TechNuggets Academy
SC-500

Free Microsoft Certified: Azure Security Engineer Associate Practice Test

12 exam-style questions with full explanations — no sign-up. Score yourself, then close your gaps with the full course.

Exam fee ~$1654 exam domainsLevel Intermediate2 timed practice tests in the course
✅ Free practice — no sign-up📝 Real exam-style questions💡 Detailed explanations💸 30-day money-back via Udemy
Question 1 of 12 · Manage identity, access, and governance
A company wants administrators to obtain Global Administrator privileges only when needed, require manager approval before activation, and automatically expire after 8 hours. Which solution BEST meets these requirements?
PIM eligible assignments with approval workflows and configurable maximum activation duration provide true just-in-time, time-bound, approved privileged access — exactly what the scenario requires.
Question 2 of 12 · Secure storage, databases, and networking
A retail company must give an external logistics partner temporary read access to a single container in an Azure Storage account for the next 24 hours. The partner does not have an Azure AD account in the company's tenant, and the storage account key must never be shared. Which solution BEST meets this requirement?
A service SAS scoped to the container, restricted to read permission, and time-boxed to 24 hours grants exactly the access needed without exposing the account key and without requiring an identity in the tenant.
Question 3 of 12 · Secure compute
A company runs Windows and Linux Azure VMs storing regulated financial data. A compliance requirement mandates that OS and data disk volumes be encrypted at the guest operating system level (not just at the storage platform level), using encryption keys the company controls in Azure Key Vault, and the encryption status must be verifiable from within the VM. Which solution should the security engineer implement?
Azure Disk Encryption (ADE) uses BitLocker (Windows) or DM-Crypt (Linux) inside the guest OS to encrypt volumes, integrates with Azure Key Vault for key storage/management, and can be verified from within the VM — satisfying the guest-level encryption requirement with customer-controlled keys.
Question 4 of 12 · Manage and monitor security posture
In Microsoft Defender for Cloud, a security team notices that two recommendations with similar remediation effort contribute very different point values toward the secure score. What determines the point value of a security recommendation?
Secure score points are calculated per security control, and each control has a fixed weight representing its relative importance to your overall security posture. A control's total points are distributed across the recommendations within it based on the proportion of healthy resources, so higher-weighted controls yield higher point values even for similarly effortful fixes.
Question 5 of 12 · Manage identity, access, and governance
An Azure Function App needs to read secrets from Azure Key Vault. The solution must avoid storing any credentials or secrets in code or application configuration. Which authentication method should you use?
A system-assigned managed identity is automatically managed by Azure AD with no secrets to store or rotate manually, and can be granted least-privilege access to Key Vault via RBAC or access policy.
Question 6 of 12 · Secure storage, databases, and networking
Contoso runs an Azure SQL Database and wants all traffic between the database and its VNets (including a VNet reachable only via ExpressRoute) to stay off any public IP address, with the database reachable via a private IP address inside the VNet. Which feature should be configured?
Private Link provisions a private endpoint with a private IP address from the VNet's address space, bringing SQL Database traffic entirely onto the Microsoft backbone with no public IP exposure, and it is reachable from on-premises over ExpressRoute or VPN.
Question 7 of 12 · Secure compute
A security team manages several Azure Kubernetes Service (AKS) clusters and needs to enforce, cluster-wide, that no pod can be deployed with a privileged security context, with the compliance status visible in Microsoft Defender for Cloud's regulatory dashboard. Which approach should they use?
The Azure Policy Add-on for AKS installs the Gatekeeper admission controller, which can preventively enforce (not just detect) constraints such as 'Kubernetes cluster should not allow privileged containers,' and compliance results surface in Defender for Cloud's regulatory compliance dashboard.
Question 8 of 12 · Manage and monitor security posture
A security team needs to onboard an AWS account to Microsoft Defender for Cloud to enable Defender for Servers and CSPM coverage on EC2 instances, but they want to avoid deploying and maintaining agents on every instance. Which onboarding approach should they use?
Defender for Cloud's native AWS connector uses a CloudFormation template to deploy the required roles, and agentless scanning (via disk snapshot analysis) provides vulnerability and malware coverage for VMs without installing any agent on the instance itself.
Question 9 of 12 · Manage identity, access, and governance
You need an Azure Policy assignment that prevents non-compliant storage accounts (for example, accounts with public blob access enabled) from being created at all, rather than just reporting them. Which policy effect should you configure?
The Deny effect blocks the resource write request outright when it violates the policy rule, preventing creation of non-compliant storage accounts.
Question 10 of 12 · Secure storage, databases, and networking
An administrator needs to configure Transparent Data Encryption (TDE) on an Azure SQL Database using a customer-managed key stored in Azure Key Vault (Bring Your Own Key). Which configuration step is REQUIRED before the key vault key can be set as the TDE protector?
TDE with a customer-managed key requires the SQL server's managed identity to have Get, Wrap Key, and Unwrap Key permissions on the Key Vault key so the server can retrieve and use the key as the TDE protector.
Question 11 of 12 · Secure compute
An application hosted on Azure App Service must read a database connection string containing a secret at runtime, without the secret ever being stored in source code, configuration files checked into source control, or deployment slot settings. Which configuration achieves this?
Using a Key Vault reference in App Settings, backed by the App Service's managed identity, retrieves the secret directly from Key Vault at runtime — the secret is never persisted in app config, code, or source control, and identity-based RBAC/access policy governs access.
Question 12 of 12 · Manage and monitor security posture
You want Microsoft Sentinel to automatically correlate multiple low-fidelity, seemingly unrelated alerts from different data sources into a single high-confidence incident using built-in machine learning correlation. Which analytics rule type should you enable?
Fusion rules use machine learning to correlate anomalous or low-fidelity activities from multiple products/data sources over time, generating a single high-fidelity incident that represents a probable multi-stage attack. This is their specific purpose in Sentinel.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →

SC-500 exam — quick answers

How much does the SC-500 exam cost?

The exam fee is approximately $165 and varies by region — confirm current pricing with the certification vendor before you book.

What topics are on the exam?

It covers 4 domains: Manage identity, access, and governance (20-25%), Secure storage, databases, and networking (25-30%), Secure compute (20-25%), Manage and monitor security posture (20-25%). The full course has a dedicated chapter, lab and practice-test coverage for each.

Is this practice test really free?

Yes — all questions on this page are free with explanations and no sign-up. The paid Udemy course adds two full-length timed exams, video lessons and hands-on labs.

Will this prepare me for the real exam?

The questions mirror the real exam's style and are mapped to the official domains. This is exam-focused preparation — combine the free test with the full course's timed simulations to gauge your readiness.

More free practice by exam domain:
Manage identity, access, and governance →Secure storage, databases, and networking →Secure compute →Manage and monitor security posture →