Microsoft AZ-500 Exam
Microsoft Azure Security Technologies (Page 19 )

Updated On: 9-Feb-2026

You have an Azure Active Directory (Azure AD) tenant.
You have the deleted objects shown in the following table.
On May 4, 2020, you attempt to restore the deleted objects by using the Azure Active Directory admin center.
Which two objects can you restore? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

  1. Group1
  2. Group2
  3. User2
  4. User1

Answer(s): B,C

Explanation:

Deleted users and deleted Office 365 groups are available for restore for 30 days.
You cannot restore a deleted security group.


Reference:

https://docs.microsoft.com/en-us/azure/active-directory/users-groups-roles/groups-restore-deleted



HOTSPOT (Drag and Drop is not supported) (Drag and Drop is not supported)
You have an Azure subscription named Subscription1 that contains the resources shown in the following table.
You create an Azure role by using the following JSON file.
You assign Role1 to User1 for RG1.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:


  1. See Explanation section for answer.

Answer(s): A

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#compute



You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains a user named User1.
You plan to publish several apps in the tenant.
You need to ensure that User1 can grant admin consent for the published apps.
Which two possible user roles can you assign to User1 to achieve this goal? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

  1. Security administrator
  2. Cloud application administrator
  3. Application administrator
  4. User administrator
  5. Application developer

Answer(s): B,C

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/grant-admin-consent



You have an Azure subscription that is associated with an Azure Active Directory (Azure AD) tenant.
When a developer attempts to register an app named App1 in the tenant, the developer receives the error message shown in the following exhibit.
You need to ensure that the developer can register App1 in the tenant.
What should you do for the tenant?

  1. Modify the Directory properties.
  2. Set Enable Security defaults to Yes.
  3. Configure the Consent and permissions settings for enterprise applications.
  4. Modify the User settings.

Answer(s): D

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/active-directory/develop/active-directory-how-applications-are-added



You have an Azure subscription that contains an Azure Active Directory (Azure AD) tenant and a user named User1.
The App registrations settings for the tenant are configured as shown in the following exhibit.
You plan to deploy an app named App1.
You need to ensure that User1 can register App1 in Azure AD. The solution must use the principle of least privilege.
Which role should you assign to User1?

  1. App Configuration Data Owner for the subscription
  2. Managed Application Contributor for the subscription
  3. Cloud application administrator in Azure AD
  4. Application developer in Azure AD

Answer(s): D

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/active-directory/roles/delegate-by-task






Post your Comments and Discuss Microsoft AZ-500 exam prep with other Community members:

Join the AZ-500 Discussion