Microsoft Certified:Azure Security Engineer Associate
Domain 3Objective 1
Plan and Implement Advanced Security for Compute AZ-500 Practice Questions (Page 4)
Part of the Secure compute, storage, and databases domain, which accounts for 20–25% of the AZ-500 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~8–16 in this domain), expect 3–5 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
10concepts
20–25%of the exam
Questions 16–20
- 16
What is the primary purpose of deploying Azure Bastion in a virtual network?
Select an answer first - 17
An organization wants to provide secure RDP and SSH access to Azure VMs without assigning public IP addresses to the VMs. Which Azure service should be deployed to meet this requirement?
Select an answer first - 18
In Azure Kubernetes Service (AKS), which resource is used to define rules that control traffic between pods?
Select an answer first - 19
Your company exposes a public API through Azure API Management (APIM). You need to protect the API from DDoS attacks and from unauthorized access. You also want to restrict access to the APIM endpoint to only the company's partner organizations. What should you do?
Select an answer first - 20
A company has a VM that stores sensitive customer data on its OS and data disks. The compliance team requires that all data at rest be encrypted, and they want to avoid any dependency on Azure Key Vault for key management. The VM is accessed only via Azure Bastion. What should you implement to encrypt the disks?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “AZ-500” is a trademark of its owner, used for identification only.