tooling and KQL fluency carry real weight. Identity dropped to 15–20% but remains foundational because networking, workload, and detection scenarios all depend on it. Two recurring blind spots: infrastructure-background candidates underprepare Sentinel, and everyone underestimates how much Key Vault nuance (access policies vs. RBAC, soft delete vs. purge protection) is tested. Read about cloud security posture →

Realistic study path

AZ-500 rewards hands-on work over reading. With AZ-104-level Azure skills in place, work the official Microsoft Learn AZ-500 paths, then build the canonical labs: a Conditional Access policy for risky sign-ins, a Key Vault with RBAC and soft delete, a Sentinel workspace with a custom analytics rule, and a network design with Private Endpoints and Azure Firewall. Drill scenario questions in PowerKram Learn mode by domain — starting with the heaviest, Defender/Sentinel — and finish with full timed Exam-mode runs. Most candidates need 8–14 weeks. Read the AZ-104 foundation path →

Cost, renewal, and career outlook

The exam costs $165 USD (regional pricing varies), delivered through Pearson VUE at a test center or online with OnVUE. The certification is valid for one year and renews through a free online assessment on Microsoft Learn. Azure security roles are growing faster than cloud roles overall, and the skills transfer directly to SC-500 and, beyond it, to SC-100 (Cybersecurity Architect Expert). For salary ranges and role-specific paths, see the Career Hub. Career Hub — Cybersecurity Specialist →

Frequently asked questions

Is AZ-500 being retired?
Yes. Microsoft has announced AZ-500 will retire on August 31, 2026, at 11:59 PM CST. The successor is SC-500 (Cloud and AI Security Engineer), in beta since May 2026. If you pass AZ-500 before the retirement date, the credential stays valid for a year and renews through the free annual online assessment; if you’ll test after that date, study for SC-500 instead. Most of the content carries over.
What are the AZ-500 exam domains and weights?
Per Microsoft’s January 2026 outline (four domains): Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel (30–35%, heaviest), Secure compute, storage, and databases (20–25%), Secure networking (20–25%), and Secure identity and access (15–20%). The Defender/Sentinel domain is the single heaviest and now includes Key Vault and Azure Policy governance.
Did the AZ-500 blueprint change recently?
Yes. On the current outline, the Defender for Cloud and Sentinel domain is the single heaviest at 30–35% (and absorbed Key Vault and Azure Policy governance), while identity and access eased to 15–20%. Older study material that treats identity as the largest domain is out of date.
What is the AZ-500 passing score and format?
700 of 1000 (scaled). The exam has roughly 40–60 questions in about 100 minutes, in multiple choice, multiple response, drag-and-drop, hot area, and case-study formats, with occasional lab questions. You don’t need to pass each domain separately.
How much does AZ-500 cost and how do I renew?
$165 USD list price (regional pricing varies). While active, the certification is valid for one year and renews via a free online assessment on Microsoft Learn, available starting six months before expiry.

Start your free 24-hour AZ-500 practice trial

Full access to 780+ questions, both study modes, source-linked explanations, and score-by-domain. No credit card required.

Start free trial →