Microsoft AZ-500 Azure Security Engineer
CERTIFICATION PAPER 2026 FULL
SOLUTION GRADED A+
● You have an Azure Subscription named Sub1.You have an Azure
Storage account named Sa1 in a resource group named RG1.
Users and applications access the blob service and the file service in Sa1
by using several shared access signatures (SASs) and stored access
policies.You discover that unauthorized users accessed both the file
service and the blob service.You need to revoke all access to
Sa1.Solution: You create a new stored access policy.Does this meet the
goal? Answer: YES.
To revoke a stored access policy, you can either delete it, or rename it by
changing the signed identifier. Changing the signed identifier breaks the
associations between any existing signatures and the stored access
policy. Deleting or renaming the stored access policy immediately
effects all of the shared access signatures associated with it.
● You have a hybrid configuration of Azure Active Directory (Azure
AD).
You have an Azure HDInsight cluster on a virtual network.You plan to
allow users to authenticate to the cluster by using their on-premises
Active Directory credentials.You need to configure the environment to
support the planned authentication.Solution: You deploy the On-
,premises data gateway to the on-premises network.Does this meet the
goal? Answer: NO
Instead, you connect HDInsight to your on-premises network by using
Azure Virtual Networks and a VPN gateway.
● You have a hybrid configuration of Azure Active Directory (Azure
AD).
You have an Azure HDInsight cluster on a virtual network.You plan to
allow users to authenticate to the cluster by using their on-premises
Active Directory credentials.You need to configure the environment to
support the planned authentication.
Solution: You create a site-to-site VPN between the virtual network and
the on-premises network.Does this meet the goal? Answer: Yes
You can connect HDInsight to your on-premises network by using Azure
Virtual Networks and a VPN gateway.
● You have an Azure subscription named Sub1 that is associated to an
Azure Active Directory (Azure AD) tenant named contoso.com.
You plan to deploy Azure AD Connect and to integrate Active Directory
and the Azure AD tenant.You need to recommend an integration solution
that meets the following requirements:
Ensures that password policies and user logon restrictions apply to user
accounts that are synced to the tenant Minimizes the number of servers
required for the solution.
Which authentication method should you include in the
recommendation?
,A. federated identity with Active Directory Federation Services
B. password hash synchronization with seamless single sign-on
C. pass-through authentication with seamless single sign-on Answer: C.
pass-through authentication with seamless single sign-on
● You have an Azure subscription named Sub1 that is associated to an
Azure Active Directory (Azure AD) tenant named contoso.com.
You sync all on-premises identities to Azure AD. You need to prevent
users who have a givenName attribute that starts with TEST from being
synced to Azure AD. The solution must minimize administrative
effort.What should you use?
A. Synchronization Rules Editor
B. Web Service Configuration Tool
C. the Azure AD Connect wizard
D. Active Directory Users and Computers Answer: A. Synchronization
Rules Editor
● DRAG DROP
You are implementing conditional access policies.You must evaluate the
existing Azure Active Directory (Azure AD) risk events and risk levels
to configure and implement the policies.You need to identify the risk
level of the following risk events:
✑ Users with leaked credentials
✑ Impossible travel to atypical locations
, ✑ Sign-ins from IP addresses with suspicious activity.
Which level should you identify for each risk event? Answer: Med
High
Med
● HOTSPOT -You create and enforce an Azure AD Identity Protection
user risk policy that has the following settings:
✑ Assignment: Include Group1, Exclude Group2
✑ Conditions: Sign-in risk of Medium and above Access:
Allow access, Require password change Answer: yes no no
● DRAG DROP -You need to configure an access review. The review
will be assigned to a new collection of reviews and reviewed by resource
owners.Which three actions should you perform in sequence? To answer,
move the appropriate actions from the list of actions to the answer area
and arrange them in the correct order.
Create an access review program.
Set reviewers to selected users.
Create an access review audit.
Create an access review control.
Set reviewers to group owners.
Set reviewers to members. Answer: Create an access review program.
Create an access review control.
CERTIFICATION PAPER 2026 FULL
SOLUTION GRADED A+
● You have an Azure Subscription named Sub1.You have an Azure
Storage account named Sa1 in a resource group named RG1.
Users and applications access the blob service and the file service in Sa1
by using several shared access signatures (SASs) and stored access
policies.You discover that unauthorized users accessed both the file
service and the blob service.You need to revoke all access to
Sa1.Solution: You create a new stored access policy.Does this meet the
goal? Answer: YES.
To revoke a stored access policy, you can either delete it, or rename it by
changing the signed identifier. Changing the signed identifier breaks the
associations between any existing signatures and the stored access
policy. Deleting or renaming the stored access policy immediately
effects all of the shared access signatures associated with it.
● You have a hybrid configuration of Azure Active Directory (Azure
AD).
You have an Azure HDInsight cluster on a virtual network.You plan to
allow users to authenticate to the cluster by using their on-premises
Active Directory credentials.You need to configure the environment to
support the planned authentication.Solution: You deploy the On-
,premises data gateway to the on-premises network.Does this meet the
goal? Answer: NO
Instead, you connect HDInsight to your on-premises network by using
Azure Virtual Networks and a VPN gateway.
● You have a hybrid configuration of Azure Active Directory (Azure
AD).
You have an Azure HDInsight cluster on a virtual network.You plan to
allow users to authenticate to the cluster by using their on-premises
Active Directory credentials.You need to configure the environment to
support the planned authentication.
Solution: You create a site-to-site VPN between the virtual network and
the on-premises network.Does this meet the goal? Answer: Yes
You can connect HDInsight to your on-premises network by using Azure
Virtual Networks and a VPN gateway.
● You have an Azure subscription named Sub1 that is associated to an
Azure Active Directory (Azure AD) tenant named contoso.com.
You plan to deploy Azure AD Connect and to integrate Active Directory
and the Azure AD tenant.You need to recommend an integration solution
that meets the following requirements:
Ensures that password policies and user logon restrictions apply to user
accounts that are synced to the tenant Minimizes the number of servers
required for the solution.
Which authentication method should you include in the
recommendation?
,A. federated identity with Active Directory Federation Services
B. password hash synchronization with seamless single sign-on
C. pass-through authentication with seamless single sign-on Answer: C.
pass-through authentication with seamless single sign-on
● You have an Azure subscription named Sub1 that is associated to an
Azure Active Directory (Azure AD) tenant named contoso.com.
You sync all on-premises identities to Azure AD. You need to prevent
users who have a givenName attribute that starts with TEST from being
synced to Azure AD. The solution must minimize administrative
effort.What should you use?
A. Synchronization Rules Editor
B. Web Service Configuration Tool
C. the Azure AD Connect wizard
D. Active Directory Users and Computers Answer: A. Synchronization
Rules Editor
● DRAG DROP
You are implementing conditional access policies.You must evaluate the
existing Azure Active Directory (Azure AD) risk events and risk levels
to configure and implement the policies.You need to identify the risk
level of the following risk events:
✑ Users with leaked credentials
✑ Impossible travel to atypical locations
, ✑ Sign-ins from IP addresses with suspicious activity.
Which level should you identify for each risk event? Answer: Med
High
Med
● HOTSPOT -You create and enforce an Azure AD Identity Protection
user risk policy that has the following settings:
✑ Assignment: Include Group1, Exclude Group2
✑ Conditions: Sign-in risk of Medium and above Access:
Allow access, Require password change Answer: yes no no
● DRAG DROP -You need to configure an access review. The review
will be assigned to a new collection of reviews and reviewed by resource
owners.Which three actions should you perform in sequence? To answer,
move the appropriate actions from the list of actions to the answer area
and arrange them in the correct order.
Create an access review program.
Set reviewers to selected users.
Create an access review audit.
Create an access review control.
Set reviewers to group owners.
Set reviewers to members. Answer: Create an access review program.
Create an access review control.