Microsoft Azure Security Engineer Associate AZ-500 — Study Guide
Practice as you learn. Every concept maps to real exam questions with verified answers in the Microsoft exam hub, or drill the full exam with timed practice on ExamRoll.io.
This guide covers each AZ-500 domain in depth. Pick a domain to go deep, or work through them in order.
The domains
- Identity and Access Management — Identity and Access Management (IAM) in Microsoft Azure is centered on Microsoft Entra ID (formerly Azure AD). It governs who can access which
- Network Security Architecture — Azure network security architecture enforces least-privilege connectivity, assumes breach, and instruments continuous monitoring. It combines
- Compute, Container and Endpoint Security — This section provides an operational reference for securing Azure compute, containers, and endpoints across IaaS and PaaS. It focuses on how to
- Data, Storage and Database Security — Azure data, storage, and database security centers on minimizing trust, isolating data planes, encrypting everywhere, and operationalizing least
- Key Management, Cryptography and Certificates — Key management on Azure centers on Azure Key Vault and Azure Managed HSM. These services provide secure storage of cryptographic material, consistent
- Security Posture Management and Governance — Security posture management and governance in Azure is the discipline of continuously assessing, prioritizing, and enforcing configurations that
- Microsoft Sentinel and Security Operations — Microsoft Sentinel is Azure’s cloud-native SIEM and SOAR platform built on Azure Monitor Log Analytics. It centralizes security telemetry, applies
- Application Security and DevSecOps — Application Security and DevSecOps in Azure focus on preventing identity misuse, protecting ingress and APIs, shifting security left in pipelines,
- Hybrid and Multi-Cloud Security — Hybrid and multi-cloud security in Azure centers on establishing a unified control plane that extends Azure-native governance, monitoring, and
- Incident Response, Recovery and Resilience — Incident response, recovery, and resilience in Azure are a continuous capability that blends well-rehearsed operational procedures with
Ready to practice?
- Browse every question with verified answers → — free, with explanations.
- Start timed practice tests on ExamRoll.io → — the full question bank, in 20+ languages.
Pass the whole exam — not just this question
You found this answer. Get every verified question and explanation in one place, and save hours of prep. Free to start.
Pass your exam →