Microsoft AZ-500 Exam
Microsoft Azure Security Technologies (Page 25 )

Updated On: 12-Feb-2026

You have the Azure virtual machines shown in the following table.
Each virtual machine has a single network interface.
You add the network interface of VM1 to an application security group named ASG1.
You need to identify the network interfaces of which virtual machines you can add to ASG1.
What should you identify?

  1. VM2 only
  2. VM2 and VM3 only
  3. VM2, VM3, VM4, and VM5
  4. VM2, VM3, and VM5 only

Answer(s): B

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/virtual-network/application-security-groups



SIMULATION
You need to create a new Azure Active Directory (Azure AD) directory named 12345678.onmicrosoft.com. The new directory must contain a user named user12345678 who is configured to sign in by using Azure Multi-Factor Authentication (MFA).

  1. See Explanation section for answer.

Answer(s): A

Explanation:

To create a new Azure AD tenant:
1. Browse to the Azure portal and sign in with an account that has an Azure subscription.
2. Select the plus icon (+) and search for Azure Active Directory.

3. Select Azure Active Directory in the search results.

4. Select Create.
5. Provide an Organization name (12345678) and an Initial domain name (12345678). Then select Create. This will create the directory named
12345678.onmicrosoft.com.

6. After directory creation is complete, select the information box to manage your new directory.
To create the user:
1. In the Azure portal, make sure you are on the Azure Active Directory fly out.

If not, select the Azure Active Directory icon from the left services navigation.

2. Under Manage, select Users.

3. Select All users and then select + New user.
4. Provide a Name and User name (user12345678) for the user. When you're done, select Create.
To enable MFA:
1. In the Azure portal, make sure you are on the Azure Active Directory fly out.

If not, select the Azure Active Directory icon from the left services navigation.

2. Under Manage, select Users.

3. Click on the Multi-Factor Authentication link.
4. Tick the checkbox next to the user's name and click the Enable link.


Reference:

https://docs.microsoft.com/en-us/power-bi/developer/create-an-azure-active-directory-tenant



You have an Azure subscription named Subcription1 that contains an Azure Active Directory (Azure AD) tenant named contoso.com and a resource group named
RG1.
You create a custom role named Role1 for contoso.com.
Where you can use Role1 for permission delegation?

  1. contoso.com only
  2. contoso.com and RG1 only
  3. contoso.com and Subscription1 only
  4. contoso.com, RG1, and Subscription1

Answer(s): A



You have an Azure subscription.
You enable Azure Active Directory (Azure AD) Privileged Identity Management (PIM).
Your company's security policy for administrator accounts has the following conditions:
-The accounts must use multi-factor authentication (MFA).
-The accounts must use 20-character complex passwords.
-The passwords must be changed every 180 days.
-The accounts must be managed by using PIM.
You receive multiple alerts about administrators who have not changed their password during the last 90 days.
You need to minimize the number of generated alerts.
Which PIM alert should you modify?

  1. Roles are being assigned outside of Privileged Identity Management
  2. Roles don't require multi-factor authentication for activation
  3. Administrators aren't using their privileged roles
  4. Potential stale accounts in a privileged role

Answer(s): D

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-how-to-configure-security-alerts?tabs=new



Your network contains an on-premises Active Directory domain named adatum.com that syncs to Azure Active Directory (Azure AD). Azure AD Connect is installed on a domain member server named Server1.
You need to ensure that a domain administrator for the adatum.com domain can modify the synchronization options. The solution must use the principle of least privilege.
Which Azure AD role should you assign to the domain administrator?

  1. Security administrator
  2. Global administrator
  3. User administrator

Answer(s): B

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/active-directory/hybrid/reference-connect-accounts-permissions






Post your Comments and Discuss Microsoft AZ-500 exam prep with other Community members:

Join the AZ-500 Discussion