Free — No Signup RequiredMicrosoft

AZ-500 Free Practice Test — Azure Security Engineer Associate

3 real exam-style questions across all 4 official blueprint domains. Answer each question to reveal the full explanation — then see exactly where to focus.

3 questions~5 minutes4 domainsPass mark: 700/1000
0 / 3
1
Manage identity and access

A company uses Azure AD Identity Protection. They want to automatically block sign-ins that have a high user risk level, but only for users in the 'Finance' department. They also want to require MFA for medium user risk level for all users (including Finance) when sign-in risk is not blocked. They have already created a Conditional Access policy for the Finance department that has a condition of 'User risk level: High' and a grant control of 'Block access'. What additional configuration is needed to also require MFA for all users with medium user risk?

Select an answer to reveal the explanation and AI Tutor

2
Secure networking

A company has a hub-spoke network topology. The hub virtual network contains an Azure Firewall and an ExpressRoute gateway for on-premises connectivity. The spoke virtual network hosts a critical application. They need to ensure that all outbound traffic from the spoke to the internet and to on-premises networks is routed through the Azure Firewall. They configure a user-defined route (UDR) on the spoke subnet with address prefix 0.0.0.0/0 and next hop as the Azure Firewall's private IP. They also disable 'Virtual network gateway route propagation' on the spoke subnet. However, traffic to on-premises still bypasses the firewall and goes through the ExpressRoute gateway. What is the most likely cause?

Select an answer to reveal the explanation and AI Tutor

3
Secure compute, storage, and databases

A company uses Azure SQL Database with Transparent Data Encryption (TDE) protected by a customer-managed key (CMK) stored in Azure Key Vault. The Key Vault has a firewall enabled that denies all public network access. The SQL server is in the same region and has a system-assigned managed identity with the 'Key Vault Crypto Service Encryption User' role assigned at the key scope. However, TDE operations fail because the SQL server cannot access the Key Vault. What additional configuration is required to allow the SQL server to access the Key Vault for TDE operations?

Select an answer to reveal the explanation and AI Tutor

Answer all 3 questions to see your domain score breakdown

7-day free trial · No credit card

Unlock all 60+ AZ-500 questions

AI Tutor after every question, per-domain analytics, spaced repetition, daily challenges — and every other certification on the platform.

Cancel anytime · One plan covers every certification

AZ-500 Practice Test — FAQ

Is this AZ-500 practice test really free?

Yes — all 3 questions on this page are free with no account required. For the full 60-question bank, AI Tutor, domain analytics, and spaced repetition, a JT Exams subscription starts from £9.99/month with a 7-day free trial.

How realistic are these AZ-500 practice questions?

Every question is written by Microsoft-certified engineers against the official AZ-500 exam blueprint. Questions follow the same wording style and scenario complexity as the actual exam. They are original questions — not brain dumps — so you learn the underlying concepts, not just memorised answers.

How many questions are on the actual AZ-500 exam?

The AZ-500 exam contains approximately 60 questions and must be completed within 120 minutes. The passing score is 700/1000.

What domains does the AZ-500 cover?

The AZ-500 covers 4 domains: Manage identity and access (null%), Secure networking (null%), Secure compute, storage, and databases (null%), Manage security operations (null%). This practice test includes questions from every domain.