1. Home
  2. Microsoft
  3. AZ-500 Exam Syllabus

Microsoft AZ-500 Exam Topics

Microsoft AZ-500 Exam

Microsoft Azure Security Technologies

Total Questions: 404

What is Included in the Microsoft AZ-500 Exam?

Authentic information about the syllabus is essential to go through the Microsoft AZ-500 exam in the first attempt. Study4Exam provides you with comprehensive information about Microsoft AZ-500 exam topics listed in the official syllabus. You should get this information at the start of your preparation because it helps you make an effective study plan. We have designed this Microsoft Azure Security Engineer Associate certification exam preparation guide to give the exam overview, practice questions, practice test, prerequisites, and information about exam topics that help to go through the Microsoft Azure Security Technologies exam. We recommend you use our preparation material to cover the entire Microsoft AZ-500 exam syllabus. Study4Exam offers 3 formats of Microsoft AZ-500 exam preparation material. Each format provides new practice questions in PDF format, web-based and desktop practice exams to get passing marks in the first attempt.

Microsoft AZ-500 Exam Overview :

Exam Name Microsoft Azure Security Technologies
Exam Code AZ-500
Actual Exam Duration 120 minutes
Expected no. of Questions in Actual Exam 60
Exam Registration Price $165
Official Information https://www.microsoft.com/en-us/learning/exam-az-500.aspx
See Expected Questions Microsoft AZ-500 Expected Questions in Actual Exam
Take Self-Assessment Use Microsoft AZ-500 Practice Test to Assess your preparation - Save Time and Reduce Chances of Failure

Microsoft AZ-500 Exam Topics :

Section Weight Objectives
Manage identity and access 30-35% - Manage Azure Active Directory identities
  • configure security for service principals
  • manage Azure AD directory groups
  • manage Azure AD users
  • manage administrative units
  • configure password writeback
  • configure authentication methods including password hash and Pass Through Authentication (PTA), OAuth, and passwordless
  • transfer Azure subscriptions between Azure AD tenants
- Configure secure access by using Azure AD
  • monitor privileged access for Azure AD Privileged Identity Management (PIM)
  • configure Access Reviews
  • activate and configure PIM
  • implement Conditional Access policies including Multi-Factor Authentication (MFA)
  • configure Azure AD identity protection

- Manage application access

  • create App Registration
  • configure App Registration permission scopes
  • manage App Registration permission consent
  • manage API access to Azure subscriptions and resources

- Manage access control

  • configure subscription and resource permissions
  • configure resource group permissions
  • configure custom RBAC roles
  • identify the appropriate role
    apply principle of least privilege
  • interpret permissions
    check access
Implement platform protection 15-20% - Implement advanced network security
  • secure the connectivity of virtual networks (VPN authentication, Express Route encryption)
  • configure Network Security Groups (NSGs) and Application Security Groups (ASGs)
  • create and configure Azure Firewall
  • implement Azure Firewall Manager
  • configure Azure Front Door service as an Application Gateway
  • configure a Web Application Firewall (WAF) on Azure Application Gateway
  • configure Azure Bastion
  • configure a firewall on a storage account, Azure SQL, KeyVault, or App Service
  • implement Service Endpoints
  • implement DDoS protection
- Configure advanced security for compute
  • configure endpoint protection
  • configure and monitor system updates for VMs
  • configure authentication for Azure Container Registry
  • configure security for different types of container
    - implement vulnerability management
    - configure isolation for AKS
    - configure security for container registry
  • implement Azure Disk Encryption
  • configure authentication and security for Azure App Service
    - configure SSL/TLS certs
    - configure authentication for Azure Kubernetes Service
    - configure automatic updates
Manage security operations 25-30% - Monitor security by using Azure Monitor
  • create and customize alerts
  • monitor security logs by using Azure Monitor
  • configure diagnostic logging and log retention

- Monitor security by using Azure Security Center

  • evaluate vulnerability scans from Azure Security Center
  • configure Just in Time VM access by using Azure Security Center
  • configure centralized policy management by using Azure Security Center
  • configure compliance policies and evaluate for compliance by using Azure Security Center
  • configure workflow automation by using Azure Security Center

- Monitor security by using Azure Sentinel

  • create and customize alerts
  • configure data sources to Azure Sentinel
  • evaluate results from Azure Sentinel
  • configure a playbook by using Azure Sentinel

- Configure security policies

  • configure security settings by using Azure Policy
  • configure security settings by using Azure Blueprint
Secure data and applications 20-25% - Configure security for storage
  • configure access control for storage accounts
  • configure key management for storage accounts
  • configure Azure AD authentication for Azure Storage
  • configure Azure AD Domain Services authentication for Azure Files
  • create and manage Shared Access Signatures (SAS
    create a shared access policy for a blob or blob container
  • configure Storage Service Encryption
  • configure Azure Defender for Storage

- Configure security for databases

  • enable database authentication
  • enable database auditing
  • configure Azure Defender for SQL
    configure Azure SQL Database Advanced Threat Protection
  • implement database encryption
    implement Azure SQL Database Always Encrypted
- Configure and manage Key Vault
  • manage access to Key Vault
  • manage permissions to secrets, certificates, and keys
    configure RBAC usage in Azure Key Vault
  • manage certificates
  • manage secrets
  • configure key rotation
  • backup and restore of Key Vault items
  • configure Azure Defender for Key Vault

Updates in the Microsoft AZ-500 Exam Topics:

Microsoft AZ-500 exam questions and practice test are the best ways to get fully prepared. Study4exam's trusted preparation material consists of both practice questions and practice test. To pass the actual Azure Security Engineer Associate AZ-500 exam on the first attempt, you need to put in hard work on these questions as they cover all updated Microsoft AZ-500 exam topics included in the official syllabus. Besides studying actual questions, you should take the Microsoft AZ-500 practice test for self-assessment and actual exam simulation. Revise actual exam questions and remove your mistakes with the Microsoft Azure Security Technologies AZ-500 exam practice test. Online and Windows-based formats of the AZ-500 exam practice test are available for self-assessment.