Microsoft AZ-500 Azure Security Engineer
EXAMINATION SET 2026 SOLVED
QUESTIONS GRADED A+
● Your company has an Active Directory forest with a single domain,
named weylandindustries.com. They also have an Azure Active
Directory (Azure AD) tenant with the same name. You have been tasked
with integrating Active Directory and the Azure AD tenant. You intend
to deploy Azure AD Connect. Your strategy for the integration must
make sure that password policies and user logon limitations affect user
accounts that are synced to the Azure AD tenant, and that the amount of
necessary servers are reduced. Solution: You recommend the use of
pass-through authentication and seamless SSO with password hash
synchronization. Does the solution meet the goal? Answer: Yes
● Your company has an Active Directory forest with a single domain,
named weylandindustries.com. They also have an Azure Active
Directory (Azure AD) tenant with the same name. You have been tasked
with integrating Active Directory and the Azure AD tenant. You intend
to deploy Azure AD Connect. Your strategy for the integration must
make sure that password policies and user logon limitations affect user
accounts that are synced to the Azure AD tenant, and that the number of
necessary servers are reduced. Solution: You recommend the use of
federation with Active Directory Federation Services (AD FS).Does the
solution meet the goal? Answer: NO
,● Your company has an Active Directory forest with a single domain,
named weylandindustries.com. They also have an Azure Active
Directory (Azure AD) tenant with the same name. You have been tasked
with integrating Active Directory and the Azure AD tenant. You intend
to deploy Azure AD Connect. Your strategy for the integration must
make sure that password policies and user logon limitations affect user
accounts that are synced to the Azure AD tenant, and that the amount of
necessary servers are reduced. Solution: You recommend the use of
password hash synchronization and seamless SSO .Does the solution
meet the goal? Answer: NO
● Your company has an Active Directory forest with a single domain,
named weylandindustries.com. They also have an Azure Active
Directory (Azure AD) tenant with the same name. After syncing all on-
premises identities to Azure AD, you are informed that users with a
givenName attribute starting with LAB should not be allowed to sync
toAzure AD.Which of the following actions should you take? Answer:
You should make use of the Synchronization Rules Editor to create an
attribute-based filtering rule
● You have been tasked with applying conditional access policies for
your company's current Azure Active Directory (Azure AD).The process
involves assessing the risk events and risk levels. Which of the
following is the risk level that should be configured for users that have
leaked credentials? Answer: high
● You have been tasked with applying conditional access policies for
your company's current Azure Active Directory (Azure AD).The process
, involves assessing the risk events and risk levels.Which of the following
is the risk level that should be configured for sign ins that originate from
IP addresses with dubious activity? Answer: Medium
● You have been tasked with configuring an access review, which you
plan to assigned to a new collection of reviews. You also have to make
sure that the reviews can be reviewed by resource owners. You start by
creating an access review program and an access review control. You
now need to configure the Reviewers. Which of the following should
you set Reviewers to? Answer: Group Owners
● Your company recently created an Azure subscription. You have,
subsequently, been tasked with making sure that you are able to secure
Azure AD roles by making use of Azure Active Directory (Azure AD)
Privileged Identity Management (PIM).Which of the following actions
should you take FIRST? Answer: You should consent to Azure Active
Directory (Azure AD) Privileged Identity Management (PIM).
● You need to consider the underlined segment to establish whether it is
accurate.You have been tasked with creating a different subscription for
each of your company's divisions. However, the subscriptions will be
linked to a single Azure ActiveDirectory (Azure AD) tenant.You want to
make sure that each subscription has identical role assignments.You
make use of Azure AD Privileged Identity Management (PIM).Select
`No adjustment required` if the underlined segment is accurate. If the
underlined segment is inaccurate, select the accurate option. Answer:
Azure Blueprints
EXAMINATION SET 2026 SOLVED
QUESTIONS GRADED A+
● Your company has an Active Directory forest with a single domain,
named weylandindustries.com. They also have an Azure Active
Directory (Azure AD) tenant with the same name. You have been tasked
with integrating Active Directory and the Azure AD tenant. You intend
to deploy Azure AD Connect. Your strategy for the integration must
make sure that password policies and user logon limitations affect user
accounts that are synced to the Azure AD tenant, and that the amount of
necessary servers are reduced. Solution: You recommend the use of
pass-through authentication and seamless SSO with password hash
synchronization. Does the solution meet the goal? Answer: Yes
● Your company has an Active Directory forest with a single domain,
named weylandindustries.com. They also have an Azure Active
Directory (Azure AD) tenant with the same name. You have been tasked
with integrating Active Directory and the Azure AD tenant. You intend
to deploy Azure AD Connect. Your strategy for the integration must
make sure that password policies and user logon limitations affect user
accounts that are synced to the Azure AD tenant, and that the number of
necessary servers are reduced. Solution: You recommend the use of
federation with Active Directory Federation Services (AD FS).Does the
solution meet the goal? Answer: NO
,● Your company has an Active Directory forest with a single domain,
named weylandindustries.com. They also have an Azure Active
Directory (Azure AD) tenant with the same name. You have been tasked
with integrating Active Directory and the Azure AD tenant. You intend
to deploy Azure AD Connect. Your strategy for the integration must
make sure that password policies and user logon limitations affect user
accounts that are synced to the Azure AD tenant, and that the amount of
necessary servers are reduced. Solution: You recommend the use of
password hash synchronization and seamless SSO .Does the solution
meet the goal? Answer: NO
● Your company has an Active Directory forest with a single domain,
named weylandindustries.com. They also have an Azure Active
Directory (Azure AD) tenant with the same name. After syncing all on-
premises identities to Azure AD, you are informed that users with a
givenName attribute starting with LAB should not be allowed to sync
toAzure AD.Which of the following actions should you take? Answer:
You should make use of the Synchronization Rules Editor to create an
attribute-based filtering rule
● You have been tasked with applying conditional access policies for
your company's current Azure Active Directory (Azure AD).The process
involves assessing the risk events and risk levels. Which of the
following is the risk level that should be configured for users that have
leaked credentials? Answer: high
● You have been tasked with applying conditional access policies for
your company's current Azure Active Directory (Azure AD).The process
, involves assessing the risk events and risk levels.Which of the following
is the risk level that should be configured for sign ins that originate from
IP addresses with dubious activity? Answer: Medium
● You have been tasked with configuring an access review, which you
plan to assigned to a new collection of reviews. You also have to make
sure that the reviews can be reviewed by resource owners. You start by
creating an access review program and an access review control. You
now need to configure the Reviewers. Which of the following should
you set Reviewers to? Answer: Group Owners
● Your company recently created an Azure subscription. You have,
subsequently, been tasked with making sure that you are able to secure
Azure AD roles by making use of Azure Active Directory (Azure AD)
Privileged Identity Management (PIM).Which of the following actions
should you take FIRST? Answer: You should consent to Azure Active
Directory (Azure AD) Privileged Identity Management (PIM).
● You need to consider the underlined segment to establish whether it is
accurate.You have been tasked with creating a different subscription for
each of your company's divisions. However, the subscriptions will be
linked to a single Azure ActiveDirectory (Azure AD) tenant.You want to
make sure that each subscription has identical role assignments.You
make use of Azure AD Privileged Identity Management (PIM).Select
`No adjustment required` if the underlined segment is accurate. If the
underlined segment is inaccurate, select the accurate option. Answer:
Azure Blueprints