Microsoft Azure Security Technologies (AZ-500) Exam Blueprint

AZ-500

40Questions
100 minDuration
700/1-1000Passing Score
$165Price
12Languages
Practice Microsoft Azure Security Technologies on QuizForge

Exam Domains

1.0 Secure identity and access 15%
  • 1.1Manage security controls for identity and access
  • 1.2Manage Azure built-in role assignments
  • 1.3Manage custom roles, including Azure roles and Microsoft Entra roles
  • 1.4Plan and manage Azure resources in Microsoft Entra Privileged Identity Management, including settings and assignments
  • 1.5Implement multi-factor authentication (MFA) for access to Azure resources
  • 1.6Implement Conditional Access policies for cloud resources in Azure
  • 1.7Manage Microsoft Entra application access and managed identities
  • 1.8Manage access to enterprise applications in Microsoft Entra ID, including OAuth permission grants
  • 1.9Manage Microsoft Entra app registrations
  • 1.10Configure app registration permission scopes
  • 1.11Manage app registration permission consent
  • 1.12Manage and use service principals
  • 1.13Manage managed identities
2.0 Secure networking 20%
  • 2.1Plan and implement security for virtual networks
  • 2.2Plan and implement Network Security Groups (NSGs) and Application Security Groups (ASGs)
  • 2.3Manage virtual networks by using Azure Virtual Network Manager
  • 2.4Plan and implement user-defined routes (UDRs)
  • 2.5Plan and implement Virtual Network peering or VPN gateway
  • 2.6Plan and implement Virtual WAN, including secured virtual hub
  • 2.7Secure VPN connectivity, including point-to-site and site-to-site
  • 2.8Implement encryption over ExpressRoute
  • 2.9Configure firewall settings on Azure resources
  • 2.10Monitor network security by using Network Watcher
  • 2.11Plan and implement security for private access to Azure resources
  • 2.12Plan and implement virtual network Service Endpoints
  • 2.13Plan and implement Private Endpoints
  • 2.14Plan and implement Private Link services
  • 2.15Plan and implement network integration for Azure App Service and Azure Functions
  • 2.16Plan and implement network security configurations for an App Service Environment (ASE)
  • 2.17Plan and implement network security configurations for an Azure SQL Managed Instance
  • 2.18Plan and implement security for public access to Azure resources
  • 2.19Plan and implement Transport Layer Security (TLS) to applications, including Azure App Service and API Management
  • 2.20Plan, implement, and manage an Azure Firewall, including Azure Firewall Manager and firewall policies
  • 2.21Plan and implement an Azure Application Gateway
  • 2.22Plan and implement an Azure Front Door, including Content Delivery Network (CDN)
  • 2.23Plan and implement a Web Application Firewall (WAF)
  • 2.24Recommend when to use Azure DDoS Protection Standard
3.0 Secure compute, storage, and databases 20%
  • 3.1Plan and implement advanced security for compute
  • 3.2Plan and implement remote access to virtual machines, including Azure Bastion and just-in-time (JIT) VM access
  • 3.3Configure network isolation for Azure Kubernetes Service (AKS)
  • 3.4Secure and monitor AKS
  • 3.5Configure authentication for AKS
  • 3.6Configure security monitoring for Azure Container Instances (ACIs)
  • 3.7Configure security monitoring for Azure Container Apps (ACAs)
  • 3.8Manage access to Azure Container Registry (ACR)
  • 3.9Configure disk encryption, including Azure Disk Encryption (ADE), encryption at host, and confidential disk encryption
  • 3.10Recommend security configurations for Azure API Management
  • 3.11Plan and implement security for storage
  • 3.12Configure access control for storage accounts
  • 3.13Manage storage account access keys
  • 3.14Select and configure an appropriate method for access to Azure Files
  • 3.15Select and configure an appropriate method for access to Azure Blob Storage
  • 3.16Select and configure appropriate methods for protecting against data security threats, including soft delete, backups, versioning, and immutable storage
  • 3.17Configure Bring your own key (BYOK)
  • 3.18Enable double encryption at the Azure Storage infrastructure level
  • 3.19Plan and implement security for Azure SQL Database and Azure SQL Managed Instance
  • 3.20Enable Microsoft Entra database authentication
  • 3.21Enable database auditing
  • 3.22Plan and implement dynamic masking
  • 3.23Implement Transparent Data Encryption (TDE)
  • 3.24Recommend when to use Azure SQL Database Always Encrypted
4.0 Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel 30%
  • 4.1Implement and manage enforcement of cloud governance policies
  • 4.2Create, assign, and interpret policies and initiatives in Azure Policy
  • 4.3Configure Azure Key Vault network settings
  • 4.4Configure access to Key Vault, including vault access policies and Azure Role Based Access Control
  • 4.5Manage certificates, secrets, and keys
  • 4.6Configure key rotation
  • 4.7Perform backup and recovery of certificates, secrets, and keys
  • 4.8Implement security controls to protect backups
  • 4.9Implement security controls for asset management
  • 4.10Manage security posture by using Microsoft Defender for Cloud
  • 4.11Identify and remediate security risks by using the Microsoft Defender for Cloud Secure Score and Inventory
  • 4.12Assess compliance against security frameworks by using Microsoft Defender for Cloud
  • 4.13Manage compliance standards in Microsoft Defender for Cloud
  • 4.14Add custom standards to Microsoft Defender for Cloud
  • 4.15Connect hybrid cloud and multi-cloud environments to Microsoft Defender for Cloud, including Amazon Web Services (AWS) and Google Cloud Platform (GCP)
  • 4.16Implement and use Microsoft Defender External Attack Surface Management (EASM)
  • 4.17Configure and manage threat protection by using Microsoft Defender for Cloud
  • 4.18Enable cloud workload protection plans in Microsoft Defender for Cloud
  • 4.19Configure Microsoft Defender for Servers, Microsoft Defender for Databases, and Microsoft Defender for Storage
  • 4.20Implement and manage agentless scanning for virtual machines in Microsoft Defender for Servers
  • 4.21Implement and manage Microsoft Defender Vulnerability Management for Azure virtual machines
  • 4.22Connect to and configure settings in Microsoft Defender for Cloud
  • 4.23Devops Security, including GitHub, Azure DevOps, and GitLab
  • 4.24Configure and manage security monitoring and automation solutions
  • 4.25Manage and respond to security alerts in Microsoft Defender for Cloud
  • 4.26Configure workflow automation by using Microsoft Defender for Cloud
  • 4.27Monitor network security events and performance data by configuring data collection rules (DCRs) in Azure Monitor
  • 4.28Configure data connectors in Microsoft Sentinel
  • 4.29Enable analytics rules in Microsoft Sentinel
  • 4.30Configure automation in Microsoft Sentinel

Exam Details

Question TypesMultiple Choice, Multiple Response, Drag and Drop, Case Study, Build List, Hot Area, Repeated Answer Choices
FormatLinear
Online ProctoringAvailable
ID RequirementsOne valid, government-issued photo ID. Name on ID must match registration. For online: webcam required, room must be clear of people and materials.
RenewalRequired -- Microsoft certifications (Associate/Expert/Specialty) are renewed annually for free via a short renewal assessment on Microsoft Learn. Renewal assessment available 6 months before expiry. Fundamentals certifications do not expire.
Retake PolicyNo waiting period for first retake if score >= 500 on failed attempt. If score < 500: 14-day waiting period before retake. Maximum 5 attempts per exam per year (365 days). Free retake voucher sometimes included in official instructor-led training.
LanguagesEnglish, Simplified Chinese, Traditional Chinese, French, German, Japanese, Korean, Portuguese, Russian, Spanish, Arabic, Indonesian

Official Study Resources