Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Microsoft logo

Microsoft Certified:Azure Security Engineer Associate

Domain 3Objective 1

Plan and Implement Advanced Security for Compute AZ-500 Practice Questions (Page 7)

Part of the Secure compute, storage, and databases domain, which accounts for 20–25% of the AZ-500 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~8–16 in this domain), expect 3–5 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)

39questions here
8free pages
10concepts
20–25%of the exam

Questions 31–35

  1. 31application · medium

    Your company uses Azure Container Registry (ACR) to store images for multiple AKS clusters. You need to ensure that each AKS cluster can pull images only from its own repository within the registry, and that no other Azure service can access the registry. What should you do?

    Select an answer first
  2. 32expert · medium

    Your organization has a production AKS cluster that pulls images from an Azure Container Registry (ACR). The security team wants to ensure that only the AKS cluster can pull images from the ACR, and that the ACR is not accessible from the internet. They also want to detect if any malicious images are pulled. Which solution should you implement?

    Select an answer first
  3. 33foundation · easy

    Which Azure feature encrypts data at rest at the host level, providing encryption for temporary disks and OS/data disks without requiring application changes?

    Select an answer first
  4. 34application · medium

    Your security team wants to reduce the attack surface of a set of domain-joined Windows VMs that are currently accessible via RDP from the internet. They want to allow RDP only when an administrator requests access, and only for a limited time. You need to implement a solution that requires minimal ongoing administrative effort. What should you do?

    Select an answer first
  5. 35application · medium

    Your organization runs a production AKS cluster and wants to detect suspicious activity, such as attempts to run privileged containers or access the Kubernetes API server from unexpected IPs. You need to enable threat detection for the cluster. What should you do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “AZ-500” is a trademark of its owner, used for identification only.