Home/microsoft/Free Microsoft Azure AZ-500 Actual Exam Questions

Free Microsoft Azure AZ-500 Actual Exam Questions

The questions for this exam were last updated on January 9, 2026

Dumps Box (DumpsBox) offers up-to-date practice exam questions for AZ-500 certification exam which are developed and validated by Microsoft subject domain experts certified in Microsoft Azure AZ-500 . These practice questions are update regularly as we keep an eye on any recent changes in AZ-500 syllabus, and when there is update our team quickly adjusts the questions. This commitment to providing the best quality exam prep material to certification aspirants is what makes DumpsBox.com the best certification exam prep website. On top of that, our strong, yet strictly moderated, community based feedback keeps the content clean and current. Each question has helpful community discussion that provides it extra perspective and introduces helpful resources for better exam preparation. This also saves students from other outdated practice questions or illicit exam dumps that can have adverse affects on career. Browse through our Microsoft Azure AZ-500 exam questions and pass your exam on first try.

Question No. 1

HOTSPOT You have an Azure key vault named KeyVault1 that contains the items shown in the following table. AZ-500 practice exam questions In KeyVault1 the following events occur in sequence:

• item is deleted.

• ltem2 and Policy1 are deleted.

For each of the following statements, select Yes if the statement is true. Otherwise, select No. AZ-500 real exam questions

Top comments
RT
Rizwan T.
2026-02-20

Since the question shows deleted items but not purged, I’d say deleted secrets and keys are still in soft-delete state if enabled, so they should be recoverable. Anything marked as purged would be gone for sure.

0
SH
Saad H.
2026-02-20

Since the question shows deleted items but doesn’t say they’re purged, I’d say those deleted secrets and keys are still recoverable if soft-delete is on. So, statements about them being recoverable should be marked Yes.

0
Question No. 2
Note: This question is part of a series of questions that present the same scenario. Each question in
the series contains a unique solution that might meet the stated goals. Some question sets might
have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these
questions will not appear in the review screen.
You have an Azure subscription named Sub1.
You have an Azure Storage account named sa1 in a resource group named RG1.
Users and applications access the blob service and the file service in sa1 by using several shared
access signatures (SASs) and stored access policies.
You discover that unauthorized users accessed both the file service and the blob service.
You need to revoke all access to sa1.
Solution: You regenerate the Azure storage account access keys.
Does this meet the goal?
Select one option, then reveal solution.
Top comments
LR
Luke R.
2026-02-20

B. Regenerating the keys won’t cut off access granted by stored access policies since those policies are managed separately from the keys. So this won’t fully block unauthorized access that’s using those policies.

0
HR
Hassan R.
2026-02-11

Maybe B because stored access policies can still grant permissions even if keys are regenerated, so it might not fully revoke all access. Regenerating keys doesn’t affect policies directly.

0
Question No. 3
Note: The question is included in a number of questions that depicts the identical set-up. However,
every question has a distinctive result. Establish if the solution satisfies the requirements.
Your company has an Active Directory forest with a single domain, named weylandindustries.com.
They also have an Azure Active Directory (Azure AD) tenant with the same name.
You have been tasked with integrating Active Directory and the Azure AD tenant. You intend to
deploy Azure AD Connect.
Your strategy for the integration must make sure that password policies and user logon limitations
affect user accounts that are synced to the Azure AD tenant, and that the amount of necessary
servers are reduced.
Solution: You recommend the use of password hash synchronization and seamless SSO.
Does the solution meet the goal?
Select one option, then reveal solution.
Top comments
IU
Irfan U.
2026-02-12

It’s B because password hash sync copies hashes but doesn’t enforce on-prem password policies in Azure AD, so synced accounts won’t reflect those restrictions fully.

0
PL
Paul L.
2026-01-16

A imo, since password hash sync keeps password policies intact and seamless SSO cuts server needs.

0
Question No. 4
You need to recommend which virtual machines to use to host App1. The solution must meet the
technical requirements for KeyVault1.
Which virtual machines should you use?
Select one option, then reveal solution.
Top comments
SO
Sami O.
2026-02-20

Probably B here. VM1 and VM2 together seem to cover the key technical requirements without going overboard. VM3 and VM4 might add some extras but the question zeroes in on what KeyVault1 needs technically, not extra layers or redundancy. So sticking to the basics with those two should do the job.

0
SO
Sami O.
2026-02-20

A. VM1 alone meets the core requirements, so adding more VMs might be overkill. The question focuses on technical specs, not extras or redundancy.

0
Question No. 5Drag & Drop

DRAG DROP You create an Azure subscription with Azure AD Premium P2. You need to ensure that you can use Azure Active Directory (Azure AD) Privileged Identity Management (PIM) to secure Azure roles. Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order. AZ-500 practice exam questions

Options
ADiscover privileged roles.
BSign up PIM for Azure AD roles.
CConsent to PIM.
DDiscover resources.
EVerify your identity by using multi-factor authentication (MFA).
Drag an item to a target. Click × to remove.
Answer Area
Bucket 1
Drop item here
Bucket 2
Drop item here
Bucket 3
Drop item here
Top comments
AV
Andrew V.
2026-02-11

Activating PIM service should come before assigning roles or setting eligibility.

0
HE
Haris E.
2026-01-16

I’d start by excluding the step about assigning roles directly to users since PIM is supposed to manage those roles dynamically. Then, first activate the Azure AD Premium P2, set up eligible assignments, and finally configure activation settings for just-in-time access.

0
Question No. 6Drag & Drop

DRAG DROP You need to perform the planned changes for OU2 and User1. Which tools should you use? To answer, drag the appropriate tools to the correct resources. Each tool may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. AZ-500 practice exam questions

Options
AThe Azure portal
BAzure AD Connect
CThe Active Directory admin center
DActive Directory Sites and Services
EActive Directory Users and Computers
Drag an item to a target. Click × to remove.
Answer Area
OU2
Drop item here
User1
Drop item here
Top comments
TU
Tom U.
2026-02-11

Since OU2 is an organizational unit, ADUC fits best for managing it directly on-prem. For User1, if it's cloud-synced or cloud-only, Azure AD portal or PowerShell would work since those handle user objects in Azure.

0
OD
Osama D.
2026-01-28

If ADUC is an option, it’s definitely best for OU2 since that’s on-prem AD. For User1, Azure AD portal or PowerShell would make more sense since users can be synced or cloud-only.

0
Question No. 7
Note: This question is part of a series of questions that present the same scenario. Each question in
the series contains a unique solution that might meet the stated goals. Some question sets might
have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these
questions will not appear in the review screen.
You have a hybrid configuration of Azure Active Directory (Azure AD).
You have an Azure HDInsight cluster on a virtual network.
You plan to allow users to authenticate to the cluster by using their on-premises Active Directory
credentials.
You need to configure the environment to support the planned authentication.
Solution: You deploy Azure Active Directory Domain Services (Azure AD DS) to the Azure subscription.
Does this meet the goal?
Select one option, then reveal solution.
Top comments
AV
Amit V.
2026-02-11

I agree with option B here. Just deploying Azure AD DS doesn’t automatically sync your on-prem AD users. Without Azure AD Connect in place, there’s no way to get those credentials over to Azure AD DS for authentication. So, the solution described won’t meet the goal on its own.

0
JI
Jason I.
2026-01-19

B - Does this need Azure AD Connect setup too?

0
Question No. 8Drag & Drop

DRAG DROP You have an Azure subscription that contains the following resources: A virtual network named VNET1 that contains two subnets named Subnet1 and Subnet2. A virtual machine named VM1 that has only a private IP address and connects to Subnet1. You need to ensure that Remote Desktop connections can be established to VM1 from the internet. Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange then in the correct order. AZ-500 practice exam questions

Options
AConfigure a network security group (NSG).
BCreate a network rule collection.
CCreate a NAT rule collection.
DCreate a new subnet.
EDeploy Azure Application Gateway.
FDeploy Azure Firewall.
Drag an item to a target. Click × to remove.
Answer Area
Bucket 1
Drop item here
Bucket 2
Drop item here
Bucket 3
Drop item here
Top comments
BL
Bilal L.
2026-02-20

I’d say start by creating and associating a public IP to VM1’s NIC, then modify the NSG to allow inbound TCP 3389, and finally check if any routing or firewall rules need updating for internet traffic.

0
MV
Mohammad V.
2026-02-16

Before opening ports, you have to make sure VM1 actually has a public IP, or else RDP from the internet won’t work. So assigning a public IP to VM1’s network interface makes sense first. Then, configuring the NSG to allow inbound on port 3389 is necessary to let the traffic through. Lastly, creating a NAT rule or appropriate routing ensures the traffic is correctly forwarded to VM1. Without the public IP and NSG change, creating routes or NAT alone won’t help since the VM wouldn’t be reachable from outside.

0
Question No. 9

HOTSPOT You need to ensure that the Azure AD application registration and consent configurations meet the identity and access requirements. What should you use in the Azure portal? To answer, select the appropriate options in the answer area. AZ-500 practice exam questions

Top comments
CK
Chris K.
2026-02-12

I’d pick App registrations for the initial setup since that’s where you define permissions and consent settings for the app itself. Enterprise applications is more about managing the service principals created when the app is used in your tenant, so it’s less about configuring consent upfront and more about reviewing or revoking it after the fact. So, App registrations > API permissions should cover what the question asks regarding identity and access requirements.

0
CK
Chris K.
2026-02-12

App registrations, API permissions for setting consent and access controls.

0
Question No. 10
You have an Azure Kubernetes Service (AKS) cluster that will connect to an Azure Container Registry.
You need to use the automatically generated service principal for the AKS cluster to authenticate to
the Azure Container Registry.
What should you create?
Select one option, then reveal solution.
Top comments
MQ
Mark Q.
2026-02-18

D for sure, role assignment lets the service principal access the registry.

0
SJ
Sarah J.
2026-02-13

Probably D. The question mentions using the auto-generated service principal, so the main step is granting it permission to the container registry. Creating a role assignment is exactly that—assigning the needed role (like AcrPull) to the service principal so AKS can authenticate and pull images. The other options don’t fit since you’re not creating new users or secrets here, just giving existing SP rights.

0
Question No. 11
You have an Azure subscription that contains an Azure SQL server named sqlsrv1 and an Azure SQL
database named DB1. Sqlsrv1 is configured for Microsoft Entra authentication only.
You have the Microsoft Entra identities shown in the following table.
AZ-500 practice exam questions
Which users can create scoped credentials for DB1?
Select one option, then reveal solution.
Top comments
SZ
Sam Z.
2026-01-16

Is this about users needing admin rights for scoped credential creation?

0
Question No. 12
You need to ensure that users can access VM0. The solution must meet the platform protection
requirements.
What should you do?
Select one option, then reveal solution.
Top comments
UD
Usman D.
2026-02-13

B/D? DNAT (D) forwards traffic but without filtering, it’s risky. A filtering rule (B) adds control to allow only legit traffic, which better fits platform protection needs.

0
ZG
Zain G.
2026-01-19

B/D? DNAT (D) opens access, but filtering (B) controls traffic better.

0
Question No. 13

You have an Azure subscription. You configure the subscription to use a different Azure Active Directory (Azure AD) tenant. What are two possible effects of the change? Each correct answer presents a complete solution.

Select all that apply, then reveal solution.
Top comments
MB
Marco B.
2026-02-20

A imo, role assignments are tied to the original tenant's users.

0
MG
Michael G.
2026-02-12

A, managed identities rely on the original tenant, so B fits too.

0
Question No. 14

SIMULATION Lab Task use the following login credentials as needed: To enter your username, place your cursor in the Sign in box and click on the username below. To enter your password. place your cursor in the Enter password box and click on the password below. Azure Username: Userl [email protected] Azure Password: GpOAe4@lDg If the Azure portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab. The following information is for technical support purposes only: Lab Instance: 28681041 Task 5 You need to ensure that only devices connected to a 131-107.0.0/16 subnet can access data in the rg1lod28681041 Azure Storage account.

Top comments
ZT
Zain T.
2026-02-16

D works; network rules on storage accounts filter by IP regardless of private/public status.

0
ZP
Zain P.
2026-01-19

You can set a network rule on the storage account to allow only the 131-107.0.0/16 subnet. That’s the simplest way to restrict access by IP range. Other options won’t filter by subnet easily.

0
Question No. 15

HOTSPOT You have an Azure subscription that contains a storage account named contoso2023. You need to perform the following tasks:

• Verify that identity-based authentication over SMB is enabled.

• Only grant users access to contoso2023 in the year 2023.

Which two settings should you use? To answer, select the appropriate settings in the answer area. AZ-500 practice exam questions

Top comments
PB
Peter B.
2026-02-20

B for identity-based auth, D fits for limiting user access by date.

0
PB
Peter B.
2026-02-20

B for identity-based auth since it involves Azure AD, and D to restrict access timing.

0