Microsoft Certified:Azure Security Engineer Associate
Domain 4Objective 1
Implement and Manage Enforcement of Cloud Governance Policies AZ-500 Practice Questions (Page 8)
Part of the Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel domain, which accounts for 30–35% of the AZ-500 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~12–23 in this domain), expect 3–6 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
15concepts
30–35%of the exam
Questions 36–40
- 36
Your company uses Azure RBAC for Key Vault data-plane access. A developer needs to create and manage keys in a Key Vault, but should not be able to delete the Key Vault itself. Which built-in role should you assign?
Select an answer first - 37
You need to grant a security team read-only access to the Azure Key Vault resource itself, but not to the secrets stored inside. Which Azure RBAC role should you assign?
Select an answer first - 38
You need to retrieve the value of a secret from Azure Key Vault in an application. Which operation should you use?
Select an answer first - 39
Your security team requires that encryption keys used for Azure Storage be rotated automatically every 90 days. You have an Azure Key Vault with a key used for customer-managed keys. What should you configure?
Select an answer first - 40
A security admin needs to rotate a customer-managed key used for Azure Storage encryption. The key is stored in Key Vault. The rotation must be automatic, but the admin also needs to ensure that the old key remains available for decrypting data encrypted with it. What should they do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “AZ-500” is a trademark of its owner, used for identification only.