Skip to main content
Cybersecurity ⭐ Premium

Microsoft Azure Security Technologies (AZ-500) - 340 Questions

By Webmaster Certland ❤️ 0 likes

Practice exam for AZ-500. Covers identity and access security, network security, compute/storage/database security, and Microsoft Defender for Cloud and Sentinel.

🔒

Premium Content

This exam is exclusive to Premium users. Upgrade to get unlimited access!

Become Premium

👁️ Free Preview (5 of 340 questions)

1. A company assigns a developer the Contributor role on a resource group. The developer needs to grant a colleague read access to a storage account within that resource group. The colleague reports that the developer cannot complete this task. What is the reason?

A The Contributor role only grants read access to storage accounts.
B The Contributor role does not include permission to create role assignments.
C Role assignments can only be created at the subscription scope, not resource group scope.
D The colleague must be removed from all other roles before a new role can be assigned.

2. A team member has the Contributor role on a subscription. A manager needs this team member to also be able to deploy resources but not modify existing role assignments. Which statement best describes whether the current role meets these requirements?

A The Contributor role meets both requirements: it allows deploying resources and does not include role assignment permissions.
B The Reader role should be used instead, as it prevents modification of role assignments.
C The Owner role is required to deploy resources to a subscription.
D The User Access Administrator role should be assigned alongside Reader to allow deployments.

3. A security engineer needs to delegate the ability to assign Azure roles to a junior administrator without granting full ownership of the subscription. The junior administrator should not be able to manage resources directly. Which built-in role should the security engineer assign?

A Owner
B Contributor
C User Access Administrator
D Security Administrator

4. A cloud administrator needs to assign the Reader role to a new user so that the user can view all resources within a specific Azure subscription. The administrator is using the Azure portal. Which sequence of steps should the administrator follow?

A Navigate to the subscription, open Access control (IAM), click Add role assignment, select Reader, assign to the user.
B Navigate to a resource group within the subscription, open Access control (IAM), and assign Reader to the user.
C Navigate to Microsoft Entra ID, open the user's profile, and assign the Reader role from user settings.
D Navigate to Azure Policy and create a policy to grant the Reader role to the user on the subscription.

5. An administrator needs to assign the Contributor role to a service principal named 'app-deploy-sp' on a resource group named 'rg-production' within subscription ID '00000000-1111-2222-3333-444444444444'. Which Azure CLI command should the administrator run?

A az role assignment create --assignee app-deploy-sp --role Contributor --resource-group rg-production
B az role assignment create --assignee app-deploy-sp --role Contributor --scope /subscriptions/00000000-1111-2222-3333-444444444444/resourceGroups/rg-production
C az role definition create --assignee app-deploy-sp --role Contributor --scope /subscriptions/00000000-1111-2222-3333-444444444444/resourceGroups/rg-production
D az role assignment create --assignee app-deploy-sp --role Contributor --scope /subscriptions/00000000-1111-2222-3333-444444444444

Want to test yourself for real?

Create a free account and run our exam simulation engine.

Free No credit card
  • Simulation engine
  • Up to 10 questions per attempt
  • Score & basic stats
Create free account Already have an account? Sign in
Best
Premium 7-day trial
  • All 340 questions
  • Detailed explanations
  • Smart Practice + Focus Mode
⭐ Start 7-day free trial

Information

Questions 340
Time 2h
Difficulty Medium
Minimum Score 70.00%

🤍 Like

Related Exams

Discussion

No comments yet. Be the first to start the discussion!

Sign in to join the discussion.