Below is our fifth free AZ-500 Practice Test. This final test in our 8-part series is designed to help you review advanced Azure security topics and assess your readiness for the Microsoft Azure Security Engineer Associate certification. Use it as a final step in your exam preparation journey.
0 of 20 Questions completed
Questions:
You have already completed the quiz before. Hence you can not start it again.
You must sign in or sign up to start the quiz.
You must first complete the following:
Test complete. Results are being recorded.
0 of 20 Questions answered correctly
Your time:
Time has elapsed
You have reached 0 of 0 point(s), (0 )
Earned Point(s): 0 of 0 , (0 )
0 Essay(s) Pending (Possible Point(s): 0 )
Question 1 of 20
You want to monitor the network connection between a virtual machine located on the East Coast of the USA and another virtual machine located on the West Coast of the USA. Which Azure Network Watcher feature can you use to check connectivity, diagnose network issues, and measure connection latency between the two virtual machines?
Question 2 of 20
You are trying to enable NSG (Network Security Group) flow logs in your Azure subscription, but encounter an AuthorizationFailed error. What is the most likely cause of this issue?
Question 3 of 20
You have configured a service endpoint for an Azure virtual network to allow access to a specific Azure service (e.g., Azure Storage). Which of the following is the recommended method to validate that traffic is correctly routed through the service endpoint?
Question 4 of 20
You configure a service endpoint for Azure Service Bus by associating a Service Bus namespace with a virtual network subnet. Which resource provider must be registered to complete the service endpoint configuration?
Question 5 of 20
When configuring a private endpoint, which connection approval method is used if the private link consumer lacks RBAC permissions on the service provider’s resource?
Question 6 of 20
John wants to ensure that a storage account is accessible only through a private endpoint and that all public endpoint traffic is denied. Which Azure feature should he use to enforce this access restriction?
Question 7 of 20
You created an Azure PrivateLink service using a Standard Load Balancer with a backend pool configured using IP addresses. When trying to connect using the shared consumers alias, they cannot access the resources. What is the reason?
Question 8 of 20
You are configuring backend Private Link by connecting Databricks Runtime clusters in a customer-managed VNet to the Azure Databricks workspace’s core services.
Which two connections are enabled by this configuration? (Choose two.)
Question 9 of 20
Which of the following actions are not supported when using virtual network (VNet) integration with Azure App Service apps? (Choose two.)
Question 10 of 20
You are using regional VNet Integration in Azure App Service to access an Azure service secured with service endpoints.
What is the correct way to configure service endpoints for this setup?
Question 11 of 20
Which Azure resource should you use to configure network customizations for an App Service Environment?
Question 12 of 20
A media company is preparing for a televised event expected to generate up to 150K requests per second from a global audience. Performance testing shows that a single App Service Environment (ASE) configuration can sustain 25K RPS. The solution must:
Scale horizontally by deploying multiple identical ASEs in multiple regions.
Ensure users always connect to the nearest healthy ASE instance.
Support a custom domain for all traffic.
Allow for the rapid addition or removal of ASE instances without requiring changes to the public endpoint.
Which Azure service best meets these requirements?
Question 13 of 20
You are configuring TLS for an Azure App Service web app. You plan to upload a private certificate to secure the custom domain. Which two requirements must the certificate meet? (Choose two.)
Question 14 of 20
An administrator has enabled TLS termination in the listener of an existing Azure Application Gateway and now needs to configure end-to-end TLS so that communication between the gateway and the backend servers remains encrypted. What is the next step?
Question 15 of 20
An admin configured Azure Firewall Manager to filter virtual network-to-internet traffic. She added 50 public IP addresses at once, causing the secure hub firewall to fail. What should she do to fix this issue?
Question 16 of 20
In Azure Firewall, which policy’s rule collection group takes precedence if a firewall policy is inherited from a parent policy?
Question 17 of 20
A company is configuring Azure Application Gateway for SSL/TLS encryption. They require the gateway to terminate SSL at the frontend, inspect the traffic, then establish a new SSL connection to the backend servers. Which configuration meets this requirement?
Question 18 of 20
You are manually scaling an Azure Application Gateway v2 SKU. When setting the number of instances based on traffic needs, calculate the compute unit metric using the CPU utilization metric from the past month. How should you calculate it?
Question 19 of 20
Which Azure FrontDoor traffic routing method for frontend hosts or domains ensures requests from the same end user are consistently sent to the same origin?
Question 20 of 20
In Azure Front Door, what happens if health probes fail for every origin in an origin group?
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
Current
Correct
Incorrect