Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Microsoft logo

Microsoft Certified:Azure Security Engineer Associate

Domain 2Objective 2

Plan and Implement Security for Private Access to Azure Resources AZ-500 Practice Questions (Page 4)

Part of the Secure networking domain, which accounts for 20–25% of the AZ-500 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~8–16 in this domain), expect 3–5 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)

34questions here
7free pages
6concepts
20–25%of the exam

Questions 16–20

  1. 16expert · hard

    A SaaS provider has a Private Link service that exposes an application behind a Standard Load Balancer. A customer has created a private endpoint in their VNet and requested a connection. The provider wants to automatically approve all connections from that customer's subscription but reject connections from other subscriptions. What should they configure?

    Select an answer first
  2. 17application · medium

    A software vendor hosts a multi-tenant SaaS application on Azure VMs. They want to allow customers to connect to the application privately from their own virtual networks, without exposing the VMs to the internet. What should the vendor implement?

    Select an answer first
  3. 18expert · hard

    A company has an Azure SQL Managed Instance (MI) in a VNet. They need to allow an on-premises application to connect to the MI through a site-to-site VPN. The on-premises network is connected to the VNet. The MI's subnet NSG currently allows all inbound traffic. What should you configure to ensure the on-premises application can connect?

    Select an answer first
  4. 19foundation · easy

    Which Azure resource must be associated with an Azure Private Link Service to provide the backend for the service?

    Select an answer first
  5. 20expert · hard

    A company has an App Service Environment (ASE) v3 with an internal load balancer (ILB). The ASE is in a spoke VNet that is peered to a hub VNet. The hub VNet has an Azure Firewall. The security team requires that all outbound traffic from the ASE go through the Azure Firewall for inspection. What should you configure?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “AZ-500” is a trademark of its owner, used for identification only.