Tag: Microsoft Certified: Cloud and AI Security Engineer Associate

Configure database auditing for Azure SQL Database and Azure SQL Managed Instance (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Secure storage, databases, and networking (25–30%)
   --> Implement security for databases
      --> Configure database auditing for Azure SQL Database and Azure SQL Managed Instance


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Overview

Database auditing records database activity so that organizations can investigate security incidents, identify unauthorized access, support compliance requirements, and understand how data is being used.

For the SC-500 exam, database auditing primarily involves configuring and managing auditing for:

  • Azure SQL Database
  • Azure SQL Managed Instance
  • SQL databases hosted in Azure
  • Microsoft Entra authentication and database activity
  • Audit destinations and retention
  • Audit logs and monitoring

Auditing is different from authentication and authorization:

  • Authentication determines who or what is connecting.
  • Authorization determines what the principal is allowed to do.
  • Auditing records what happened, who performed the action, when it occurred, and other relevant details.

A user might be correctly authenticated and authorized to read a table, but auditing can record that the user actually performed the read operation.


Why Database Auditing Is Important

Database auditing supports several security and governance objectives.

Detecting suspicious activity

Audit records can help identify:

  • Repeated failed login attempts
  • Access to sensitive tables
  • Unexpected changes to database objects
  • Changes to permissions or roles
  • Unusual administrative activity
  • Attempts to access data outside normal business patterns

Supporting compliance

Many regulatory and organizational standards require organizations to maintain evidence of access to sensitive data. Audit logs can help demonstrate:

  • Who accessed data
  • Which operations were performed
  • When the operations occurred
  • Whether privileged users changed security settings
  • Whether sensitive data was accessed or modified

Investigating security incidents

When an incident occurs, audit logs can help security teams reconstruct events and determine:

  • Which account was used
  • Which database was accessed
  • Which commands were executed
  • Whether data was read, changed, or deleted
  • Whether permissions were modified
  • The approximate time sequence of activity

Establishing accountability

Auditing helps associate database activity with a user, application, service principal, or managed identity. This is especially important when multiple applications or administrators access the same database.


Azure SQL Auditing

Azure SQL auditing tracks database events and writes audit records to a configured destination.

Auditing can be configured at different scopes, depending on the service:

  • Azure SQL logical server
  • Individual Azure SQL Database
  • Azure SQL Managed Instance
  • SQL databases hosted by the managed instance

The exact configuration experience and available settings can vary between Azure SQL Database and Azure SQL Managed Instance.

For Azure SQL Database, auditing can generally be configured at the server or database level. A database-level configuration can provide more specific control for an individual database.

For Azure SQL Managed Instance, auditing is configured for the managed instance and can capture activity across the databases hosted by that instance.


Azure SQL Database Auditing

Azure SQL Database auditing records database events for databases hosted on an Azure SQL logical server.

Auditing can be enabled through the Azure portal, Azure PowerShell, Azure CLI, REST APIs, or infrastructure-as-code tools.

At a high level, configuring auditing involves:

  1. Selecting the SQL server or database.
  2. Opening the auditing configuration.
  3. Enabling auditing.
  4. Selecting an audit destination.
  5. Configuring retention and related settings.
  6. Saving the configuration.
  7. Reviewing the generated audit records.

Auditing can be configured at the server level so that databases inherit the server’s auditing configuration. A database-level configuration can be used when a particular database requires different auditing behavior.


Azure SQL Managed Instance Auditing

Azure SQL Managed Instance provides auditing for database activity across the managed instance.

Because a managed instance can host multiple databases, auditing at the managed-instance level is useful when an organization wants consistent auditing across its database environment.

Auditing can help record activity such as:

  • Database connections
  • Queries and stored procedure execution
  • Data access
  • Data changes
  • Permission changes
  • Schema changes
  • Security-related operations

The audit configuration should be reviewed carefully to ensure that the selected events meet the organization’s security and compliance requirements without generating unnecessary volumes of data.


Audit Destinations

Azure SQL auditing supports several destinations. The appropriate destination depends on the organization’s retention, analysis, and monitoring requirements.

Azure Storage

Audit logs can be written to an Azure Storage account.

Azure Storage is useful when an organization needs:

  • Long-term retention
  • Centralized storage
  • Low-cost archival
  • Integration with other data-processing tools
  • Storage-based compliance evidence

When using Azure Storage, consider:

  • Storage account security
  • Access control
  • Network restrictions
  • Encryption
  • Retention policies
  • Immutability requirements
  • Lifecycle management

Audit logs should not be stored in a location where unauthorized users can modify or delete them.

For stronger protection, organizations can use storage security features such as restricted access, role-based access control, and immutable storage where appropriate.


Log Analytics Workspace

Audit logs can be sent to a Log Analytics workspace.

This destination is useful when security teams need to:

  • Query audit records
  • Correlate database events with other Azure activity
  • Build dashboards
  • Create alerts
  • Investigate incidents
  • Use Microsoft Sentinel for security monitoring

Log Analytics is often the most useful destination for operational security monitoring because audit data can be queried using Kusto Query Language.

For example, security teams might use audit data to investigate:

  • Access to sensitive databases
  • Changes to database permissions
  • Unusual administrative activity
  • Repeated failed connections
  • Unexpected data modification

Event Hubs

Audit logs can also be sent to Azure Event Hubs.

Event Hubs is useful when audit data must be streamed to another system, such as:

  • A security information and event management platform
  • A security analytics platform
  • A custom monitoring application
  • A third-party compliance or monitoring solution

Event Hubs is designed for high-throughput event ingestion and streaming rather than long-term log storage by itself.


Choosing a Destination

RequirementSuitable destination
Long-term archivalAzure Storage
Interactive investigation and queriesLog Analytics workspace
Streaming audit data to another systemEvent Hubs
Security analytics and alertingLog Analytics and Microsoft Sentinel
Compliance retentionAzure Storage, often with additional retention controls

An organization may use more than one destination when it needs both operational monitoring and long-term retention.


Types of Activity That Can Be Audited

The exact audit events available depend on the Azure SQL service and configuration, but auditing can capture several important categories of activity.

Authentication and connection activity

Examples include:

  • Successful database connections
  • Failed connection attempts
  • Authentication-related events
  • Connection information

These events can help identify brute-force attempts, misconfigured applications, or unexpected access.

Data access

Examples include:

  • Reading data
  • Selecting data from sensitive tables
  • Executing stored procedures
  • Accessing specific database objects

Data-access auditing is particularly important for databases containing:

  • Personally identifiable information
  • Financial information
  • Healthcare information
  • Customer records
  • Confidential business data

Data changes

Examples include:

  • Insert operations
  • Update operations
  • Delete operations
  • Bulk data changes

Auditing data changes can help determine whether records were modified or removed.

Schema changes

Examples include:

  • Creating tables
  • Altering tables
  • Dropping tables
  • Creating or modifying stored procedures
  • Changing database objects

Schema auditing is useful because unauthorized schema changes can create security vulnerabilities or affect application behavior.

Permission and role changes

Examples include:

  • Granting permissions
  • Revoking permissions
  • Adding users to database roles
  • Removing users from database roles
  • Changing ownership or security-related settings

These events are important for detecting privilege escalation.

Administrative activity

Examples include:

  • Changes to auditing configuration
  • Changes to database settings
  • Changes to security configuration
  • Administrative commands

Administrative auditing helps establish accountability for privileged operations.


Auditing Versus Microsoft Defender for SQL

Azure SQL auditing and Microsoft Defender for SQL serve related but different purposes.

Azure SQL auditing

Auditing primarily records database activity for:

  • Investigation
  • Compliance
  • Accountability
  • Historical analysis
  • Security monitoring

It answers questions such as:

What activity occurred in the database?

Microsoft Defender for SQL

Microsoft Defender for SQL provides additional security capabilities, such as:

  • Threat detection
  • Security alerts
  • Vulnerability assessment
  • Security recommendations
  • Identification of suspicious database activity

It answers questions such as:

Does this activity appear suspicious or represent a security risk?

Auditing and Defender for SQL can be used together. Auditing provides detailed activity records, while Defender for SQL can identify and alert on potentially malicious behavior.


Auditing and Microsoft Sentinel

Audit logs can be integrated with Microsoft Sentinel to support centralized security monitoring.

A typical workflow is:

  1. Enable auditing on Azure SQL Database or Azure SQL Managed Instance.
  2. Send audit logs to a Log Analytics workspace.
  3. Connect the workspace to Microsoft Sentinel.
  4. Create queries and analytics rules.
  5. Configure alerts and incidents.
  6. Investigate related activity across Azure and other environments.

For example, Microsoft Sentinel could correlate:

  • A suspicious Microsoft Entra sign-in
  • A database permission change
  • Access to a sensitive table
  • Activity from an unusual IP address
  • A subsequent data export

This correlation provides more context than reviewing database logs alone.


Retention and Log Management

Audit logs should be retained according to:

  • Regulatory requirements
  • Organizational policies
  • Incident-response requirements
  • Legal and contractual obligations
  • Storage costs
  • Data sensitivity

Retention should be long enough to support investigations and compliance audits.

Important considerations include:

  • How long logs are retained
  • Whether logs can be deleted by ordinary administrators
  • Whether logs are protected from modification
  • Whether access to logs is itself audited
  • Whether archived logs can be searched or restored
  • Whether retention policies apply consistently across databases

Audit logs may contain sensitive information, so they should be protected using appropriate access controls and encryption.


Securing Audit Logs

Audit logs are security evidence and should be protected as carefully as the database itself.

Restrict access

Only authorized personnel should be able to read, export, or delete audit logs.

Use least-privilege access through Microsoft Entra ID and Azure RBAC where supported.

Protect against deletion or modification

Consider:

  • Storage immutability
  • Resource locks where appropriate
  • Restricted administrative access
  • Separate security or compliance ownership
  • Monitoring of changes to audit configuration

A log that can be easily deleted by the person being investigated provides limited forensic value.

Encrypt audit data

Audit data should be protected using encryption at rest and secure transport.

Azure services generally provide encryption at rest, but organizations must still configure access and key-management controls appropriately.

Monitor auditing configuration

Security teams should monitor changes to:

  • Whether auditing is enabled
  • Audit destinations
  • Retention settings
  • Audit policies
  • Database-level overrides
  • Permissions to audit destinations

An attacker who disables auditing may be attempting to conceal activity.


Configuring Auditing in the Azure Portal

The following is a conceptual configuration process. The exact portal labels may vary as Azure services evolve.

Azure SQL Database

  1. Open the Azure portal.
  2. Navigate to the Azure SQL logical server or database.
  3. Select Auditing under the security-related settings.
  4. Enable auditing.
  5. Choose one or more supported destinations.
  6. Configure the destination details.
  7. Configure retention or related settings.
  8. Save the configuration.
  9. Generate or perform test activity.
  10. Verify that audit records are being delivered.

When configuring auditing at the server level, review whether individual databases inherit the configuration or override it.

Azure SQL Managed Instance

  1. Open the Azure portal.
  2. Navigate to the managed instance.
  3. Select the auditing configuration.
  4. Enable auditing.
  5. Select the destination.
  6. Configure retention and related settings.
  7. Save the configuration.
  8. Verify that activity from the managed instance’s databases is being recorded.

Common Exam Considerations

Server-level versus database-level configuration

A server-level auditing configuration can provide centralized coverage, while a database-level configuration can provide more specific control.

When troubleshooting, determine whether:

  • Auditing is enabled at the server level
  • The database has its own auditing configuration
  • A database-level setting overrides the inherited configuration
  • The selected destination is correctly configured

Auditing does not grant access

Enabling auditing does not allow a user to connect to a database or read data.

Authentication and authorization must still be configured separately.

Auditing does not block activity

Auditing records activity. It does not, by itself, prevent a user from executing a query or changing data.

To prevent activity, use controls such as:

  • Microsoft Entra authentication
  • Azure RBAC
  • Database roles and permissions
  • Network access controls
  • Microsoft Defender for SQL
  • Azure Policy
  • Microsoft Purview or other data-governance controls

Auditing is not the same as diagnostic logging

Diagnostic settings are used to route platform logs and metrics to destinations such as Log Analytics, Storage, or Event Hubs.

Azure SQL auditing is a database-specific auditing capability. Diagnostic settings may be involved in routing or collecting related logs, but they do not replace the need to configure database auditing appropriately.

Do not collect more data than necessary

Auditing should be designed to meet security and compliance objectives while controlling:

  • Storage costs
  • Query volume
  • Log noise
  • Sensitive information exposure
  • Operational overhead

A useful audit policy focuses on meaningful events and protects the resulting records.


Best Practices

  1. Enable auditing for production databases.
  2. Use Log Analytics when interactive investigation and alerting are required.
  3. Use Azure Storage for long-term retention and archival.
  4. Send relevant audit data to Microsoft Sentinel for centralized security monitoring.
  5. Protect audit destinations with least-privilege access.
  6. Use retention policies that meet regulatory and organizational requirements.
  7. Protect logs against unauthorized deletion or modification.
  8. Monitor changes to auditing configuration.
  9. Review audit records regularly.
  10. Correlate audit activity with identity, network, and application logs.
  11. Use Microsoft Defender for SQL for threat detection in addition to auditing.
  12. Test auditing after configuration changes.
  13. Document which events are audited and why.
  14. Avoid relying on auditing as a substitute for authorization.
  15. Ensure that audit logs themselves are treated as sensitive data.

Practice Exam Questions

Question 1

An organization needs to record activity performed against an Azure SQL Database so that security analysts can investigate suspicious queries and create alerts. Which destination is the most appropriate?

A. Azure Key Vault
B. Azure Storage only
C. Log Analytics workspace
D. Azure Resource Graph

Correct answer: C

Explanation: A Log Analytics workspace is designed for querying and analyzing log data. It can also be used with Microsoft Sentinel to create alerts and investigate security incidents. Azure Storage is better suited to archival and long-term retention.


Question 2

A company must retain Azure SQL audit records for several years at a relatively low cost. The records must also be protected from unauthorized modification. Which approach is most appropriate?

A. Store the records only in the SQL database being audited
B. Send the records to Azure Storage and configure appropriate retention and immutability controls
C. Send the records only to Azure Event Hubs without any downstream storage
D. Disable auditing after exporting the records once per year

Correct answer: B

Explanation: Azure Storage is appropriate for long-term retention. Additional controls, such as retention policies and immutable storage, can help protect audit records from deletion or modification.


Question 3

Which statement best describes the purpose of Azure SQL auditing?

A. It records database activity for investigation, accountability, and compliance
B. It automatically grants users permission to access database objects
C. It replaces Microsoft Entra authentication
D. It prevents all unauthorized queries from executing

Correct answer: A

Explanation: Auditing records activity that occurs in the database. It does not grant permissions, replace authentication, or automatically block queries.


Question 4

An administrator enables auditing for an Azure SQL Database but users still cannot connect to the database. What is the most likely explanation?

A. Auditing can only be enabled after all users are assigned the Owner role
B. Auditing automatically blocks connections until Microsoft Sentinel is configured
C. Auditing records activity but does not provide authentication or authorization
D. Auditing requires Azure Storage to be configured before any user can connect

Correct answer: C

Explanation: Authentication and authorization are separate from auditing. A user must still have a valid authentication method and sufficient database permissions.


Question 5

A security team wants to correlate Azure SQL activity with Microsoft Entra sign-ins, virtual machine alerts, and other cloud security events. Which solution is most appropriate?

A. Azure Files
B. Microsoft Sentinel connected to a Log Analytics workspace
C. Azure DNS
D. Azure Resource Manager locks only

Correct answer: B

Explanation: Microsoft Sentinel can use Log Analytics data to correlate database audit events with identity, infrastructure, and other security events.


Question 6

An organization wants to investigate whether a privileged administrator changed database permissions. Which type of audit activity is most relevant?

A. Permission and role changes
B. Storage account replication events
C. Virtual network route changes only
D. Azure billing events only

Correct answer: A

Explanation: Permission and role changes can reveal privilege escalation or unauthorized changes to database access.


Question 7

A company configures auditing at the Azure SQL logical server level. One database has different auditing requirements and must use a separate configuration. What should the administrator investigate?

A. Whether the database can override or use a database-level auditing configuration
B. Whether auditing can only be configured at the subscription level
C. Whether the database must be moved to Azure Cosmos DB
D. Whether auditing requires a dedicated virtual machine

Correct answer: A

Explanation: Azure SQL Database auditing can be configured at the server or database level. The administrator should determine whether the database-level configuration provides the required override or separate behavior.


Question 8

Which statement correctly compares Azure SQL auditing and Microsoft Defender for SQL?

A. Auditing blocks threats, while Defender for SQL only stores logs
B. Auditing and Defender for SQL are identical features
C. Auditing records database activity, while Defender for SQL provides additional threat detection and security recommendations
D. Defender for SQL is required before auditing can be enabled

Correct answer: C

Explanation: Auditing provides activity records for investigation and compliance. Microsoft Defender for SQL adds security capabilities such as threat detection, alerts, and vulnerability-related recommendations.


Question 9

An organization sends Azure SQL audit records to Event Hubs. What is the primary reason for selecting Event Hubs?

A. To stream audit events to another monitoring or security system
B. To replace database authentication
C. To provide database table-level permissions
D. To encrypt database columns automatically

Correct answer: A

Explanation: Event Hubs is designed for high-throughput event ingestion and streaming. It can forward audit events to downstream monitoring or security systems.


Question 10

A security team notices that audit records are missing after an administrator changed the auditing configuration. Which action should be performed first?

A. Delete the database and recreate it
B. Disable Microsoft Entra authentication
C. Confirm that auditing is still enabled and verify the configured destination and delivery settings
D. Assign the Security Reader role to every database user

Correct answer: C

Explanation: The first troubleshooting step is to verify the auditing configuration, including whether auditing remains enabled and whether the destination is correctly configured. The team should also verify that the destination is receiving records and that no configuration change disabled or redirected auditing.


Final Exam Point

The key exam distinction is that auditing records database activity, while authentication, authorization, network controls, and threat-detection services determine whether activity should be allowed or considered suspicious.


Go to the SC-500 Exam Prep Hub main page

Implement and manage network security groups (NSGs) and application security groups (ASGs) (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Secure storage, databases, and networking (25–30%)
   --> Implement security for Azure network services
      --> Implement and manage network security groups (NSGs) and application security groups (ASGs)


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Overview

Network security groups (NSGs) and application security groups (ASGs) are foundational Azure networking features used to control traffic within and between Azure virtual networks.

  • Network security groups provide traffic filtering through inbound and outbound security rules.
  • Application security groups allow administrators to organize virtual machines and network interfaces according to application roles rather than relying on individual IP addresses.

Together, NSGs and ASGs support defense in depth, network segmentation, least-privilege access, and easier security-rule management.

An NSG can be associated with:

  • A subnet
  • A network interface card (NIC)
  • Both a subnet and a NIC

When an NSG is associated with a subnet, its rules apply to the resources in that subnet. When it is associated with a NIC, its rules apply to the traffic for that network interface.


1. Understand Network Security Groups

A network security group is an Azure resource containing security rules that allow or deny network traffic.

Each rule can evaluate traffic based on:

  • Source
  • Source port
  • Destination
  • Destination port
  • Protocol
  • Direction
  • Priority
  • Action

Supported protocols include:

  • TCP
  • UDP
  • Any

The action is either:

  • Allow
  • Deny

For example, an NSG rule could allow HTTPS traffic from the Internet to a web server while denying direct inbound access to the database tier.

Example security rule

PropertyExample
NameAllow-HTTPS
DirectionInbound
Priority100
SourceInternet
Source port*
DestinationWeb server subnet
Destination port443
ProtocolTCP
ActionAllow

A lower priority number has higher precedence. For example, priority 100 is evaluated before priority 200.


2. NSG Default Rules

Every NSG contains default security rules. These rules cannot be deleted, but custom rules can override them by using a higher priority.

Common default inbound rules include:

  • Allow traffic from the VirtualNetwork service tag
  • Allow traffic from the AzureLoadBalancer service tag
  • Deny all other inbound traffic

Common default outbound rules include:

  • Allow traffic to the VirtualNetwork service tag
  • Allow traffic to the Internet
  • Deny all other outbound traffic

The default rules are evaluated after custom rules. Therefore, a custom rule with a priority lower than the default deny rule can allow traffic that would otherwise be denied.

Important exam point

NSGs are not automatically “deny all” in every direction. They include default rules that permit certain virtual-network and outbound Internet traffic. Security administrators should explicitly review and override these defaults when stricter controls are required.


3. Inbound and Outbound Rule Evaluation

NSGs filter both inbound and outbound traffic.

Inbound traffic

For a virtual machine with NSGs at both the subnet and NIC levels:

  1. Azure evaluates the subnet-level NSG.
  2. Azure evaluates the NIC-level NSG.
  3. Traffic must be allowed by both NSGs.

Outbound traffic

For outbound traffic:

  1. Azure evaluates the NIC-level NSG.
  2. Azure evaluates the subnet-level NSG.
  3. Traffic must be allowed by both NSGs.

The effective result is the combined set of applicable rules. A deny rule in either NSG can prevent traffic from flowing.

Example

Suppose:

  • The subnet NSG allows inbound TCP 443.
  • The NIC NSG denies inbound TCP 443.

The traffic is denied because both NSGs must permit the traffic.

Similarly:

  • The subnet NSG allows outbound TCP 1433.
  • The NIC NSG denies outbound TCP 1433.

The connection is denied.


4. NSG Rule Priority

Each custom NSG rule must have a unique priority number.

  • Lower numbers have higher priority.
  • Rules are evaluated in priority order.
  • Evaluation stops when a matching rule is found.
  • A later rule cannot override an earlier matching rule.

Example

PriorityRuleAction
100Allow TCP 443 from InternetAllow
110Deny all inbound trafficDeny

HTTPS traffic is allowed because the priority 100 rule is evaluated first.

If the rules were reversed:

PriorityRuleAction
100Deny all inbound trafficDeny
110Allow TCP 443 from InternetAllow

The HTTPS allow rule would never be reached for matching traffic.

Best practices

  • Reserve priority ranges for different application tiers.
  • Use descriptive rule names.
  • Avoid overlapping rules.
  • Place specific rules before broad rules.
  • Avoid using unnecessarily permissive rules such as Any for both source and destination.
  • Document why each rule exists.

5. Source and Destination Options

NSG rules can use several types of source and destination values.

Any

Matches all addresses.

Use this only when broad access is intentionally required.

IP addresses or CIDR ranges

You can specify:

  • A single IP address
  • Multiple IP addresses
  • A subnet range
  • Multiple CIDR ranges

Example:

10.10.1.0/24

Service tags

A service tag represents a group of IP address prefixes associated with an Azure service or category of traffic.

Examples include:

  • VirtualNetwork
  • Internet
  • AzureLoadBalancer
  • AzureCloud
  • Storage
  • AzureKeyVault

Microsoft maintains the IP prefixes represented by service tags and updates them as Azure addresses change. This avoids manually maintaining large lists of IP addresses.

Application security groups

An ASG can be used as the source or destination of an NSG rule. This allows rules to be based on application roles instead of IP addresses.

For example:

Source ASG: Asg-Web
Destination ASG: Asg-Database
Destination port: 1433
Protocol: TCP
Action: Allow

This rule allows members of the web application group to communicate with members of the database group over TCP port 1433.


6. Network Security Group Association

An NSG can be associated with a subnet, a NIC, or both.

Subnet-level association

A subnet-level NSG is useful when a common policy should apply to all resources in the subnet.

Examples:

  • Deny inbound Internet traffic to a private application subnet.
  • Allow communication from a shared management subnet.
  • Restrict outbound traffic from a database subnet.

NIC-level association

A NIC-level NSG is useful when a particular virtual machine requires additional controls beyond the subnet policy.

Examples:

  • A management server requires SSH access.
  • A specific application server needs an additional inbound port.
  • A sensitive VM requires stricter outbound restrictions.

Recommended design

Use subnet-level NSGs for broad segmentation and NIC-level NSGs for workload-specific restrictions. Avoid creating unnecessarily complicated combinations that are difficult to troubleshoot.


7. Understand Application Security Groups

An application security group is a logical grouping of network interfaces.

ASGs allow administrators to define security rules according to application architecture, such as:

  • Web servers
  • Application servers
  • Database servers
  • Management servers
  • Monitoring servers

Instead of creating rules based on individual IP addresses, you can create rules based on group membership.

Example application groups

Asg-Web
Asg-App
Asg-Database
Asg-Management

A rule could allow:

Asg-Web → Asg-App → TCP 8080
Asg-App → Asg-Database → TCP 1433
Asg-Management → Asg-Web → TCP 22

This design is easier to maintain when virtual machines are added, removed, or assigned new IP addresses.

ASGs are logical groupings; they do not themselves filter traffic. The filtering is performed by NSG rules that reference the ASGs.


8. ASG Constraints

Important ASG constraints include:

  • An ASG contains network interfaces, not entire virtual machines directly.
  • All NICs in an ASG must be in the same virtual network.
  • An ASG cannot contain NICs from different virtual networks.
  • If an NSG rule uses an ASG as both source and destination, the referenced ASGs must contain NICs in the same virtual network.
  • A NIC can belong to multiple ASGs.
  • An ASG does not automatically grant access; a matching NSG rule is still required.

The location and virtual-network requirements should be considered when designing application groups.


9. ASGs and Dynamic Application Membership

ASGs are especially useful when application membership changes frequently.

For example, an organization may have:

  • Three web servers today
  • Six web servers next month
  • Different private IP addresses after redeployment

If the web server NICs are members of Asg-Web, the NSG rule can remain unchanged as servers are added or removed.

The administrator only needs to update ASG membership.

Benefits

  • Reduces dependence on hard-coded IP addresses
  • Simplifies rule maintenance
  • Supports application-centric segmentation
  • Makes security intent easier to understand
  • Reduces the number of rules required
  • Helps maintain consistent policies during scaling

Microsoft recommends using ASGs and service tags where appropriate to reduce rule complexity.


10. Example Three-Tier Application Design

Consider a three-tier application:

Internet
|
v
Web tier
|
v
Application tier
|
v
Database tier

Create the following ASGs:

  • Asg-Web
  • Asg-App
  • Asg-Database

Then configure NSG rules such as:

PrioritySourceDestinationPortAction
100InternetAsg-Web443Allow
110Asg-WebAsg-App8080Allow
120Asg-AppAsg-Database1433Allow
130Asg-ManagementAsg-Web22Allow
4000AnyAnyAnyDeny

This approach prevents direct Internet access to the application and database tiers.

The database tier does not need to allow traffic from the entire virtual network. It only needs to allow traffic from the application tier on the required port.


11. Service Tags Versus ASGs

Service tags and ASGs solve different problems.

FeatureService tagsApplication security groups
RepresentsAzure service IP ranges or traffic categoriesApplication network interfaces
ExampleStorage, Internet, AzureLoadBalancerAsg-Web, Asg-Database
Main purposeSimplify access to Azure servicesSimplify application segmentation
Managed byMicrosoft-managed IP prefix updatesCustomer-managed membership
Common useAllow traffic from Azure StorageAllow web servers to access database servers

Use service tags when the source or destination is an Azure service or well-defined traffic category. Use ASGs when the source or destination is a group of application workloads.


12. Augmented Security Rules

Augmented security rules allow multiple values to be specified in a single rule.

For example, one rule can contain:

  • Multiple source IP addresses
  • Multiple destination IP addresses
  • Multiple ports
  • Port ranges

This can reduce the number of individual rules required.

Example:

Source ports: *
Destination ports: 80, 443, 8080
Protocol: TCP
Action: Allow

Augmented rules should be used carefully. Combining unrelated access requirements into one rule can make the security policy harder to understand. Where possible, use service tags and ASGs to express the security intent more clearly.


13. Managing NSGs and ASGs

NSGs and ASGs can be managed through:

  • Azure portal
  • Azure PowerShell
  • Azure CLI
  • Azure Resource Manager templates
  • Bicep
  • Terraform

Typical management tasks include:

  1. Create an NSG.
  2. Create an ASG.
  3. Associate the NSG with a subnet or NIC.
  4. Add NICs to the ASG.
  5. Create inbound and outbound rules.
  6. Test connectivity.
  7. Review effective security rules.
  8. Update or remove obsolete rules.

Azure CLI examples

Create an NSG:

az network nsg create \
--resource-group NetworkRG \
--name nsg-web

Create an ASG:

az network asg create \
--resource-group NetworkRG \
--name asg-web \
--location eastus

Create an inbound rule allowing HTTPS to the web ASG:

az network nsg rule create \
--resource-group NetworkRG \
--nsg-name nsg-web \
--name Allow-HTTPS \
--access Allow \
--protocol Tcp \
--direction Inbound \
--priority 100 \
--source-address-prefix Internet \
--source-port-range "*" \
--destination-asgs asg-web \
--destination-port-range 443

The exact command syntax can vary depending on whether the rule references IP addresses, service tags, or ASGs.


14. Troubleshooting NSG Connectivity

When traffic is unexpectedly blocked, review the following:

1. Confirm the destination port

Ensure the application is actually listening on the expected port.

2. Confirm the source address

The source may be:

  • A private IP address
  • A public IP address
  • A load balancer
  • A service tag
  • Another application group

A rule that allows the wrong source range will not match.

3. Check both NSGs

Review:

  • The subnet-level NSG
  • The NIC-level NSG

A deny rule in either NSG can block traffic.

4. Review effective security rules

Effective security rules show the aggregated rules applied to a NIC, including rules from both the subnet and NIC NSGs.

In the Azure portal, effective rules can be viewed from the VM’s networking settings. They can also be retrieved with Azure CLI:

az network nic list-effective-nsg \
--name vm-nic \
--resource-group NetworkRG

This is one of the most important troubleshooting tools for NSG-related connectivity problems.

5. Check rule priority

A broad deny rule with a higher priority can prevent a later allow rule from being evaluated.

6. Check ASG membership

If an NSG rule references an ASG, verify that the destination or source NIC is actually a member of that ASG.

7. Check other networking controls

NSGs are not the only possible cause of blocked traffic. Also consider:

  • Azure Firewall
  • Network virtual appliances
  • Route tables
  • Private endpoints
  • Application Gateway
  • Operating-system firewalls
  • Application configuration
  • Network Watcher connection troubleshooting

15. NSGs Are Not a Replacement for Azure Firewall

NSGs provide basic network traffic filtering at the subnet and NIC levels. They are not a full network firewall solution.

NSGs generally do not provide the same capabilities as Azure Firewall, such as:

  • Centralized stateful inspection
  • Advanced threat intelligence filtering
  • Intrusion detection and prevention
  • Centralized application and network rule processing
  • Advanced logging and security operations integration

A common defense-in-depth architecture uses:

  • NSGs for subnet and workload segmentation
  • Azure Firewall for centralized traffic inspection
  • Application Gateway WAF for web application protection
  • Private Link for private access to PaaS services
  • Microsoft Defender for Cloud for security posture management

16. Best Practices

Use least privilege

Allow only the required:

  • Sources
  • Destinations
  • Ports
  • Protocols
  • Directions

Prefer application-based rules

Use ASGs instead of individual IP addresses when controlling communication between application tiers.

Use service tags appropriately

Use service tags to avoid maintaining changing Azure service IP ranges manually.

Avoid unrestricted access

Avoid rules that allow:

Source: Any
Destination: Any
Port: Any
Protocol: Any
Action: Allow

unless there is a documented and justified requirement.

Separate application tiers

Use different subnets and ASGs for:

  • Web
  • Application
  • Database
  • Management

Review effective rules

Regularly inspect effective security rules to verify that the actual applied policy matches the intended design.

Use infrastructure as code

Define NSGs, ASGs, and rules in Bicep, ARM templates, or another approved infrastructure-as-code solution to improve consistency and auditability.

Remove obsolete rules

Unused rules increase complexity and may create unintended access paths.

Document security intent

Use descriptive names and descriptions such as:

Allow-App-to-Database-SQL

rather than:

Rule1

Practice Exam Questions

Question 1

A company hosts a three-tier application in Azure. Web servers must communicate with application servers over TCP port 8080. Application servers must communicate with database servers over TCP port 1433. The company wants security rules to remain valid when virtual machines are added or their private IP addresses change.

What should you implement?

A. Create ASGs for each application tier and reference them in NSG rules.
B. Create a separate NSG for every virtual machine using static IP addresses.
C. Allow all traffic between the application subnets.
D. Use public IP addresses for all application servers.

Correct answer: A

Explanation: ASGs allow NSG rules to reference application roles instead of individual IP addresses. Membership can change without requiring the security rules to be rewritten.


Question 2

An NSG associated with a subnet allows inbound TCP port 443. An NSG associated with a VM’s NIC denies inbound TCP port 443 from the same source.

What is the result?

A. The subnet NSG takes precedence, so traffic is allowed.
B. The NIC NSG takes precedence, so traffic is denied.
C. Azure randomly selects one of the rules.
D. The traffic is allowed only if the VM has a public IP address.

Correct answer: B

Explanation: Both the subnet-level and NIC-level NSGs apply. Traffic must be allowed by both. The deny rule in the NIC-level NSG blocks the connection.


Question 3

An administrator creates an NSG rule with priority 100 that denies all inbound traffic. Another rule with priority 200 allows inbound HTTPS traffic.

What happens to inbound HTTPS traffic?

A. HTTPS is allowed because it uses a secure protocol.
B. HTTPS is allowed because the allow rule is more specific.
C. HTTPS is denied because the priority 100 rule is evaluated first.
D. Azure combines the actions and allows the traffic.

Correct answer: C

Explanation: Lower priority numbers are evaluated first. The broad deny rule at priority 100 matches the traffic, so the later allow rule is not evaluated.


Question 4

A VM cannot receive traffic from another VM in the same virtual network. The NSG associated with the destination NIC allows the traffic, but the subnet-level NSG contains a deny rule.

What should the administrator do first?

A. Assign a public IP address to the destination VM.
B. Review and modify the subnet-level NSG rule.
C. Disable the destination VM’s operating-system firewall.
D. Create an Azure Firewall policy.

Correct answer: B

Explanation: Both the subnet-level and NIC-level NSGs apply. A deny rule at the subnet level can block traffic even when the NIC-level NSG allows it.


Question 5

An organization wants to allow traffic from Azure Storage without manually maintaining a list of changing Azure IP addresses.

Which feature should be used?

A. Application security group
B. User-defined route
C. Service tag
D. Public IP prefix

Correct answer: C

Explanation: Service tags represent Microsoft-managed groups of IP address prefixes for Azure services. Microsoft updates the prefixes as service addresses change.


Question 6

A security administrator creates an ASG named Asg-Database. The administrator then creates an NSG rule allowing traffic to Asg-Database on TCP port 1433.

A database VM is not receiving the traffic.

Which issue could explain the problem?

A. The VM’s NIC is not a member of Asg-Database.
B. ASGs automatically deny all traffic.
C. ASGs can contain only public IP addresses.
D. ASGs work only with Azure Firewall.

Correct answer: A

Explanation: An NSG rule referencing an ASG applies only to network interfaces that are members of that ASG. The ASG itself does not automatically include every VM in a subnet.


Question 7

Which statement about application security groups is correct?

A. An ASG directly filters traffic without an NSG.
B. An ASG can contain NICs from multiple virtual networks.
C. An ASG is a logical grouping of network interfaces used by NSG rules.
D. An ASG replaces the need for subnet-level NSGs.

Correct answer: C

Explanation: ASGs provide logical grouping. NSG rules perform the actual allow or deny operation. NICs in an ASG must be in the same virtual network.


Question 8

A VM cannot connect to a database server. The administrator wants to see the combined inbound and outbound rules applied from the subnet and NIC NSGs.

Which feature should be used?

A. Azure Advisor
B. Effective security rules
C. Microsoft Defender Vulnerability Management
D. Azure Service Health

Correct answer: B

Explanation: Effective security rules show the aggregated rules applied to a network interface and are designed to help troubleshoot NSG-related connectivity issues.


Question 9

A company wants to allow management traffic only from a management subnet to selected application servers. The application servers are distributed across several subnets in the same virtual network.

What is the most maintainable approach?

A. Add every application server’s private IP address to a separate rule.
B. Allow management traffic from the entire virtual network to every server.
C. Create an ASG for the management servers and an ASG for the target application servers, then reference them in an NSG rule.
D. Assign public IP addresses to the management servers.

Correct answer: C

Explanation: ASGs allow security policies to be expressed according to application roles. The rule can remain stable as servers are added or their IP addresses change.


Question 10

An administrator wants to create a rule that allows TCP ports 80, 443, and 8080 from a specified source range using one NSG rule.

Which NSG capability supports this configuration?

A. Augmented security rules
B. Azure Bastion
C. Application Gateway WAF
D. Private Link

Correct answer: A

Explanation: Augmented security rules allow multiple ports, addresses, and ranges to be specified in a single rule, reducing the number of individual rules required.


Final Exam Point

NSGs and ASGs are most effective when used together: NSGs enforce traffic rules, while ASGs make those rules easier to express and maintain according to application architecture.


Go to the SC-500 Exam Prep Hub main page

Implement and configure network access policies by using Azure Virtual Network Manager (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Secure storage, databases, and networking (25–30%)
   --> Implement security for Azure network services
      --> Implement and configure network access policies by using Azure Virtual Network Manager


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Overview

Azure Virtual Network Manager is a network-management service that provides centralized control over Azure virtual networks. It can organize virtual networks into groups and apply network configurations consistently across subscriptions and management groups.

For security, Azure Virtual Network Manager provides security admin rules. These rules allow a central networking or security team to enforce organization-wide network access policies across managed virtual networks.

Security admin rules complement, rather than replace, network security groups (NSGs):

  • Security admin rules provide centrally managed security guardrails.
  • NSGs provide workload- and subnet-level traffic filtering.
  • Azure Firewall provides centralized, stateful traffic inspection and advanced firewall capabilities.

AVNM can also manage connectivity and routing configurations, but security admin rules are the primary feature for centrally enforcing network access policies.


1. Why Use Azure Virtual Network Manager?

Managing NSGs independently across many subscriptions can lead to:

  • Inconsistent security policies
  • Duplicate rules
  • Accidental exposure of high-risk ports
  • Difficulty enforcing organization-wide requirements
  • Security gaps when new virtual networks or resources are created
  • Conflicts between central security requirements and application-team configurations

AVNM addresses these challenges by allowing administrators to define security policies once and apply them to groups of virtual networks.

For example, an organization could centrally enforce the following policy:

Deny inbound SSH and RDP traffic from the Internet to all managed virtual networks unless an explicitly approved exception exists.

The central security team manages the security admin configuration, while application teams can continue managing their own NSGs for more specific workload requirements.


2. Understand the Main Azure Virtual Network Manager Components

Network manager instance

The network manager instance is the primary AVNM resource. It defines:

  • The management scope
  • The regions in which configurations can be deployed
  • The features enabled for the instance

The management scope can include:

  • Selected subscriptions
  • Management groups

The network manager only manages resources within its defined scope. A virtual network outside that scope is not affected by the manager’s configurations.

Network groups

A network group is a logical collection of virtual networks to which configurations can be applied.

Membership can be:

  • Static — administrators manually select virtual networks.
  • Dynamic — Azure Policy conditions determine which virtual networks belong to the group.

Examples of network groups include:

  • Production
  • Development
  • Corporate
  • Internet-facing
  • Regulated workloads
  • High-security workloads
  • Regional network groups

Dynamic membership is useful when new virtual networks should automatically receive the appropriate security policy based on tags, subscriptions, resource groups, or other policy conditions.

Configurations

AVNM supports several configuration types, including:

  • Connectivity configurations
  • Security admin configurations
  • Routing configurations

A security admin configuration contains rule collections, and each rule collection contains security admin rules.

Deployment

Creating or modifying a configuration does not immediately apply it to the target virtual networks. The configuration must be deployed to the relevant regions.

This commit-and-deploy model allows administrators to prepare, review, and then deploy a configuration.


3. Understand Security Admin Rules

A security admin rule is a centrally defined network security rule that applies to virtual networks in targeted network groups.

A rule can specify:

  • Priority
  • Action
  • Direction
  • Protocol
  • Source
  • Destination
  • Source ports
  • Destination ports

Security admin rules support three actions:

  1. Allow
  2. Always allow
  3. Deny

The rules are applied at the virtual-network level and are evaluated before NSG rules.


4. Security Admin Rule Actions

Allow

An Allow rule permits the specified traffic to continue to NSG evaluation.

This means that an NSG can still deny the traffic.

For example:

  • A security admin rule allows inbound TCP 443.
  • The subnet NSG denies inbound TCP 443.

The traffic is ultimately denied by the NSG.

Use Allow when central governance wants to permit a category of traffic but still wants workload owners to apply additional restrictions.

Always allow

An Always allow rule allows the traffic and prevents subsequent NSG rules from denying it.

Use this action only when central governance must guarantee that a particular flow is permitted.

For example, an organization might use an Always allow rule for a required management or monitoring flow.

Because Always allow bypasses subsequent NSG evaluation for the matching traffic, it should be used carefully.

Deny

A Deny rule blocks the traffic immediately.

NSG rules are not evaluated for traffic that matches the security admin deny rule.

This is useful for centrally blocking:

  • Internet-based SSH
  • Internet-based RDP
  • Known high-risk ports
  • Unauthorized network segments
  • Traffic to sensitive workloads

The difference between the three actions is important for the exam:

ActionResult
AllowPermits traffic to continue to NSG evaluation
Always allowPermits traffic and prevents NSGs from denying it
DenyBlocks traffic immediately before NSG evaluation

5. Security Admin Rule Priority

Security admin rules use priorities from 1 through 4,096.

  • Lower numbers have higher priority.
  • A rule with priority 10 is evaluated before a rule with priority 100.
  • A matching higher-priority rule can prevent a lower-priority rule from being evaluated.

Example

Suppose an organization has these rules:

PriorityTarget groupTrafficAction
10Approved-Admin-NetworksInbound TCP 22Allow
100All-Managed-NetworksInbound TCP 22 from InternetDeny

The approved administration networks receive the higher-priority allow rule. Other managed networks are subject to the deny rule.

However, if the priority 10 rule uses Allow, the traffic still proceeds to NSG evaluation. If the rule must bypass a conflicting NSG deny rule, the administrator would need to use Always allow, assuming that action is appropriate for the requirement.


6. Security Admin Rules Versus NSGs

Security admin rules and NSGs have different scopes and purposes.

CharacteristicSecurity admin rulesNSGs
Main audienceCentral network/security administratorsApplication and workload teams
Applied toManaged virtual networksSubnets and network interfaces
ScopeOrganization-wide or group-wideWorkload- or subnet-specific
ActionsAllow, Always allow, DenyAllow, Deny
EvaluationBefore NSGsAfter security admin rules
Central enforcementYesUsually managed at workload level
Can block traffic before NSG evaluation?Yes, with DenyNo
Can bypass NSG denial?Yes, with Always allowNo

A security admin rule does not eliminate the need for NSGs. A common design is:

  1. AVNM enforces organization-wide security requirements.
  2. NSGs enforce application-specific access.
  3. Azure Firewall provides centralized inspection where required.

7. Example: Centrally Blocking High-Risk Ports

An organization wants to prevent Internet-based access to:

  • TCP 22 — SSH
  • TCP 3389 — RDP

The security team creates a network group containing all managed virtual networks.

A security admin configuration contains rules such as:

PriorityDirectionSourceDestinationPortAction
100InboundInternetAny22Deny
110InboundInternetAny3389Deny

After deployment, the rules apply to resources in the targeted virtual networks.

This approach is more reliable than asking every application team to create and maintain equivalent NSG deny rules independently.


8. Example: Allowing Approved Exceptions

Suppose an organization blocks inbound SSH from the Internet but has a small set of approved administration networks.

Create two network groups:

  • All-Networks
  • Approved-Admin-Networks

Then create security admin rules:

PriorityNetwork groupSourceDestinationPortAction
10Approved-Admin-NetworksApproved admin rangeAny22Allow
100All-NetworksInternetAny22Deny

The more specific exception is evaluated first because it has the lower priority.

If the approved traffic must not be blocked by a workload NSG, use Always allow instead of Allow, subject to the organization’s security design.

The important principle is that exceptions should be narrowly scoped and have a higher priority than the broad deny rule.


9. Create a Network Manager Instance

The general implementation process is:

  1. Create an Azure Virtual Network Manager instance.
  2. Define its management scope.
  3. Enable the Security admin feature.
  4. Create network groups.
  5. Add virtual networks to the groups.
  6. Create a security admin configuration.
  7. Add rule collections and rules.
  8. Associate rule collections with network groups.
  9. Deploy the configuration to the required regions.
  10. Verify the resulting policy and connectivity.

The manager’s scope should be designed carefully. A manager scoped to a management group can govern virtual networks across multiple subscriptions within that scope.


10. Configure Network Group Membership

Static membership

With static membership, an administrator manually adds virtual networks to a network group.

This provides precise control but requires ongoing maintenance.

Use static membership when:

  • The number of virtual networks is small.
  • Membership changes are infrequent.
  • The organization needs explicit approval for every member.

Dynamic membership

With dynamic membership, Azure Policy determines which virtual networks belong to the group.

For example, a policy could include virtual networks that:

  • Have a specific tag
  • Belong to a particular subscription
  • Exist in a particular resource group
  • Match a defined naming convention

Dynamic membership is useful in large environments because new qualifying virtual networks can be added automatically.

However, membership updates and configuration application are not necessarily instantaneous. Administrators should account for deployment and policy-evaluation delays.


11. Create a Security Admin Configuration

A security admin configuration contains one or more rule collections.

A rule collection generally defines:

  • A collection name
  • A set of security admin rules
  • The network groups to which the collection applies

A rule should be designed around a clearly stated security requirement.

For example:

Block inbound RDP from the Internet to all production virtual networks.

The corresponding rule could specify:

  • Direction: Inbound
  • Protocol: TCP
  • Source: Internet
  • Destination: Any
  • Destination port: 3389
  • Action: Deny
  • Priority: 100

The configuration is then associated with the appropriate production network group and deployed to the required regions.


12. Deployment and Eventual Consistency

AVNM configurations do not take effect merely because they have been created.

Administrators must deploy the configuration to the regions containing the target virtual networks.

There may also be a delay when:

  • A configuration is first deployed
  • A network group’s membership changes
  • New resources are added to a managed virtual network
  • A security admin rule is modified

Microsoft describes this as an eventual consistency model. A newly created resource may not receive the security admin rules immediately.

Exam consideration

If a rule appears not to be working immediately:

  1. Confirm that the configuration was deployed.
  2. Confirm that the deployment targeted the correct region.
  3. Confirm that the virtual network belongs to the expected network group.
  4. Allow time for membership and configuration propagation.
  5. Verify whether the resource or subnet is exempt from security admin rules.

13. Important Exceptions and Limitations

Security admin rules do not apply universally.

Private endpoints in managed virtual networks

Security admin rules do not apply to private endpoints that fall under the scope of a managed virtual network.

Service-specific subnets

Certain service subnets are exempt because the services require specific network behavior.

Examples include subnets used by:

  • Azure Application Gateway
  • Azure Bastion
  • Azure Firewall
  • Azure Route Server
  • Azure VPN Gateway
  • Azure Virtual WAN
  • Azure ExpressRoute Gateway

Azure SQL Managed Instance and Azure Databricks

By default, security admin rules are not applied to virtual networks containing certain services, including:

  • Azure SQL Managed Instance
  • Azure Databricks

These services can have network intent policies that conflict with security admin rules.

For supported scenarios, administrators can configure the security configuration to apply Allow rules only to such virtual networks. This does not mean that Deny rules are applied; the setting is specifically intended to avoid conflicts with service-required network policies.


14. Network Groups as Sources and Destinations

AVNM can use network groups to define the source and destination of security admin rules.

For example:

Source: Web-Networks
Destination: Database-Networks
Protocol: TCP
Destination port: 1433
Action: Allow

This expresses the intended relationship between groups of virtual networks rather than relying only on individual IP addresses.

However, the use of network groups as source and destination in security admin rules is identified in Microsoft documentation as a public-preview capability. Preview features may have limitations and should not automatically be assumed to be suitable for production workloads.


15. AVNM and Connectivity Configurations

Although this topic focuses on network access policies, AVNM also supports connectivity configurations.

Connectivity configurations can establish:

  • Hub-and-spoke connectivity
  • Mesh connectivity
  • Regional mesh connectivity
  • Global mesh connectivity

Security admin rules and connectivity configurations solve different problems:

  • Connectivity configurations determine how virtual networks connect.
  • Security admin configurations determine which traffic is permitted or denied.

A network can be connected but still have traffic blocked by security admin rules or NSGs.

AVNM’s configurations are additive in some scenarios, and multiple connectivity configurations can exist in a region. However, only one security admin configuration can be deployed to a region for a given network manager instance; multiple security rule collections can be placed within that configuration.


16. AVNM and Azure Firewall

Azure Virtual Network Manager security admin rules are not a replacement for Azure Firewall.

Use security admin rules for:

  • Organization-wide allow or deny policies
  • Blocking high-risk ports
  • Enforcing network segmentation
  • Applying consistent guardrails across many virtual networks
  • Preventing workload NSGs from bypassing central deny rules

Use Azure Firewall for:

  • Stateful traffic inspection
  • Centralized network and application rules
  • Threat intelligence filtering
  • Centralized logging
  • Advanced firewall policy management
  • Traffic inspection between network segments

A defense-in-depth design may use AVNM security admin rules, NSGs, Azure Firewall, private endpoints, and application-layer controls together.


17. Best Practices

Define a clear management scope

Use a management group or carefully selected subscriptions that contain the virtual networks requiring centralized governance.

Separate central and workload responsibilities

Central security teams should manage organization-wide guardrails. Application teams should manage workload-specific NSGs.

Use deny-by-default principles

Block unnecessary traffic and permit only the flows required by the business or application.

Use specific priorities

Reserve priority ranges for:

  • Emergency blocks
  • Approved exceptions
  • Standard organization-wide denies
  • General allow rules

Use network groups strategically

Group virtual networks by meaningful characteristics such as:

  • Environment
  • Business unit
  • Data sensitivity
  • Regulatory requirements
  • Internet exposure
  • Application role

Use dynamic membership where appropriate

Dynamic membership reduces manual administration but requires careful Azure Policy design and awareness of propagation delays.

Test exceptions

Verify that approved exceptions work without unintentionally allowing broader access.

Avoid unnecessary Always allow rules

Always allow bypasses NSG denial for matching traffic. Use it only when central governance must guarantee the flow.

Document exclusions

Record why certain service subnets or virtual networks are exempt from security admin rules.

Verify after deployment

Confirm:

  • The configuration is deployed
  • The deployment succeeded
  • The expected network groups contain the correct virtual networks
  • The rules have the intended priorities
  • Connectivity behaves as designed

Practice Exam Questions

Question 1

A company wants to centrally block inbound RDP traffic from the Internet across all production virtual networks. Individual application teams currently manage their own NSGs.

Which solution best meets the requirement?

A. Create a security admin Deny rule in Azure Virtual Network Manager and apply it to a production network group.
B. Create a separate NSG on every VM and configure an RDP deny rule.
C. Configure Azure DNS to block RDP traffic.
D. Add a route for TCP port 3389 to each subnet.

Correct answer: A

Explanation: Security admin rules provide centralized enforcement across managed virtual networks. A Deny rule blocks matching traffic before NSG evaluation.


Question 2

A security administrator creates an AVNM security admin rule with the action Allow for inbound TCP port 443. A subnet-level NSG denies the same traffic.

What happens?

A. The security admin Allow rule always overrides the NSG.
B. The traffic is allowed because security admin rules bypass NSGs.
C. The traffic is denied by the NSG.
D. The traffic is routed through Azure Firewall automatically.

Correct answer: C

Explanation: An Allow security admin rule permits traffic to continue to NSG evaluation. The NSG can still deny the traffic.


Question 3

An organization needs to guarantee that approved monitoring traffic is not blocked by workload-level NSGs.

Which security admin action should be considered?

A. Allow
B. Deny
C. Audit
D. Always allow

Correct answer: D

Explanation: Always allow permits the matching traffic and prevents subsequent NSG rules from denying it. It should be used carefully because it bypasses NSG denial for that flow.


Question 4

Which priority has the highest precedence in an Azure Virtual Network Manager security admin configuration?

A. 4,096
B. 2,000
C. 100
D. 10

Correct answer: D

Explanation: Lower priority numbers are evaluated first. Priority 10 has higher precedence than priorities 100, 2,000, and 4,096.


Question 5

An organization wants new virtual networks with the tag Environment=Production to automatically receive a centralized security policy.

What should the administrator use?

A. Static network group membership
B. Dynamic network group membership based on Azure Policy
C. A public IP prefix
D. An NSG attached to one production VM

Correct answer: B

Explanation: Dynamic network group membership uses policy-based conditions to determine which virtual networks belong to a group.


Question 6

An administrator creates a security admin configuration but traffic is still permitted through a virtual network that should be protected.

What should be checked first?

A. Whether the configuration was deployed to the correct region
B. Whether the VM has a larger SKU
C. Whether the virtual network has a DNS server
D. Whether the VM has an availability set

Correct answer: A

Explanation: AVNM configurations do not take effect until they are deployed to the relevant regions. Incorrect or missing deployment is a common cause of unexpected behavior.


Question 7

Which statement correctly describes the relationship between security admin rules and NSGs?

A. NSGs are evaluated before security admin rules.
B. Security admin rules and NSGs cannot be used together.
C. Security admin rules are evaluated before NSGs.
D. Security admin rules apply only to public IP addresses.

Correct answer: C

Explanation: Security admin rules provide centralized network-level enforcement and are evaluated before NSG rules.


Question 8

A virtual network contains Azure SQL Managed Instance. The administrator notices that the expected security admin Deny rules are not being applied.

What is the most likely explanation?

A. SQL Managed Instance supports only public IP addresses.
B. Security admin rules are never applied to production networks.
C. NSGs automatically disable AVNM.
D. Certain service network intent requirements can cause security admin rules to be skipped by default.

Correct answer: D

Explanation: Azure SQL Managed Instance and certain other services have network intent policies that can conflict with security admin rules. Such virtual networks may be exempt by default, with supported Allow-rules-only behavior available for applicable scenarios.


Question 9

A company wants to centrally deny Internet-based SSH traffic but permit SSH from an approved administration network. Which design is most appropriate?

A. Create a lower-priority allow exception for the approved network and a broader higher-numbered deny rule for all managed networks.
B. Create only an allow rule for the Internet.
C. Create a deny rule for the approved administration network.
D. Remove all NSGs from the virtual networks.

Correct answer: A

Explanation: The approved exception should have a lower priority number than the broad deny rule. If the exception must bypass NSG denial, the administrator should evaluate whether Always allow is appropriate.


Question 10

Which statement about Azure Virtual Network Manager security admin rules is correct?

A. They replace Azure Firewall for stateful traffic inspection.
B. They directly modify the operating-system firewall on each VM.
C. They can enforce centralized network policies across virtual networks in targeted network groups.
D. They apply automatically to every virtual network in every Azure tenant.

Correct answer: C

Explanation: AVNM applies centralized security admin rules to virtual networks in network groups within the manager’s defined scope. It does not replace Azure Firewall, modify guest operating-system firewalls, or automatically govern resources outside its scope.


Go to the SC-500 Exam Prep Hub main page

Configure security for an Azure Virtual WAN (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Secure storage, databases, and networking (25–30%)
   --> Implement security for Azure network services
      --> Configure security for an Azure Virtual WAN


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Overview

Azure Virtual WAN is a Microsoft-managed networking service that provides centralized connectivity between Azure virtual networks, branch offices, remote users, and other connected environments. It combines networking, routing, VPN, ExpressRoute, and security capabilities through a unified operational model.

For the SC-500 exam, the important security concept is that Azure Virtual WAN should not be viewed only as a connectivity service. It can also provide a centralized inspection and enforcement point for traffic flowing between:

  • Azure virtual networks
  • On-premises branch offices
  • Remote users
  • Other Virtual WAN hubs
  • The internet
  • Azure platform services and private resources

A common secure design is to use a secured virtual hub, Azure Firewall, Firewall Manager, and Virtual WAN routing capabilities to ensure that traffic is inspected before reaching protected destinations.


What Is Azure Virtual WAN?

Azure Virtual WAN consists of several major components:

Virtual WAN resource

The Virtual WAN resource is the top-level container for one or more virtual hubs. It provides a centralized management and configuration boundary.

Virtual hub

A virtual hub is a Microsoft-managed network infrastructure component deployed in an Azure region. It provides connectivity and routing services for connected networks and gateways.

A virtual hub can contain or provide access to:

  • Site-to-site VPN gateways
  • Point-to-site user VPN gateways
  • ExpressRoute gateways
  • The Virtual WAN hub router
  • Azure Firewall
  • Supported network virtual appliances
  • Connections to Azure virtual networks
  • Connections to branch sites

Unlike a customer-managed hub VNet, a Virtual WAN hub is operated by Microsoft. You do not directly deploy or manage the underlying hub virtual network in the same way that you manage a normal Azure VNet.

Virtual network connections

Azure VNets connect to a Virtual WAN hub through virtual network connections. These connections allow workloads in the VNets to communicate with other connected networks according to the hub’s routing configuration.

VPN and ExpressRoute connections

Branch offices and on-premises networks can connect to Virtual WAN through:

  • Site-to-site VPN
  • ExpressRoute
  • Point-to-site user VPN

The connection type depends on the organization’s requirements for connectivity, performance, availability, and authentication.


Basic and Standard Virtual WAN

Azure Virtual WAN is available in two primary types:

CapabilityBasic Virtual WANStandard Virtual WAN
Site-to-site VPNSupportedSupported
ExpressRouteNot supportedSupported
Point-to-site user VPNNot supportedSupported
Inter-hub transitNot supportedSupported
VNet-to-VNet transitNot supportedSupported
Azure FirewallNot supportedSupported
Network virtual appliances in Virtual WANNot supportedSupported

For most enterprise security scenarios, Standard Virtual WAN is required because secured hubs, Azure Firewall, advanced transit, and additional gateway capabilities depend on Standard functionality.

A Basic Virtual WAN can be upgraded to Standard, but it cannot be downgraded from Standard back to Basic.


What Is a Secured Virtual Hub?

A secured virtual hub is an Azure Virtual WAN hub with an integrated Azure Firewall.

Azure Firewall provides centralized traffic inspection and policy enforcement for traffic moving through the Virtual WAN environment. A secured hub can inspect traffic destined for:

  • Private IP addresses
  • Azure virtual networks
  • Other connected networks
  • The internet
  • Azure platform services, depending on the routing and security design

Azure Firewall can inspect traffic between different network locations, including:

  • North-south traffic: traffic between on-premises networks and Azure
  • East-west traffic: traffic between Azure networks or workloads
  • Internet-bound traffic: traffic from Azure workloads to the internet

This approach centralizes security enforcement rather than requiring every workload or spoke network to independently deploy a firewall.

Why use a secured virtual hub?

A secured virtual hub can provide:

  • Centralized traffic inspection
  • Consistent firewall policies
  • Reduced need for manually configured routes
  • Centralized security management across multiple hubs
  • Protection for Azure and branch connectivity
  • A more consistent Zero Trust architecture
  • Easier enforcement of organization-wide security requirements

For example, an organization might connect several regional VNets and branch offices to Virtual WAN. Instead of deploying and maintaining separate firewalls in every location, the organization can use Azure Firewall in secured hubs and apply consistent policies.


Azure Firewall Manager

Azure Firewall Manager provides centralized management for firewall policies and secured virtual hubs.

It can be used to:

  • Create secured virtual hubs
  • Manage Azure Firewall policies
  • Apply consistent security rules across multiple hubs
  • Configure routing-related security settings
  • Manage security for multiple regions
  • Separate centralized security administration from individual workload administration

Firewall Manager is particularly useful when an organization has multiple Virtual WAN hubs in different Azure regions.

For example:

  • A global company has hubs in North America, Europe, and Asia.
  • Each hub connects regional VNets and branch offices.
  • Security administrators manage common firewall policies centrally.
  • Regional teams manage their workloads without independently designing the entire network security architecture.

Firewall Manager supports centralized rule management across secured hubs.


Routing Intent

One of the most important security features in Azure Virtual WAN is routing intent.

Routing intent allows you to define how traffic should be routed through a security solution, such as Azure Firewall or a supported network virtual appliance.

Common routing intent patterns include:

Internet traffic inspection

Internet-bound traffic from connected VNets or branches is routed through the security solution before reaching the internet.

This helps enforce policies such as:

  • Blocking malicious destinations
  • Restricting outbound access
  • Inspecting internet-bound traffic
  • Applying centralized filtering
  • Logging traffic for investigation

Private traffic inspection

Private traffic between connected networks is routed through the security solution.

For example:

  • VNet A communicates with VNet B.
  • A branch office communicates with an Azure workload.
  • One regional hub communicates with another regional hub.

Routing intent can be used to steer this private traffic through the firewall for inspection.

Why routing intent matters

Without centralized routing, administrators may need to create and maintain multiple user-defined routes. Incorrect or incomplete routes can allow traffic to bypass inspection.

Routing intent helps simplify this process by automatically steering specified traffic categories through the security solution. The Virtual WAN architecture is designed to reduce the need for manually maintained routing configurations.


Traffic Flow Through a Secured Virtual Hub

A simplified secure traffic flow might look like this:

Branch Office
|
| Site-to-site VPN or ExpressRoute
|
Virtual WAN Hub
|
Azure Firewall
|
+--------------------+
| |
Private Azure VNet Internet

For traffic between two Azure VNets:

VNet A
|
| Virtual WAN connection
|
Virtual WAN Hub
|
Azure Firewall
|
Virtual WAN Hub
|
| Virtual WAN connection
|
VNet B

The exact traffic path depends on the hub configuration, routing intent, firewall policy, connection settings, and whether the traffic is classified as private or internet-bound.

The important exam concept is:

A connection to Virtual WAN does not automatically mean that all traffic is inspected by Azure Firewall. The routing and security configuration must direct the traffic through the security solution.


Azure Firewall Policy in a Secured Virtual Hub

Azure Firewall policies define the traffic that is allowed, denied, or inspected.

Depending on the Azure Firewall tier and configuration, policies can include:

  • Network rules
  • Application rules
  • NAT rules
  • Threat intelligence filtering
  • DNS-related security controls
  • TLS inspection capabilities, where supported and configured
  • IDPS capabilities with Azure Firewall Premium

Network rules

Network rules control traffic based on characteristics such as:

  • Source address
  • Destination address
  • Protocol
  • Destination port

Examples include:

  • Allow TCP 443 from a corporate network to an application subnet
  • Deny TCP 22 from untrusted networks
  • Allow DNS traffic to an approved DNS service
  • Block traffic to a known prohibited network range

Application rules

Application rules can control supported application-layer traffic, such as HTTP and HTTPS, based on:

  • Fully qualified domain names
  • Web categories
  • Application characteristics

For example, an organization might allow servers to access only approved software repositories.

NAT rules

NAT rules can publish selected internal services through a public IP address. NAT should be configured carefully because it can expose internal resources to external traffic.

Security considerations include:

  • Restricting source addresses
  • Limiting exposed ports
  • Avoiding unnecessary public exposure
  • Applying least privilege
  • Monitoring inbound connections
  • Using private connectivity whenever possible

Virtual WAN Network Virtual Appliances

Azure Virtual WAN can also support supported network virtual appliances, depending on the Virtual WAN type and deployment architecture.

A network virtual appliance might provide specialized capabilities such as:

  • Third-party firewall functionality
  • Intrusion prevention
  • Secure web gateway features
  • Specialized network inspection
  • Vendor-specific security controls

However, an NVA is not automatically equivalent to Azure Firewall. Before selecting an NVA, verify:

  • Supported Virtual WAN integration
  • Routing behavior
  • High availability
  • Scaling model
  • Inspection capabilities
  • Logging and monitoring
  • TLS inspection support
  • Compatibility with required traffic patterns
  • Whether the appliance supports the organization’s security requirements

Microsoft documentation specifically notes that NVAs deployed in a Virtual WAN hub can have different capabilities from Azure Firewall.


Virtual WAN Hub Address Space

When creating a Virtual WAN hub, you must specify a hub address space.

Important considerations include:

  • The minimum hub address space is /24.
  • Microsoft recommends using /23 or larger when future growth is expected.
  • If Azure Firewall is used in the Virtual WAN hub, a minimum /22 address space is required to provide sufficient IP address capacity for firewall scaling.
  • The hub address space cannot be changed after the hub is created.
  • The hub address space must not overlap with connected VNets, on-premises networks, or other Virtual WAN hub address spaces.

The address space is used internally by the hub and its services, including the hub router, VPN gateways, ExpressRoute, Azure Firewall, and supported NVAs.

Exam warning

Do not select a hub address range that overlaps with:

  • An on-premises network
  • A connected VNet
  • Another Virtual WAN hub
  • A future planned network

Address-space overlap can cause routing conflicts and connectivity failures.


Virtual WAN Connectivity Security

Site-to-site VPN

Site-to-site VPN provides encrypted connectivity between an on-premises VPN device and a Virtual WAN hub.

The on-premises device generally requires:

  • An externally reachable public IP address
  • IPsec/IKE compatibility
  • Correct VPN configuration
  • Matching authentication and encryption settings
  • Appropriate routing configuration

Virtual WAN supports IPsec/IKE VPN connectivity, including IKEv1 and IKEv2 scenarios.

Security best practices include:

  • Use strong pre-shared keys or supported authentication methods.
  • Store sensitive VPN secrets securely.
  • Rotate credentials according to organizational policy.
  • Avoid exposing management interfaces on the public internet.
  • Monitor VPN connection status and gateway logs.
  • Use redundant connections for critical sites.
  • Validate learned and advertised routes.

Point-to-site user VPN

Point-to-site VPN allows individual users to connect to a Virtual WAN hub.

Authentication can be integrated with Microsoft Entra ID. This enables centralized identity-based access and can support organizational authentication requirements.

Security controls may include:

  • Microsoft Entra authentication
  • Multifactor authentication
  • Conditional Access
  • Group-based authorization
  • Device compliance requirements
  • Restricted user access
  • Short-lived or controlled access
  • Monitoring of user VPN activity

The key distinction is that site-to-site VPN connects networks, while point-to-site VPN connects individual users or devices.

ExpressRoute

ExpressRoute provides private connectivity between on-premises infrastructure and Azure.

ExpressRoute traffic does not traverse the public internet in the same way as ordinary internet-based connectivity. Virtual WAN can provide transit connectivity and routing between connected networks.

Security considerations include:

  • Controlling which routes are advertised
  • Avoiding unintended transit
  • Applying private traffic inspection where required
  • Monitoring route propagation
  • Using encryption requirements appropriate to the organization
  • Understanding that private connectivity does not automatically eliminate the need for authorization and inspection

Route Tables and Route Propagation

Virtual WAN uses hub routing and route tables to determine how traffic is forwarded between connected networks.

A route table can define:

  • Which routes a connection learns
  • Which routes are propagated to a connection
  • Which networks can communicate
  • Whether a connection receives default routes
  • Whether traffic is directed toward a firewall or NVA

Route association

A connection is associated with a Virtual WAN route table. The association determines which route table is used for forwarding decisions.

Route propagation

Route propagation determines which routes are advertised to a connection.

For example, a connection might receive routes for:

  • Other VNets
  • Branch networks
  • Other Virtual WAN hubs
  • The internet default route
  • Specific private address ranges

Security importance

Route propagation can affect whether traffic:

  • Reaches a protected network
  • Can communicate with another spoke
  • Is routed through a firewall
  • Can access the internet
  • Can bypass an inspection point

A secure configuration should advertise only the routes that are necessary.


Internet Security and the Default Route

The default route is:

0.0.0.0/0

When internet security is enabled and routing is configured to send internet traffic through a firewall or NVA, the default route can be advertised to connected VNets.

This causes internet-bound traffic from those VNets to use the centralized security solution.

However, administrators must understand the operational impact:

  • Internet access may be blocked unless firewall rules allow it.
  • DNS resolution may be affected by routing and firewall policies.
  • Application dependencies may fail if required endpoints are not allowed.
  • The firewall must be configured to permit legitimate outbound traffic.
  • Route propagation must be validated after changes.

The security objective is to prevent workloads from bypassing the organization’s inspection and filtering controls.


Private Traffic Inspection

Private traffic inspection is used when traffic between private networks must pass through a security solution.

Examples include:

  • VNet-to-VNet communication
  • Branch-to-VNet communication
  • Hub-to-hub communication
  • Traffic between application tiers
  • Traffic between production and shared services

Private traffic inspection is especially important in Zero Trust architectures because private IP addressing alone does not prove that traffic is trustworthy.

A workload in one VNet should not automatically be trusted merely because it is connected to the same Virtual WAN environment.

Security policies should consider:

  • Source network
  • Destination network
  • Application role
  • Protocol
  • Port
  • Identity and workload context
  • Required business relationship
  • Logging and monitoring requirements

Branch-to-Branch and Hub-to-Hub Connectivity

Virtual WAN can provide transit connectivity between connected branch sites and hubs.

This can simplify global network architecture, but it also creates security considerations.

For example, if branch-to-branch traffic is enabled, one branch may be able to communicate with another branch through Virtual WAN. This may be useful, but it could also create an unintended trust relationship.

Before enabling branch-to-branch connectivity, determine:

  • Which branches should communicate
  • Whether branch traffic must be inspected
  • Whether segmentation is required
  • Whether the firewall can inspect the traffic
  • Whether route propagation exposes unnecessary networks
  • Whether the connectivity requirement is temporary or permanent

The principle is:

Enable only the transit connectivity that is required by the business and security architecture.


Azure Virtual WAN and Zero Trust

A Zero Trust design assumes that no network location is inherently trusted.

For Virtual WAN, this means:

  • Do not trust traffic solely because it originates from a connected VNet.
  • Do not assume private traffic is safe.
  • Inspect traffic where required.
  • Use least-privilege routing.
  • Restrict internet access.
  • Authenticate remote users.
  • Apply consistent firewall policies.
  • Monitor traffic and configuration changes.
  • Segment workloads and branches.
  • Avoid unnecessary route propagation.

A secured Virtual WAN hub can support Zero Trust by centralizing inspection and reducing opportunities for traffic to bypass security controls.


Logging and Monitoring

Virtual WAN and related resources can produce resource logs that can be sent to:

  • Log Analytics workspaces
  • Event Hubs
  • Storage accounts

Logging can support:

  • Security investigations
  • VPN troubleshooting
  • Route analysis
  • Firewall monitoring
  • Compliance evidence
  • Detection of configuration changes
  • Investigation of unexpected connectivity

Resource logs are not necessarily enabled automatically. The organization must configure diagnostic settings and select the appropriate destination.

A recommended design is to send security-relevant logs to a centralized Log Analytics workspace and integrate them with Microsoft Sentinel when broader security analytics and incident response are required.

Monitor these areas

Monitor:

  • Virtual hub health
  • Hub router status
  • VPN connection state
  • ExpressRoute connectivity
  • Learned routes
  • Advertised routes
  • Firewall health
  • Firewall rule hits
  • Denied connections
  • Unexpected internet access
  • Configuration changes
  • Resource deployment failures

Hub Router Status

A Virtual WAN hub router can have statuses such as:

  • Provisioned
  • Provisioning
  • Failed
  • None

A Failed status may indicate a problem during router instantiation.

A None status may occur when the router was not provisioned, including scenarios involving Basic Virtual WAN or older hub deployments.

The hub router is important because it provides the routing infrastructure for transit connectivity. If the router is not functioning correctly, connected networks may experience routing or connectivity problems.


Security Best Practices

1. Use Standard Virtual WAN for enterprise security scenarios

Standard Virtual WAN supports the capabilities generally required for secured hubs, advanced transit, ExpressRoute, point-to-site VPN, Azure Firewall, and supported NVAs.

2. Use secured virtual hubs for centralized inspection

Deploy Azure Firewall in the Virtual WAN hub when traffic from multiple networks must be inspected consistently.

3. Use Firewall Manager for centralized policy management

Use centralized firewall policies to reduce inconsistent regional configurations.

4. Configure routing intent deliberately

Ensure private and internet-bound traffic is routed through the appropriate security solution.

5. Avoid overlapping address spaces

Plan hub, VNet, branch, and on-premises address spaces before deployment.

6. Use least-privilege route propagation

Advertise only the routes that each connection needs.

7. Do not assume connected networks are trusted

Apply inspection and access controls based on the required communication paths.

8. Protect VPN credentials

Store VPN secrets securely and rotate them according to policy.

9. Monitor logs centrally

Enable diagnostic settings and send relevant logs to a centralized monitoring destination.

10. Validate changes before production deployment

Test:

  • Route propagation
  • Firewall inspection
  • VPN connectivity
  • Internet access
  • Private network access
  • DNS resolution
  • Failover behavior
  • Logging and alerting

Common Exam Traps

Trap 1: “A VNet connected to Virtual WAN automatically uses Azure Firewall.”

Not necessarily. Traffic must be routed through the firewall using the appropriate security and routing configuration.

Trap 2: “Basic Virtual WAN supports Azure Firewall.”

Basic Virtual WAN does not support Azure Firewall. Standard Virtual WAN is required.

Trap 3: “A private connection is automatically secure.”

Private connectivity reduces exposure to the public internet, but it does not replace authorization, segmentation, inspection, or monitoring.

Trap 4: “Routing intent is only for internet traffic.”

Routing intent can be used for internet-bound traffic and private traffic inspection.

Trap 5: “The Virtual WAN hub address space can be changed later.”

The hub address space cannot be modified after the hub is created.

Trap 6: “An NVA and Azure Firewall always have identical capabilities.”

They do not. Validate the NVA’s supported features and Virtual WAN integration.

Trap 7: “Enabling branch-to-branch connectivity is always desirable.”

It can create additional trust paths and should be enabled only when required.


Practice Exam Questions

Question 1

An organization has several Azure VNets and branch offices connected through Azure Virtual WAN. The security team requires all internet-bound traffic from the VNets to pass through a centralized Azure Firewall.

What should the organization configure?

A. A network security group on every subnet
B. Routing intent that directs internet traffic through Azure Firewall
C. A point-to-site VPN connection for every workload
D. A separate public IP address for every VNet

Correct answer: B

Explanation: Routing intent can direct internet-bound traffic through Azure Firewall in a secured virtual hub. NSGs do not provide centralized internet traffic inspection across Virtual WAN.


Question 2

Which Virtual WAN type is required for an architecture that uses Azure Firewall, ExpressRoute, and inter-hub transit?

A. Basic Virtual WAN
B. Standard Virtual WAN
C. Basic virtual hub with a route table
D. Any Virtual WAN type

Correct answer: B

Explanation: Standard Virtual WAN supports Azure Firewall, ExpressRoute, inter-hub transit, point-to-site VPN, and other advanced capabilities. Basic Virtual WAN is limited primarily to site-to-site VPN connectivity.


Question 3

A company wants to centrally manage Azure Firewall policies across secured Virtual WAN hubs deployed in multiple regions.

Which service should it use?

A. Azure Network Watcher
B. Azure Bastion
C. Azure Firewall Manager
D. Azure DNS Private Resolver

Correct answer: C

Explanation: Azure Firewall Manager provides centralized management of firewall policies and secured virtual hubs across regions.


Question 4

An administrator is creating a Virtual WAN hub that will use Azure Firewall. Which address-space decision is appropriate?

A. Use an address space that overlaps with the largest connected VNet
B. Use a minimum /30 address space
C. Use a minimum /22 address space for a hub with Azure Firewall
D. Use the same address space as the on-premises network

Correct answer: C

Explanation: A Virtual WAN hub using Azure Firewall requires a minimum /22 address space to provide sufficient capacity for firewall scaling. The address space must also avoid overlap with connected networks.


Question 5

An organization wants to inspect traffic between two Azure VNets connected to the same Virtual WAN environment.

Which capability is most relevant?

A. Private traffic inspection through routing intent
B. Azure Storage firewall rules
C. Point-to-site VPN authentication
D. Azure Resource Locks

Correct answer: A

Explanation: Private traffic inspection allows traffic between connected private networks to be directed through a firewall or supported NVA.


Question 6

A security engineer enables branch-to-branch connectivity in Virtual WAN. What is the primary security concern?

A. Branches will no longer be able to use VPN
B. Branch-to-branch connectivity may create unintended trust paths
C. Azure Firewall will be automatically deleted
D. ExpressRoute will be converted to a public connection

Correct answer: B

Explanation: Branch-to-branch connectivity can allow one branch to communicate with another. It should be enabled only when required and should be evaluated against segmentation and inspection requirements.


Question 7

Which statement about the Virtual WAN hub address space is correct?

A. It can be changed at any time after hub deployment
B. It must overlap with the connected VNets
C. It cannot overlap with connected or on-premises address spaces
D. It is used only for point-to-site VPN clients

Correct answer: C

Explanation: The hub address space cannot be changed after creation and must not overlap with other Virtual WAN hubs, connected VNets, or on-premises networks.


Question 8

A company wants to connect individual employees to a Virtual WAN hub and authenticate them using Microsoft Entra ID.

Which connectivity option should it use?

A. Site-to-site VPN
B. Point-to-site user VPN
C. ExpressRoute Direct
D. VNet peering

Correct answer: B

Explanation: Point-to-site user VPN connects individual users or devices and can be configured with Microsoft Entra ID authentication.


Question 9

An administrator configures routing intent but users report that internet access is failing from a connected VNet. What should the administrator check first?

A. Whether the firewall policy allows the required outbound traffic
B. Whether every VM has a public IP address
C. Whether the VNet has a storage account
D. Whether Azure Bastion is deployed

Correct answer: A

Explanation: Routing internet traffic through Azure Firewall does not automatically allow it. The firewall policy must permit the required destinations, protocols, and ports.


Question 10

A security team needs to investigate unexpected VPN disconnects and routing changes in Virtual WAN.

What should it configure?

A. Azure Resource Locks only
B. Diagnostic settings that send Virtual WAN resource logs to a monitoring destination
C. A public IP address on every connected subnet
D. A separate Virtual WAN for every VPN connection

Correct answer: B

Explanation: Virtual WAN and related resources can produce resource logs that can be sent to Log Analytics, Event Hubs, or a storage account. These logs support troubleshooting, auditing, and security investigations.


Key Takeaways

For the SC-500 exam, remember these core points:

  • Standard Virtual WAN is required for advanced enterprise capabilities.
  • A secured virtual hub integrates Azure Firewall with a Virtual WAN hub.
  • Azure Firewall Manager centralizes firewall policy management.
  • Routing intent directs private or internet-bound traffic through a security solution.
  • Connected networks are not automatically trusted.
  • Plan Virtual WAN hub address spaces carefully because they cannot be changed after creation.
  • Avoid address-space overlap.
  • Use least-privilege route propagation.
  • Secure site-to-site and point-to-site connectivity.
  • Monitor Virtual WAN resource logs, routes, gateways, and firewall activity.
  • Validate that traffic actually passes through the intended inspection point.

Go to the SC-500 Exam Prep Hub main page

SC-500 Practice Exam #2

This practice exam is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.

Implementing End-to-End Security Controls for Cloud and AI Workloads


Section 1: Manage Identity, Access, and Governance


Question 1 — Privileged Identity Management

A company uses Microsoft Entra Privileged Identity Management (PIM) to control access to privileged roles. A security administrator must ensure that administrators cannot retain permanent active assignments to a highly privileged role. Administrators must request access when needed, provide justification, and activate the role for a limited period.

Which configuration best meets these requirements?

A. Assign the role permanently as active and require multifactor authentication at every sign-in.

B. Create eligible assignments, configure activation requirements, and set a maximum activation duration.

C. Assign the role through an Azure Policy initiative and configure a resource lock.

D. Create a Conditional Access policy that blocks all users outside the corporate network.

Answer: B

Explanation: Eligible assignments allow users to activate a role when required rather than having permanent active privileges. PIM can require justification, multifactor authentication, approval, and a limited activation duration, depending on the role and configuration.

Conditional Access can add authentication and access restrictions, but it does not replace PIM’s eligible-assignment and activation workflow. Azure Policy and resource locks govern Azure resources, not Microsoft Entra privileged-role activation.


Question 2 — Authentication Methods

A company wants employees to sign in using phishing-resistant authentication. The security team wants to prioritize a method that does not rely on a password and is designed to resist credential phishing.

Which option is the best fit?

A. SMS one-time passcodes

B. Email one-time passcodes

C. Security questions

D. Passkeys using FIDO2 security keys

Answer: D

Explanation: FIDO2 security keys and supported passkey implementations provide phishing-resistant authentication. Authentication is cryptographically bound to the legitimate relying party, helping prevent credentials from being reused on a fraudulent website.

SMS and email codes can be vulnerable to phishing or interception, and security questions are not a strong authentication method.

Exam tip: Distinguish between merely adding another authentication step and using a phishing-resistant authentication method.


Question 3 — Azure RBAC and Least Privilege

A developer must restart virtual machines in a specific resource group. The developer must not be able to create virtual machines, modify network security groups, or assign roles to other users.

Which approach best follows least privilege?

A. Assign Owner at the subscription scope.

B. Assign Contributor at the subscription scope.

C. Assign a suitable narrowly scoped role that permits the required VM restart operation at the resource group or resource scope.

D. Assign User Access Administrator at the resource group scope.

Answer: C

Explanation: Azure RBAC assignments should grant only the required actions at the narrowest practical scope. A suitable built-in role or custom role can permit VM restart operations without granting broad resource-management or role-assignment permissions.

Owner and Contributor are too broad for this requirement. User Access Administrator focuses on managing access assignments rather than restarting VMs.


Question 4 — Scenario: Azure Policy and Resource Locks

A production resource group contains a critical Azure resource. The organization wants to accomplish two things:

  1. Prevent accidental deletion of the resource.
  2. Require newly deployed storage accounts to use secure transfer.

Which combination of controls should be used?

A. A CanNotDelete resource lock and an Azure Policy definition enforcing secure transfer.

B. A ReadOnly resource lock and a Microsoft Sentinel automation rule.

C. A PIM eligible assignment and a Key Vault certificate.

D. A Defender for Cloud recommendation and a network security group.

Answer: A

Explanation: A CanNotDelete lock prevents deletion while allowing permitted modifications. Azure Policy can audit or deny storage-account configurations that do not meet the secure-transfer requirement.

A ReadOnly lock is more restrictive and can prevent many write operations. Sentinel automation rules and PIM do not directly enforce these two resource requirements.

Important distinction: Resource locks protect resources from certain management operations. Azure Policy evaluates and enforces resource configuration requirements.


Question 5 — Fill in the Blank: Azure Resource Access

An application hosted on an Azure resource must access Azure Key Vault without embedding a client secret in its code. The application should authenticate using an identity managed by Azure.

The capability to configure is a __________ identity.

A. guest

B. managed

C. consumer

D. shared

Answer: B. managed

Explanation: Managed identities provide Azure resources with identities that can authenticate to supported services. Azure manages the credentials, reducing the need to store and rotate application secrets.

Authentication alone does not grant access to Key Vault. The managed identity must also receive the appropriate authorization, such as a suitable Key Vault data-plane role when using Azure RBAC authorization.


Question 6 — Multiple Answer: Azure Backup Security

An organization wants to strengthen the security of its Azure Backup recovery points against accidental or malicious deletion.

Which two controls should the security team consider?

A. Configure Azure Bastion for all backup vaults.

B. Enable Microsoft Sentinel syslog collection.

C. Use Azure Backup security features such as soft delete and, where supported, immutability.

D. Configure Multi-User Authorization (MUA) for supported critical backup operations.

Answer: C and D

Explanation: Azure Backup provides several layers of protection for recovery points and critical operations.

  • Soft delete helps protect backup data from accidental or malicious deletion by retaining deleted backup data for a configured or service-defined period.
  • Immutability, where supported and appropriately configured, helps prevent protected backup data from being modified or deleted.
  • Multi-User Authorization (MUA) adds an approval layer for supported critical operations, reducing the risk of a single compromised administrator destroying backups.

Bastion is for secure VM administration. Syslog collection supports monitoring but does not itself protect recovery points.


Question 7 — Scenario: Securing an API Plugin


A developer is building an API plugin for a declarative agent. The API accesses confidential business data and must verify the identity of the caller. The team wants delegated access so that the API can act within the signed-in user’s permitted access.

Which authentication approach most directly supports this requirement?

A. Publish the API without authentication and rely on network restrictions.

B. Embed a shared administrator password in the plugin definition.

C. Use a managed identity for the API and assume it automatically represents every user’s delegated permissions.

D. Configure an appropriate Microsoft identity platform OAuth authentication flow with delegated permissions and consent.

Answer: D

Explanation: OAuth-based authentication with delegated permissions allows an application to access an API on behalf of a signed-in user, within the granted permissions and consent framework.

A managed identity can authenticate an Azure-hosted workload as itself, but it does not automatically represent the user’s delegated permissions. Network restrictions are useful defense in depth, not a replacement for API authentication and authorization.


Section 2: Secure Storage, Databases, and Networking


Question 8 — Scenario: Azure Storage Network Restrictions

A company stores confidential files in an Azure Storage account. Only clients on approved corporate networks should be able to connect to the storage service. The security team also wants to retain identity-based authorization for users accessing blobs.

Which configuration best meets these requirements?

A. Enable anonymous blob access and use Azure Policy to audit downloads.

B. Assign Storage Blob Data Contributor to all employees and rely on storage-account keys for network restrictions.

C. Configure the storage firewall to allow approved network paths and use Microsoft Entra ID-based authorization with appropriate data-plane permissions.

D. Enable Microsoft Defender for Storage and leave the storage account’s network access unrestricted.

Answer: C

Explanation: The storage firewall or network access settings restrict which network paths can reach the storage account. Microsoft Entra ID-based authorization and appropriate data-plane roles control what an authenticated identity can do with blob data.

Defender for Storage provides additional threat protection, but it does not replace network restrictions or authorization.


Question 9 — Multiple Answer: Azure SQL Security

A financial application uses Azure SQL Database. Auditors require a record of database activity, and the security team wants to detect suspicious database behavior and potential threats.

Which two capabilities should be configured?

A. Azure SQL auditing

B. Azure Bastion

C. Microsoft Defender for Databases

D. Azure Firewall Manager only

Answer: A and C

Explanation:

  • Azure SQL auditing records database events to support investigation, accountability, and compliance.
  • Microsoft Defender for Databases adds database threat-protection capabilities and can surface suspicious activities and security recommendations.

Bastion provides secure administrative access to VMs. Azure Firewall Manager manages firewall deployments and policies, not SQL auditing.


Question 10 — Scenario: Network Security Groups

An application has a web tier and a database tier in separate subnets. The database must accept connections from the web tier on TCP port 1433 but must not accept direct connections from the internet.

Which design is most appropriate?

A. Assign a public IP address to the database and use a broad outbound NSG rule.

B. Use an NSG rule to allow the required database traffic from the web tier, with other inbound traffic denied by the applicable rules.

C. Configure Azure Bastion to forward all application traffic to the database.

D. Enable Microsoft Defender for SQL and remove the database subnet’s network controls.

Answer: B

Explanation: Network security groups filter inbound and outbound traffic using rules that specify source, destination, port, protocol, and priority. An appropriately scoped rule can allow the web tier to connect to the database while blocking other unwanted connections.

NSGs are stateful, and their rules are evaluated by priority. Ensure that the effective rules and network architecture actually prevent direct internet access; simply adding an allow rule is not enough.


Question 11 — Matching: Private Connectivity

Match each Azure networking capability to its primary purpose.

CapabilityPurpose
1. Azure Private EndpointA. Encrypted connectivity between networks over a VPN
2. Azure VPN GatewayB. Filter traffic using network security rules at a subnet or network interface
3. Network Security GroupC. Provide a private IP-based connection to a supported service
4. Azure FirewallD. Centralized network traffic inspection and filtering

Answer

  • 1 → C
  • 2 → A
  • 3 → B
  • 4 → D

Explanation: A private endpoint maps a supported service to a private IP address in a virtual network. VPN Gateway provides VPN connectivity. NSGs filter network traffic at subnet or network-interface scope. Azure Firewall provides centralized network traffic filtering and inspection.

Exam trap: Private Link, VPN Gateway, NSGs, and Azure Firewall are complementary controls, not interchangeable services.


Question 12 — Scenario: Azure Key Vault Authorization

An application can successfully authenticate to Azure Key Vault using its managed identity, but it receives an authorization error when attempting to retrieve a secret. The vault uses Azure role-based access control for its data plane.

What should the administrator do?

A. Assign the managed identity an appropriate Key Vault data-plane role, such as Key Vault Secrets User, at the appropriate scope.

B. Assign the managed identity Reader at the subscription scope.

C. Enable Azure Bastion on the Key Vault.

D. Create a Sentinel playbook that retries the secret request.

Answer: A

Explanation: Authentication establishes the identity; authorization determines what that identity can access. With the Azure RBAC permission model, retrieving secrets requires an appropriate data-plane role, such as Key Vault Secrets User, at a suitable scope.

The Reader role generally provides control-plane read access to Azure resources; it does not grant permission to read secret values. A playbook cannot correct a missing authorization assignment.


Question 13 — Multiple Answer: Azure SQL Data Protection

A company wants to protect sensitive information in Azure SQL Database. Its requirements include encrypting stored database data and maintaining an audit trail of database activity.

Which two features best address these requirements?

A. Azure Bastion and JIT VM access

B. Azure Private Link and NSGs only

C. Microsoft Sentinel automation rules and Azure Policy only

D. Transparent Data Encryption (TDE) and Azure SQL auditing

Answer: D

Explanation: TDE encrypts database files and associated data at rest. Azure SQL auditing records selected database events for security investigation and compliance.

These controls address different objectives: encryption protects data at rest, while auditing supports accountability and investigation. Neither feature alone replaces identity controls, network security, or other data-protection measures.


Question 14 — Fill in the Blank: Azure Network Diagnostics

An administrator wants to determine which network security rules apply to a network interface and investigate why traffic is being allowed or denied.

The administrator should use Azure Network Watcher __________ security rules.

A. export

B. effective

C. privileged

D. delegated

Answer: B. effective

Explanation: Azure Network Watcher provides tools for examining effective security rules on a network interface. These help administrators understand the combined effect of applicable NSG rules and troubleshoot connectivity.

This is particularly useful when subnet-level and network-interface-level rules interact.


Question 15 — Scenario: Azure Private Link

An organization hosts a database service that supports Azure Private Link. The company wants clients in a virtual network to connect using a private IP address and wants to disable public network access where the service supports that configuration.

Which approach is most appropriate?

A. Create a public IP address and restrict access using a password.

B. Configure an NSG without creating a private connection to the service.

C. Create a private endpoint, configure the required name resolution, and disable public network access if supported and required.

D. Enable Microsoft Defender for Databases and assume the service no longer has a public endpoint.

Answer: C

Explanation: A private endpoint provides private IP-based connectivity to a supported service. Correct DNS configuration is important so that clients resolve the service name to the intended private endpoint. Where supported, disabling public network access provides an additional control.

A private endpoint does not automatically mean the public endpoint is disabled; that must be configured separately when the service supports it.


Section 3: Secure Compute


Question 16 — Scenario: Trusted Launch and Disk Encryption

A company is deploying a new Azure VM for a sensitive workload. The security team requires protection against boot-level attacks and encryption of data stored on the VM’s disks.

Which combination most directly addresses both requirements?

A. Azure Bastion and Microsoft Sentinel

B. Trusted Launch and an appropriate VM disk-encryption configuration

C. Azure Policy and Microsoft Entra PIM only

D. A network security group and a public IP address

Answer: B

Explanation: Trusted Launch provides VM security features such as Secure Boot and virtual TPM. Disk encryption protects data stored on supported VM disks.

These controls protect different layers. Trusted Launch does not, by itself, mean that all disk-encryption requirements have been met.


Question 17 — Multiple Answer: Azure Kubernetes Service

A security team is reviewing an Azure Kubernetes Service (AKS) deployment. It wants to reduce workload exposure and improve container security.

Which two actions are appropriate?

A. Review and apply AKS network and workload-isolation controls.

B. Enable Microsoft Defender for Containers for relevant protection and security insights.

C. Give every workload cluster Owner permissions on the subscription.

D. Make all container images publicly accessible to simplify deployment.

Answer: A and B

Explanation: AKS security is layered. Network policies and appropriate isolation controls help restrict workload communication, while Defender for Containers provides security capabilities for containerized environments.

Broad subscription permissions and publicly exposing container images increase risk rather than reducing it.


Question 18 — Scenario: Just-in-Time VM Access

Administrators need occasional RDP access to a group of Azure VMs. Security policy requires that management ports not remain unnecessarily exposed and that access requests be time-limited.

Which capability best meets this requirement?

A. Azure Storage firewall rules

B. Microsoft Purview DSPM

C. Azure SQL auditing

D. Just-in-time (JIT) VM access

Answer: D

Explanation: JIT VM access reduces persistent exposure of management ports by allowing access to be requested for a limited time under configured conditions. It is commonly used to reduce exposure of ports such as RDP and SSH.

JIT is not a replacement for identity authorization, network controls, or monitoring, but it directly addresses the requirement for time-limited management-port access.


Question 19 — Scenario: Azure App Service and Web Traffic

A company hosts a public web application on Azure App Service. The security team wants to protect the application from common web attacks, including malicious HTTP requests that match known attack patterns.

Which option is the best fit when the design calls for a Web Application Firewall (WAF)?

A. Azure Machine Configuration

B. Azure Backup soft delete

C. A supported WAF deployment, such as Azure Application Gateway WAF or Azure Front Door WAF, positioned to inspect the application’s web traffic

D. Microsoft Entra PIM

Answer: C

Explanation: A WAF can inspect HTTP(S) traffic and help protect web applications against common web exploits. The appropriate WAF product and deployment pattern depend on the application’s ingress architecture and requirements.

PIM controls privileged identity access, Azure Machine Configuration assesses or enforces machine configuration, and Backup soft delete protects backup data.


Question 20 — Matching: Application and Container Security

Match each technology or capability with its primary purpose.

TechnologyPurpose
1. Microsoft Defender for ContainersA. Secure API access, traffic policies, and backend integration
2. Azure API ManagementB. Assess or enforce supported machine configuration settings
3. Azure Machine ConfigurationC. Detect container-related risks and provide container security capabilities
4. Azure BastionD. Secure administrative access to Azure VMs

Answer

  • 1 → C
  • 2 → A
  • 3 → B
  • 4 → D

Explanation: Defender for Containers supports container security. API Management helps secure and govern APIs and their backend access. Azure Machine Configuration helps assess and enforce supported configuration settings on machines. Bastion provides secure RDP/SSH access to VMs.


Question 21 — Scenario: AI Guardrails

A company deploys an AI application using Microsoft Foundry. Testing reveals that the model sometimes returns harmful content and can be manipulated by adversarial prompts. The company wants to apply configurable controls to evaluate prompts and responses.

Which approach is most appropriate?

A. Enable Azure Bastion and restrict RDP access.

B. Configure and test appropriate Foundry guardrails, including relevant content filters and Prompt Shields.

C. Enable Azure SQL auditing.

D. Assign the AI application the Contributor role at the subscription scope.

Answer: B

Explanation: Microsoft Foundry guardrails can evaluate model interactions and apply controls such as content filters, blocklists, and Prompt Shields. The appropriate controls should be configured and validated against the application’s risk profile.

Guardrails help mitigate unsafe interactions and prompt-injection risks, but they do not eliminate all AI risks. Identity, data access, monitoring, and application-layer controls remain necessary.


Question 22 — Multiple Answer: AI Identity and Data Security

An organization has deployed AI agents that can access Microsoft 365 data and Azure resources. Security wants to assess risks caused by excessive agent permissions and overexposed organizational data.

Which two actions are appropriate?

A. Use Microsoft Defender XDR to investigate AI agent identities and assess potential blast radius.

B. Enable anonymous access to SharePoint so that agents do not need authorization.

C. Use Microsoft Purview Data Security Posture Management to identify relevant AI data risks and overexposure.

D. Replace all agent identities with a single shared administrator account.

Answer: A and C

Explanation: Microsoft Defender XDR can help discover AI agents and analyze identity-related risks and attack paths. Microsoft Purview DSPM helps identify data security risks associated with AI usage and data exposure.

Shared administrator accounts and anonymous access undermine least privilege and make it harder to establish accountability. Microsoft’s current AI security learning path covers both Entra Agent ID risk analysis and Purview DSPM for AI data risks.


Question 23 — Fill in the Blank: AI Traffic Security

An organization wants to apply centralized security and governance controls to model traffic for AI applications built with Microsoft Foundry. The relevant capability in the SC-500 learning path is AI Gateway in Azure __________ Management.

A. Identity

B. Storage

C. Firewall

D. API

Answer: D. API

Explanation: The SC-500 AI security learning path covers configuring AI Gateway in Azure API Management for Microsoft Foundry. The gateway can provide a centralized point for applying access restrictions, governance, and monitoring to AI model traffic.

AI Gateway complements other controls, including agent identity security, Foundry guardrails, and Defender for Cloud workload protection.


Section 4: Manage and Monitor Security Posture


Question 24 — Scenario: Prioritizing Cloud Security Risks

A security team uses Microsoft Defender for Cloud to assess hundreds of security recommendations. The team wants to identify issues that could contribute to a realistic attack path to a critical database, rather than simply fixing recommendations in alphabetical order.

Which capability is most appropriate?

A. Azure Backup soft delete

B. Microsoft Entra password protection

C. Defender CSPM attack path analysis

D. Microsoft Sentinel workspace retention

Answer: C

Explanation: Defender CSPM attack path analysis helps identify chains of security issues that could expose important resources to attack. It provides context for prioritizing risks based on potential attack paths rather than treating every recommendation as equally urgent.

For example, an internet-exposed workload with excessive permissions and access to a sensitive database may deserve higher priority than an isolated configuration issue. Attack path analysis and Cloud Security Explorer are covered in Microsoft’s Defender for Cloud learning path.


Question 25 — Multiple Answer: Microsoft Sentinel Data Collection

A company is onboarding network security appliances and Windows servers to Microsoft Sentinel. The appliances can send Common Event Format (CEF) messages, while Windows servers use Windows Event Forwarding (WEF).

Which two statements are correct?

A. CEF collection and Windows Security event collection using DCRs are distinct ingestion configurations.

B. Enabling a Sentinel automation rule automatically configures every appliance to send logs.

C. WEF eliminates the need to configure the appropriate data collection path into Azure Monitor and Sentinel.

D. A Sentinel playbook must be used to parse every CEF message before it can be ingested.

Answer: A

Explanation: CEF and Windows Security events use different collection configurations. For Windows Security events, DCRs can define which events are collected, including scenarios involving WEF. CEF collection requires the appropriate forwarding and ingestion setup for the source appliance.

Automation rules and playbooks help automate security operations; they do not automatically configure log sources or replace ingestion pipelines.

Important: This is a multiple-answer-style question, but only A is correct as written. In a live exam, always follow the number of answers requested and evaluate each option independently.


Question 26 — Scenario: Defender for Cloud Multicloud Coverage

An organization has workloads in Azure and AWS. The security team can see Azure recommendations in Defender for Cloud but does not have the expected security posture visibility for its AWS environment.

What should the team do first?

A. Deploy Azure Bastion in the AWS account.

B. Configure the appropriate AWS connector and required integration settings in Defender for Cloud, then verify the connected resources and enabled capabilities.

C. Create an Azure Policy assignment directly on the AWS resources.

D. Enable Microsoft Sentinel’s Windows Security Events connector.

Answer: B

Explanation: Defender for Cloud can integrate with AWS to provide security posture visibility and, depending on the configured plans and integration, workload protection. The security team should configure the appropriate connector, authentication, scope, and required plans, then verify that the intended resources are covered.

Azure Policy does not directly govern AWS resources in the same way it governs Azure resources. A Sentinel Windows event connector does not establish Defender for Cloud’s AWS integration.


Question 27 — Matching: Security Posture Tools

Match each capability with the task it most directly supports.

CapabilityTask
1. Defender CSPMA. Assess compliance against regulatory frameworks and identify control gaps.
2. Defender for Cloud regulatory complianceB. Discover and investigate external attack-surface exposure
3. Microsoft Defender EASMC. Assess cloud posture and prioritize security risks
4. Microsoft Defender for Servers vulnerability assessmentD. Identify vulnerabilities on covered servers and VMs

Answer

  • 1 → C
  • 2 → A
  • 3 → B
  • 4 → D

Explanation: These tools support related but different security outcomes:

  • Defender CSPM identifies posture issues and helps prioritize risk.
  • Regulatory compliance evaluates the environment against selected security standards and frameworks.
  • Defender EASM discovers and assesses externally visible assets.
  • Defender for Servers vulnerability assessment identifies vulnerabilities on covered servers and VMs.

Question 28 — Scenario: Security Copilot Agent Permissions

A company wants to deploy a partner-built agent from Microsoft Security Store. During setup, the agent requests permissions to access Microsoft security product data. The agent cannot be fully configured until the required permissions are approved.

Which action should the organization expect to take?

A. Grant the agent unrestricted subscription Owner access without reviewing its requested permissions.

B. Disable all Microsoft Entra authentication requirements for the agent.

C. Remove all plugins and assume the agent will retain its original capabilities.

D. Have an appropriately authorized Global Administrator review and approve the required Microsoft product permissions, then complete the remaining setup using an authorized Security Copilot role.

Answer: D

Explanation: Partner-built Security Copilot agents that require access to Microsoft product data can require Global Administrator approval of their requested permissions. The administrator should review the requested permissions and approve only as appropriate. An authorized Security Copilot Owner or Contributor can then complete the remaining setup steps.

The key principle is to review and approve permissions deliberately rather than granting broad access by default. Acquiring a partner agent and configuring its operational permissions are related but distinct steps.


Question 29 — Fill in the Blank: Defender for Cloud AI Protection

A company wants to secure AI workloads through Microsoft Defender for Cloud. The team wants to review AI-related security posture insights, detect runtime threats, and investigate security alerts.

The Microsoft Defender for Cloud dashboard specifically associated with these AI-related posture insights is the Data & __________ security dashboard.

A. Identity

B. Network

C. AI

D. Backup

Answer: C

Explanation: The dashboard is called the Data & AI security dashboard. It helps teams review insights related to AI security posture.

Defender for Cloud AI workload protection also involves enabling the appropriate AI protection plan, assessing posture through CSPM, detecting runtime threats through workload protection, and investigating incidents in Microsoft Defender XDR.


Question 30 — Scenario: Investigating a Suspicious AI Agent

An organization detects an AI agent that appears to have access to more resources than it needs. The security team wants to understand which resources could be affected if the agent’s identity were compromised and whether the agent has risky paths to sensitive data.

Which approach is most appropriate?

A. Use Microsoft Defender XDR to discover the agent and investigate its identity-related risks and potential blast radius.

B. Use Azure Storage lifecycle management to delete old files.

C. Use Azure Bastion to rotate the agent’s permissions.

D. Use Azure SQL auditing as the sole tool for analyzing all agent identity relationships.

Answer: A

Explanation: Microsoft Defender XDR can help security teams discover AI agents and investigate identity-related risks, including potential blast radius and attack paths. This helps determine which resources or data might be exposed if an agent identity is compromised.

The investigation should be followed by remediation, such as reducing excessive permissions, correcting access assignments, and reviewing the agent’s identity lifecycle. Microsoft’s current AI security learning path specifically covers discovering AI agents and assessing their blast radius.


What to review after this exam

Focus especially on the distinctions that commonly drive scenario questions:

  • Authentication vs. authorization: successful sign-in does not automatically grant access to Key Vault or other resources.
  • Azure Policy vs. resource locks: configuration governance is different from protection against resource deletion or modification.
  • Private endpoints vs. public access: creating a private endpoint does not necessarily disable a service’s public endpoint.
  • Trusted Launch vs. disk encryption: boot integrity and encryption at rest solve different problems.
  • Defender CSPM vs. workload protection: posture management identifies and prioritizes weaknesses; workload protection detects threats to supported workloads.
  • Sentinel ingestion vs. automation: connectors and collection configurations bring logs into the workspace; automation rules and playbooks support response workflows.
  • AI guardrails vs. AI identity controls: guardrails evaluate model interactions, while identity and access controls govern which resources an agent can reach.

Go to the SC-500 Exam Prep Hub main page

SC-500 Practice Exam #3

This practice exam is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.

Implementing End-to-End Security Controls for Cloud and AI Workloads


Section 1 — Manage identity, access, and governance


Question 1 — Privileged Identity Management (PIM)

A security administrator has a standing Owner role assignment at the subscription level. The organization wants to reduce standing privileges while allowing the administrator to perform emergency configuration changes when necessary. The administrator should provide justification, complete multifactor authentication, and have the activation approved by another administrator.

Which configuration best meets these requirements?

A. Assign the Contributor role permanently and use an Azure Policy exemption for emergency changes.

B. Create a custom Azure role and assign it permanently at the management group scope.

C. Convert the Owner assignment to an eligible PIM assignment and configure approval, justification, and MFA requirements for activation.

D. Create a resource lock and configure an alert to notify the security team whenever the administrator changes a resource.

Correct answer: C

Explanation: Microsoft Entra Privileged Identity Management (PIM) supports eligible role assignments that users activate only when needed. Activation requirements can include justification, MFA, and approval. This reduces standing privileged access while retaining a controlled emergency-access process. A resource lock or policy exemption does not replace privileged access management.


Question 2 — Azure Key Vault protection

A company stores encryption keys and application secrets in Azure Key Vault. Its security policy requires that deleted secrets and keys cannot be permanently purged by an administrator before the configured retention period expires, even if the administrator has elevated permissions.

Which setting most directly enforces this requirement?

A. Enable purge protection.

B. Enable diagnostic settings and send audit logs to Log Analytics.

C. Configure a private endpoint for the vault.

D. Assign the Key Vault Reader role to all administrators.

Correct answer: A

Explanation: Purge protection prevents a deleted vault object from being permanently purged during its retention period. Soft delete retains deleted objects for recovery; purge protection prevents early permanent deletion. Diagnostic logging, private endpoints, and reader permissions serve different security purposes.


Question 3 — Conditional Access for AI agent identities

An organization deploys dozens of autonomous AI agents using Microsoft Entra Agent ID. All agents created from a particular agent identity blueprint must be blocked from accessing corporate APIs if they are identified as high risk. New agents created from that blueprint must automatically receive the same protection.

What should the security engineer configure?

A. A Conditional Access policy targeting all human users and requiring MFA.

B. An Azure Policy definition that audits agent registrations.

C. An access review that periodically checks the agents’ API permissions.

D. A Conditional Access policy targeting the relevant agent identity blueprint, with a control that blocks access when the configured risk condition is met.

Correct answer: D

Explanation: Conditional Access can target agent identities and agent identity blueprints. A policy applied to a blueprint covers agent identities derived from it, including future agents. Risk-based controls can block access when the applicable risk condition is met. The policy must target the correct identity type; a policy targeting human users does not automatically cover agent identities.


Question 4 — Azure Policy versus resource locks

A team manages production resources in Azure. Security requirements state that storage accounts must have secure transfer enabled and that a specific production database must not be deleted accidentally.

Which combination best addresses both requirements?

A. Assign the Reader role to the application team and enable diagnostic logging on the database.

B. Use Azure Policy to enforce or audit the secure-transfer configuration, and apply a CanNotDelete resource lock to the database.

C. Apply a ReadOnly lock to the subscription and use a management group to enable secure transfer.

D. Use Microsoft Defender for Cloud recommendations to block storage configuration changes and assign the database the Contributor role.

Correct answer: B

Explanation: Azure Policy evaluates resource configurations against defined rules and can audit, deny, or remediate supported configurations. A CanNotDelete lock prevents deletion while allowing authorized modifications. A ReadOnly lock is more restrictive and can prevent updates. Defender for Cloud provides posture recommendations, but recommendations alone do not enforce these controls.


Question 5 — Least-privilege access to Azure resources

A deployment operator needs to start and stop virtual machines in one resource group. The operator must not create virtual machines, change their networking, modify role assignments, or access other resource groups.

Which TWO approaches best support least privilege?

A. Assign Owner at the subscription scope and use activity logs to detect excess permissions.

B. Assign Contributor at the resource-group scope and ask the operator not to modify networking.

C. Create or use a role that includes the required virtual machine start/stop actions, and assign it at the narrowest suitable scope.

D. Assign a suitable built-in virtual machine operator role at the target resource-group scope, after verifying that its permitted actions meet the requirements.

Correct answers: C and D

Explanation: Least privilege means granting only the permissions needed at the narrowest appropriate scope. A custom role can precisely define allowed actions, while a suitable built-in role may already provide the required permissions. The role’s actual actions and any applicable data-plane permissions should be checked before assignment. Owner and Contributor are broader than the stated requirement.


Question 6 — OAuth permissions and consent

A developer registers an application that calls Microsoft Graph on behalf of signed-in employees. The application requests delegated permissions that allow it to read users’ files. The security team wants to minimize the risk of excessive access being granted during application consent.

Which action is most appropriate?

A. Review the requested delegated permissions and configure consent policies so that only approved permissions and appropriate consent workflows are allowed.

B. Assign the application the Global Administrator role so it can request consent without interruption.

C. Enable public network access for the application registration.

D. Create a resource lock on the application registration and assume that this prevents overprivileged consent.

Correct answer: A

Explanation: Delegated permissions allow an application to act on behalf of a signed-in user within the permissions granted to it and the user. Reviewing requested permissions and controlling user and administrator consent helps prevent excessive access. Global Administrator is not an appropriate default application permission, and resource locks do not control OAuth consent.


Question 7 — Protecting backup data

A company is concerned that an attacker who compromises an administrator account could delete recovery points and then encrypt the production environment. The company wants to strengthen the resilience of its Azure Backup data against destructive administrative actions.

Which approach is most appropriate?

A. Store backup logs in the same production virtual machine that is being protected.

B. Give all backup operators the Backup Contributor and Owner roles at the subscription level.

C. Rely exclusively on Azure Policy to prevent all possible backup deletions, without reviewing the backup configuration.

D. Configure the applicable Azure Backup security features, including immutable vault protection where supported, and restrict privileged backup operations using least-privilege access and appropriate safeguards.

Correct answer: D

Explanation: Backup resilience depends on multiple layers: restricting privileged operations, protecting backup configuration, and enabling supported immutability and deletion safeguards. Exact capabilities vary by workload and vault configuration, so verify which protections are supported for the protected data source. Broad administrative roles and co-locating logs with production workloads do not adequately protect recovery points.


Section 2 — Secure storage, databases, and networking


Question 8 — Eliminate public exposure of Azure Storage

A storage account contains confidential documents used by an application hosted in an Azure virtual network. The application must continue to access the storage account, but the company wants to eliminate access through the storage account’s public network endpoint.

Which configuration best meets the requirement?

A. Allow all public IP addresses in the storage firewall and require HTTPS.

B. Configure a private endpoint, ensure the application resolves the storage account name to the private endpoint IP address, and disable public network access after validating the private connectivity.

C. Create an NSG rule that blocks inbound traffic to the storage account’s public endpoint.

D. Enable Microsoft Defender for Storage and leave the public network endpoint enabled.

Correct answer: B

Explanation: Azure Private Link provides private connectivity to supported Azure services through a private endpoint in a virtual network. Correct DNS configuration is essential so the application resolves the service name to the private IP address. Disabling public network access removes the public access path; Defender for Storage detects threats but does not itself remove public exposure.


Question 9 — Secure access to Azure Storage

A data-processing application needs temporary access to blobs in an Azure Storage account. The organization wants to avoid distributing the storage account key and wants to issue a time-limited token using Microsoft Entra credentials.

Which option is the best fit?

A. Embed the storage account access key in the application’s source code and rotate it every month.

B. Assign the application the Owner role at the subscription level.

C. Make the container public and rely on application-level authentication.

D. Use a user delegation SAS, generated using Microsoft Entra credentials, and restrict its permissions and validity period to the required operations.

Correct answer: D

Explanation: A user delegation SAS is signed using a user delegation key obtained through Microsoft Entra authorization rather than a storage account key. The SAS should have only the necessary permissions and a limited validity period. It remains a bearer token, so it must be protected against disclosure. Public containers and embedded account keys increase exposure.


Question 10 — Detect threats against Azure Storage

A company uses Azure Blob Storage to receive files from external partners. The security team wants threat detection that can identify suspicious storage activity and malware in uploaded files, using Microsoft Defender’s storage protections where supported.

What should the team implement?

A. Enable Microsoft Defender for Storage and configure the relevant malware-scanning and threat-detection capabilities for the storage environment.

B. Enable Azure SQL auditing on the storage account.

C. Assign the Storage Blob Data Reader role to every external partner.

D. Configure a ReadOnly resource lock on the storage account.

Correct answer: A

Explanation: Microsoft Defender for Storage provides security monitoring and threat detection for supported storage workloads. Its capabilities include identifying suspicious activities and, where configured and supported, scanning uploaded blobs for malware. SQL auditing applies to SQL services, while RBAC and resource locks do not provide malware detection.


Question 11 — Azure SQL auditing

A security operations team needs to investigate who accessed an Azure SQL Database, what database activities occurred, and when suspicious operations took place. The team wants to query the audit records centrally alongside other security events.

Which configuration best meets the requirement?

A. Enable Transparent Data Encryption (TDE) and use its encryption status as an audit trail.

B. Enable a database resource lock and review Azure Resource Health.

C. Configure Azure SQL auditing to send audit events to a suitable destination, such as Log Analytics, and query the collected records.

D. Enable SQL authentication for every user and rely on application logs alone.

Correct answer: C

Explanation: Azure SQL auditing records selected database events and can send audit data to supported destinations, including Log Analytics. Central collection enables investigation and correlation with other security information. TDE protects data at rest; it does not replace activity auditing.


Question 12 — Troubleshoot network security rules

A virtual machine cannot receive traffic from an approved application subnet. The network team believes an NSG rule allows the traffic, but the connection still fails. The team wants to determine which network security rules are effectively applied to the VM’s network interface.

Which tool should the team use first?

A. Microsoft Defender External Attack Surface Management.

B. Azure Network Watcher IP flow verify or effective security rules, selecting the appropriate feature to test the traffic or inspect the applied rules.

C. Azure Key Vault diagnostic settings.

D. Microsoft Purview Data Security Posture Management.

Correct answer: B

Explanation: Network Watcher provides diagnostic tools for Azure network connectivity. IP flow verify can determine whether a particular traffic flow is allowed or denied and identify the relevant rule. Effective security rules show the aggregate rules applied to a network interface. The choice depends on whether the team needs a specific flow decision or a complete view of applied rules.


Question 13 — Centralized outbound traffic inspection

An organization has several application subnets. It must centrally inspect outbound traffic and restrict access to specified fully qualified domain names (FQDNs), including when applications use changing destination IP addresses. The solution should reduce duplicated outbound filtering rules across subnets.

Which service is the most appropriate?

A. Azure Network Security Groups alone.

B. Azure Private Link.

C. Azure Bastion.

D. Azure Firewall with suitable application rules and a routing design that directs the relevant outbound traffic through the firewall.

Correct answer: D

Explanation: Azure Firewall supports centralized traffic filtering, including application rules based on FQDNs, when the relevant traffic is routed through it. NSGs filter traffic using network-layer attributes such as IP addresses, ports, and protocols; they do not provide equivalent centralized FQDN-based application filtering. Private Link and Bastion solve different problems.


Question 14 — Private endpoint DNS

An application connects to an Azure SQL logical server through a private endpoint. The private endpoint has been created successfully, and the application can reach other resources in its virtual network. However, the SQL hostname still resolves to a public IP address.

What should the engineer investigate first?

A. Whether the appropriate Private DNS zone is configured, linked to the virtual network, and contains the expected private endpoint DNS records.

B. Whether the application has the Azure Owner role.

C. Whether Microsoft Defender for Servers is enabled.

D. Whether the SQL database has Transparent Data Encryption enabled.

Correct answer: A

Explanation: Private endpoint connectivity typically relies on DNS resolution to map the service hostname to the private endpoint’s IP address. A correctly configured private DNS zone and virtual network link are common requirements. Database encryption and VM security settings do not fix an incorrect DNS resolution path.


Question 15 — Azure SQL vulnerability assessment

A security engineer must identify potential database misconfigurations and vulnerabilities, review findings against security baselines, and track recommendations for remediation. The organization also wants to detect suspicious database activities.

Which approach best addresses both needs?

A. Use TDE for vulnerability discovery and NSGs for SQL auditing.

B. Use Azure resource locks to identify database vulnerabilities and Azure Policy to record each query.

C. Use Microsoft Defender for Databases for supported database threat protection and vulnerability-assessment capabilities, configuring the relevant settings and reviewing findings.

D. Enable public access to the database so that the security scanner can reach it from anywhere.

Correct answer: C

Explanation: Microsoft Defender for Databases provides supported database security capabilities, including threat detection and vulnerability-assessment functionality, depending on the database type and configuration. Findings help identify weaknesses and prioritize remediation. TDE protects data at rest, while resource locks and NSGs are not substitutes for database security assessment.


Section 3 — Secure compute


Question 16 — Azure VM Trusted Launch

A company wants to strengthen the boot integrity of supported Azure virtual machines. Its requirements include protection against bootkits and verification of the boot chain, together with a virtualized hardware root of trust for supported security scenarios.

Which configuration is the best fit?

A. Enable Trusted Launch with Secure Boot and virtual TPM (vTPM), after verifying that the VM size, image, and operating system support it.

B. Enable Azure Bastion and disable the VM’s operating system updates.

C. Enable Azure Disk Encryption and assume that it prevents bootkits.

D. Assign the VM a managed identity and remove all network security groups.

Correct answer: A

Explanation: Trusted Launch adds security features such as Secure Boot and vTPM for supported Azure VMs. Secure Boot helps prevent unauthorized boot components from loading, while vTPM provides a protected virtualized hardware trust capability. Disk encryption protects data at rest but does not provide the same boot-integrity controls.


Question 17 — Secure workload identity in AKS

An application running in Azure Kubernetes Service (AKS) must access a specific Azure Key Vault. The security team wants to avoid storing long-lived service principal credentials in Kubernetes secrets and wants the workload to obtain Microsoft Entra tokens using a federated identity configuration.

Which approach should the team use?

A. Place a subscription Owner credential in a Kubernetes secret and mount it into the pod.

B. Enable anonymous access to Key Vault and filter requests in application code.

C. Configure Microsoft Entra Workload ID for AKS, use the appropriate federated identity credential and Kubernetes service account, and grant the workload identity only the necessary Key Vault permissions.

D. Give every node in the cluster the same permanent client secret.

Correct answer: C

Explanation: Microsoft Entra Workload ID for AKS uses workload identity federation so Kubernetes workloads can authenticate to Microsoft Entra ID without managing long-lived application secrets. The federated credential links the Kubernetes service account identity to the Entra application or managed identity. Least-privilege permissions should then be granted to the identity for the required Key Vault operations.


Question 18 — Just-in-time VM access

A security review finds that administrators can connect to Azure virtual machines over RDP from broad source IP ranges at all times. The company wants to reduce exposure by opening management ports only when an authorized administrator requests access, for a limited duration and from an approved source.

Which control most directly meets this requirement?

A. Assign the VM the Security Reader role.

B. Enable a ReadOnly resource lock.

C. Configure an NSG rule that permanently allows RDP from the corporate network.

D. Enable and configure just-in-time (JIT) VM access through Microsoft Defender for Cloud, setting approved ports, source IP restrictions, and permitted access duration.

Correct answer: D

Explanation: JIT VM access reduces the time that management ports are exposed. A request can temporarily open the required port according to configured rules and duration limits. A permanently allowed NSG rule does not provide the same time-bound access model. JIT requirements and supported VM configurations should be verified before deployment.


Question 19 — Web Application Firewall (WAF)

A company hosts a public web application behind a supported Azure application delivery service. The security team wants to inspect incoming HTTP(S) requests and detect or block common web attacks, such as SQL injection and cross-site scripting, using managed rule sets.

Which control should the team configure?

A. An NSG that allows only TCP port 443.

B. A Web Application Firewall policy with an appropriate managed rule set, initially validating detection and false positives before enforcing blocking as appropriate.

C. Azure Disk Encryption on the web server’s operating system disk.

D. A private endpoint for the public-facing website that allows every internet client to connect privately.

Correct answer: B

Explanation: A WAF evaluates HTTP(S) traffic and can detect or block common web application attacks using managed rules and custom rules. An NSG filters network traffic but does not inspect requests for application-layer attack patterns in the same way. A staged rollout helps reduce false positives while establishing effective protection.


Question 20 — Secure API backends with Azure API Management

An organization publishes an API through Azure API Management (APIM). Clients must present Microsoft Entra access tokens, and APIM must reject requests when the token’s issuer, audience, or signature is invalid. The backend should receive only requests that pass the gateway’s validation policy.

Which approach is most appropriate?

A. Configure APIM policy-based JWT validation, such as validate-jwt or the applicable Entra-aware validation policy, with the expected issuer, audience, and signing-key configuration.

B. Place the token in a URL query string and let the backend decide whether to inspect it.

C. Enable anonymous access at APIM and use a network security group to validate token claims.

D. Assign all API callers the API Management service’s Contributor role.

Correct answer: A

Explanation: APIM policies can validate JWTs before forwarding requests to the backend. Validation should enforce the expected issuer and audience and verify the token using trusted signing keys. Tokens should be sent in the authorization header rather than exposed in URLs. Azure RBAC roles for managing APIM resources do not authenticate API consumers.


Question 21 — Enforce VM security configuration

A company needs to assess and enforce supported operating-system security settings on Azure VMs and Arc-enabled servers, such as required configuration values. The team wants configuration compliance and remediation capabilities rather than only network-level filtering.

Complete the statement:

Azure __________ can be used to audit and enforce supported machine configuration settings on applicable Azure and Arc-enabled machines.

A. Private Link

B. Network Watcher

C. Machine Configuration

D. Application Gateway

Correct answer: C — Machine Configuration

Explanation: Azure Machine Configuration provides capabilities to audit and enforce supported configuration settings on applicable machines, including Azure VMs and Arc-enabled servers. It can help assess compliance against configuration requirements and remediate supported deviations. Network Watcher and Private Link serve networking purposes, while Application Gateway provides application delivery capabilities.


Question 22 — Container security in Azure

An organization runs containerized applications in AKS. The security team wants to identify container-related risks, monitor supported runtime threats, and receive security recommendations through Microsoft’s cloud security platform.

Which solution is the most appropriate starting point?

A. Use Azure SQL auditing for all container events.

B. Enable the applicable Microsoft Defender for Containers plan in Microsoft Defender for Cloud and configure the required components and data collection for the desired protections.

C. Use Azure Policy alone as a replacement for container threat detection.

D. Enable a resource lock on the AKS cluster and assume that the lock prevents malicious activity inside containers.

Correct answer: B

Explanation: Microsoft Defender for Containers provides supported security capabilities for container environments, including recommendations and threat detection features. The exact coverage depends on the environment and configuration, so required components and data collection should be verified. Azure Policy can enforce supported configurations, but it does not replace runtime threat detection.


Question 23 — AI workload protection

A team deploys an AI application using Microsoft Foundry. The application must reduce the risk of unsafe model outputs and prompt-based attacks, and the security team wants to apply configurable safeguards to model interactions. The team also wants centralized security visibility for the AI workload.

Which approach best meets the requirements?

A. Use an NSG as the only AI safety control and allow all model requests.

B. Store all prompts and API keys in source code so that developers can debug issues quickly.

C. Enable Azure Backup and rely on recovery points to prevent unsafe AI responses.

D. Configure appropriate Microsoft Foundry guardrails and content-safety controls, and use the relevant Microsoft Defender for Cloud AI workload protection capabilities for security visibility and threat detection.

Correct answer: D

Explanation: Foundry guardrails and content-safety controls help mitigate specified risks in model inputs and outputs, depending on the model, configuration, and supported features. Microsoft Defender for Cloud’s AI security capabilities provide additional workload protection and visibility. No single guardrail guarantees that all harmful or adversarial interactions will be prevented, so controls should be tested and layered.


Section 4 — Manage and monitor security posture


Question 24 — Defender for Cloud attack path analysis

Microsoft Defender for Cloud identifies a public-facing virtual machine with a vulnerability. The VM has a managed identity with access to a storage account containing sensitive data. The security team wants to understand whether the exposed VM could provide a path to the sensitive storage resource and prioritize remediation based on the potential impact.

Which capability is most appropriate?

A. Microsoft Sentinel’s data retention settings.

B. Azure SQL auditing.

C. Defender for Cloud’s attack path analysis and related cloud security posture management tools.

D. Azure Resource Manager deployment history alone.

Correct answer: C

Explanation: Defender for Cloud’s cloud security posture management capabilities can help identify attack paths that connect exposures, misconfigurations, identities, and sensitive resources. Attack path analysis supports prioritization based on potential risk and reachable assets. It complements, rather than replaces, vulnerability remediation and identity-permission reviews.


Question 25 — Ingest Common Event Format logs into Microsoft Sentinel

A company has a network security appliance that exports security events in Common Event Format (CEF). The SOC wants those events available in Microsoft Sentinel for analytics rules and incident investigation.

Which approach is most appropriate?

A. Configure the supported CEF ingestion architecture, including the required Linux-based log forwarder and Azure Monitor Agent setup, and enable the applicable Microsoft Sentinel data connector.

B. Install the Windows Event Forwarding collector on the network appliance and assume it can ingest CEF directly.

C. Enable Azure SQL auditing on the Sentinel workspace.

D. Create an Azure Policy assignment that converts CEF messages into Sentinel incidents.

Correct answer: A

Explanation: Microsoft Sentinel supports CEF ingestion using a supported log-forwarding architecture. The appropriate connector and agent configuration must be implemented so the appliance’s CEF events reach the workspace and can be queried. Windows Event Forwarding serves Windows event collection scenarios, while Azure Policy does not perform log ingestion or event conversion.


Question 26 — Collect Windows security events

An organization needs to collect Windows security events from servers into Microsoft Sentinel. The team wants to control which Windows events are collected and manage the collection configuration centrally through Azure Monitor.

Which approach is the best fit?

A. Use a private endpoint for each Windows event log.

B. Enable Microsoft Defender for Storage on every server.

C. Configure an Azure Firewall application rule to forward Windows events directly into Sentinel.

D. Configure the appropriate Azure Monitor Agent deployment and a Data Collection Rule (DCR) that specifies the Windows event channels or event selection required for collection.

Correct answer: D

Explanation: Azure Monitor Agent and Data Collection Rules are used to define and manage supported log collection. For Windows security events, the DCR specifies the event selection and destination configuration appropriate to the chosen collection method. Azure Firewall and Defender for Storage do not configure Windows event ingestion into Sentinel.


Question 27 — Automate incident handling in Microsoft Sentinel

Match each Microsoft Sentinel capability to its primary purpose.

CapabilityPrimary purpose
1. Analytics ruleA. Perform response actions through an automation workflow, such as notifying a team or invoking a supported remediation action
2. Automation ruleB. Detect suspicious patterns in collected data and generate alerts or incidents according to the rule configuration
3. PlaybookC. Apply incident-handling logic, such as assigning an incident, changing its status, or triggering a playbook based on configured conditions

Choose the correct mapping.

A. 1-C, 2-B, 3-A

B. 1-B, 2-C, 3-A

C. 1-A, 2-C, 3-B

D. 1-B, 2-A, 3-C

Correct answer: B

Explanation: Analytics rules identify suspicious activity and can generate alerts or incidents. Automation rules apply incident-management logic and can trigger playbooks. Playbooks are workflows, commonly built with Azure Logic Apps, that carry out response or integration actions. Together, these capabilities help automate detection and incident handling.


Question 28 — Discover external attack surface exposure

A company suspects that teams have deployed internet-facing assets outside the approved cloud inventory. The security team needs to discover externally visible assets associated with the organization, including assets that might not be registered in its current Azure resource inventory.

Which service is designed for this purpose?

A. Azure Network Watcher.

B. Microsoft Defender for Storage.

C. Microsoft Defender External Attack Surface Management (Defender EASM).

D. Microsoft Entra Privileged Identity Management.

Correct answer: C

Explanation: Microsoft Defender EASM helps discover and inventory an organization’s externally exposed digital assets and identify potential external exposure and vulnerabilities. It can help uncover assets that are not evident from the organization’s known cloud resource inventory. Network Watcher focuses on Azure network diagnostics, and PIM manages privileged access.


Question 29 — Microsoft Security Copilot access control

A security team is deploying Microsoft Security Copilot. Analysts should be able to use the capabilities and data sources appropriate to their assigned responsibilities, but they must not automatically receive administrative control over the workspace, all plugins, or all agents.

What is the best administrative approach?

A. Configure Security Copilot workspace access and roles using least privilege, and review the permissions and enablement of plugins and agents before making them available.

B. Give every analyst the same highest-privilege administrative role to simplify support.

C. Share a single administrator account among the analysts.

D. Disable all role-based access controls and rely on the analysts’ job titles.

Correct answer: A

Explanation: Security Copilot access should be governed through the applicable workspace roles, permissions, and controls for plugins and agents. Least privilege helps ensure that analysts can perform their assigned tasks without automatically receiving broad administrative capabilities. Shared accounts and blanket administrative access undermine accountability and increase risk.


Question 30 — Identify AI-related data exposure risks

A company is rolling out AI assistants that can search organizational content. The security team is concerned that sensitive information may be overexposed through existing permissions, shared content, or AI-enabled access paths. The team wants to identify and assess AI-related data security risks across supported data sources.

Which solution is most appropriate?

A. Use Azure Bastion to identify overshared documents.

B. Use Microsoft Purview Data Security Posture Management (DSPM) for AI to assess relevant AI-related data risks and help identify oversharing or sensitive-data exposure in supported environments.

C. Use an Azure SQL resource lock to prevent AI assistants from reading documents.

D. Use Microsoft Defender External Attack Surface Management to inspect all internal document permissions.

Correct answer: B

Explanation: Microsoft Purview DSPM for AI helps organizations assess data security risks associated with AI usage, including relevant sensitive-data exposure and oversharing risks in supported environments. Findings should guide remediation of permissions, data controls, and AI access paths. Bastion provides secure VM connectivity, while EASM focuses on external attack surface discovery.


Exam 3 — Final review

Use your results to identify the topics that need more practice before attempting Exam 4.

Skill domainQuestionsMain areas tested
Identity, access, and governance1–7PIM, Key Vault, agent identity, Conditional Access, Azure Policy, RBAC, OAuth consent, backup protection
Storage, databases, and networking8–15Private Link, SAS, Defender for Storage, SQL auditing, Network Watcher, Azure Firewall, private DNS, database protection
Secure compute16–23Trusted Launch, AKS workload identity, JIT access, WAF, API security, Machine Configuration, container security, AI guardrails
Security posture and monitoring24–30Attack path analysis, Sentinel ingestion, Windows event collection, automation, EASM, Security Copilot, Purview DSPM for AI

Suggested review strategy: For any question you missed, focus on the difference between controls that prevent access, controls that detect risk, and tools that investigate or remediate issues. Many certification questions test whether you can select the right control for a specific requirement rather than simply recognize a product name.


Go to the SC-500 Exam Prep Hub main page

SC-500 Practice Exam #4

This practice exam is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.

Implementing End-to-End Security Controls for Cloud and AI Workloads


Section 1 — Manage identity, access, and governance


Question 1 — PIM activation and emergency access

A company has two requirements for subscription-level administrators:

  • Routine administration must use just-in-time privileged access with approval.
  • Emergency access must remain possible if the normal approval process is unavailable.

Which design best balances these requirements?

A. Assign every administrator permanent Owner access and monitor activity with Azure Activity Logs.

B. Use eligible PIM assignments with configured activation controls, and maintain separately governed emergency-access accounts with carefully restricted, monitored credentials and procedures.

C. Replace all privileged assignments with Reader access and grant Owner access manually when needed.

D. Use Azure Policy to require approval before each Azure Resource Manager operation.

Correct answer: B

Explanation: PIM reduces standing privilege by making eligible roles activatable under defined conditions. Emergency-access arrangements should be designed separately so that an outage or unavailable approver does not prevent recovery. Those accounts require strict protection, monitoring, and periodic validation. Azure Policy does not provide per-operation approval for every management-plane action.


Question 2 — Key Vault network and authorization controls

An application hosted in a virtual network must retrieve a secret from Azure Key Vault. The company requires that:

  • The vault is not reachable through its public network endpoint.
  • Only the application identity can read the required secret.
  • Administrators can audit vault access.

Which design best satisfies all three requirements?

A. Enable public network access, allow all Azure services through the firewall, and give the application Contributor access.

B. Use a Key Vault resource lock and store the secret in the application’s configuration file.

C. Assign the Key Vault Administrator role to the application and disable diagnostic logging.

D. Configure a private endpoint and private DNS, disable public network access after validating connectivity, grant the application identity the required secret-read permission, and enable diagnostic logging to a suitable destination.

Correct answer: D

Explanation: These are separate control layers. Private Link and DNS provide private connectivity; disabling public network access removes the public access path. Key Vault data-plane permissions restrict which identity can read secrets, while diagnostic settings support audit and investigation. A resource lock does not provide these controls.


Question 3 — Infrastructure as code security

A development team deploys Azure infrastructure through Bicep templates and a CI/CD pipeline. Security requirements state that templates containing known security issues should be identified before deployment, and that noncompliant resource configurations must be blocked from production.

Which approach best meets these requirements?

A. Integrate supported infrastructure-as-code scanning into the development pipeline and enforce applicable Azure Policy controls during deployment.

B. Enable Microsoft Defender for Servers after all resources have been deployed.

C. Assign the deployment identity the Owner role and rely on developers to review templates manually.

D. Apply a CanNotDelete lock to the resource group before each deployment.

Correct answer: A

Explanation: Scanning templates in the development pipeline can identify security problems before resources are deployed. Azure Policy can enforce applicable resource requirements at deployment time, depending on the policy definition and effect. These controls complement each other: template scanning identifies issues early, while policy enforcement helps prevent noncompliant deployments.


Question 4 — OAuth application permissions

A background application needs to read files from a designated SharePoint site without a signed-in user. The application currently requests broad Microsoft Graph application permissions. The security team wants to minimize the data the application can access.

What should the team do?

A. Convert all application permissions to delegated permissions, even though no user will be signed in.

B. Assign the application Global Administrator so it can access only the intended site.

C. Review the required application permissions and implement a supported site-scoped authorization approach, such as appropriately configured selected-site permissions, granting access only to the required site.

D. Enable user consent for all application permissions and allow the application to choose its own access scope.

Correct answer: C

Explanation: Application permissions allow an application to act without a signed-in user and can be broad if not restricted. For supported SharePoint and Microsoft Graph scenarios, selected-site permissions can restrict an application’s access to designated sites, subject to the relevant permission model and setup. Granting tenant-wide administrative access would violate least privilege.


Question 5 — Microsoft Entra agent identity security

An organization uses autonomous AI agents that obtain Microsoft Entra tokens to access internal APIs. The security team wants to block high-risk agent identities and ensure that new agents in an approved category receive the same policy automatically.

Which TWO actions best support these requirements?

A. Configure an applicable Conditional Access policy to block agent identities identified as high risk.

B. Create an Azure resource lock on each API and use it as the agent access policy.

C. Use supported custom security attributes to categorize agent identities and target the appropriate Conditional Access policy so matching future identities are covered.

D. Create a policy targeting all human users and assume it automatically includes every agent identity and agent user account.

Correct answers: A and C

Explanation: Conditional Access can block risky agent identities where the relevant capabilities and licensing are available. Supported custom security attributes can help target policies by agent category, including matching future identities. Agent identities and agent user accounts are distinct identity types, so a policy targeting one should not be assumed to cover the other. Conditional Access also does not replace authorization checks on the target API.


Question 6 — Managed identity and Key Vault access

A Function App needs to retrieve a database password from Azure Key Vault. The organization prohibits storing credentials in application settings and source code. The Function App should have no permission to create or delete secrets.

Which configuration is most appropriate?

A. Create a service principal with a client secret and store the secret in an encrypted application setting.

B. Assign the Function App the Key Vault Administrator role and rotate the database password monthly.

C. Use the Function App’s system-assigned managed identity and assign it Owner at the subscription scope.

D. Enable a managed identity for the Function App and grant it only the required Key Vault secret-read permission through the supported authorization model.

Correct answer: D

Explanation: Managed identities allow supported Azure resources to authenticate to Microsoft Entra-protected services without managing application credentials. A narrowly scoped secret-read permission meets the stated need while avoiding unnecessary create and delete permissions. Subscription-level Owner and Key Vault Administrator are excessive for this scenario.


Question 7 — Regulatory compliance versus security enforcement

A company must evaluate its Azure environment against a regulatory compliance standard and identify which security controls are not satisfied. It also needs to prevent newly deployed storage accounts from violating a mandatory configuration requirement.

Which combination is most appropriate?

A. Use Azure Activity Logs to generate regulatory compliance assessments and resource locks to enforce all storage configuration rules.

B. Use Microsoft Defender for Cloud’s regulatory compliance capabilities to assess control status, and Azure Policy to enforce the applicable storage configuration requirement.

C. Use Microsoft Sentinel analytics rules to configure storage account properties and Defender EASM to block deployments.

D. Use Azure Backup reports to assess every regulatory control and PIM to enforce storage encryption.

Correct answer: B

Explanation: Defender for Cloud’s regulatory compliance dashboard helps assess security posture against supported standards and track control status. Azure Policy can audit, deny, or remediate supported resource configurations depending on the policy effect and resource provider support. Compliance assessment and configuration enforcement are related but distinct functions.


Section 2 — Secure storage, databases, and networking


Question 8 — Storage access for an external partner

A company must allow an external partner to upload files to one Azure Blob Storage container for the next two hours. The partner must not read existing blobs, list other containers, or access the storage account key.

Which approach best meets the requirement?

A. Assign the partner Storage Account Contributor at the subscription scope.

B. Enable anonymous read/write access on the storage account and disable it after two hours.

C. Issue a short-lived SAS restricted to the required container and create/write operations, with an appropriate validity period and secure distribution; use a user delegation SAS where supported and appropriate.

D. Give the partner the storage account key and request that it be deleted after the transfer.

Correct answer: C

Explanation: A narrowly scoped, short-lived SAS can grant only the required operations on the specified resource. A user delegation SAS uses Microsoft Entra credentials to obtain a user delegation key rather than relying on the storage account key. Because SAS tokens are bearer credentials, they must be protected and their validity and permissions kept as limited as practical.


Question 9 — Azure SQL private connectivity

An Azure SQL Database has a private endpoint. A workload in a connected on-premises network still resolves the SQL server hostname to a public IP address. The private endpoint itself reports as approved.

Which action is the best next step?

A. Verify the private DNS zone records and configure the appropriate DNS forwarding or resolution path so the on-premises workload resolves the SQL hostname to the private endpoint address.

B. Enable Transparent Data Encryption on the database.

C. Assign the on-premises server the SQL Server Contributor role.

D. Disable SQL auditing to prevent DNS conflicts.

Correct answer: A

Explanation: A private endpoint does not automatically ensure that every connected network resolves the service hostname to its private IP address. The DNS architecture must be configured for the client environment, including appropriate private DNS records and forwarding or resolver configuration. TDE and auditing do not resolve network names.


Question 10 — Azure Firewall versus NSGs

A company needs to enforce outbound access to approved internet FQDNs from multiple Azure subnets. It also needs centralized inspection and consistent policy management rather than separate FQDN rules on each subnet.

Which solution is most appropriate?

A. Configure a separate NSG on every subnet with rules for the domain names.

B. Use Azure Bastion and allow all outbound traffic from each VM.

C. Configure a private endpoint for every internet destination.

D. Route relevant outbound traffic through Azure Firewall and configure suitable application rules for the approved FQDNs, with a routing design that ensures traffic traverses the firewall.

Correct answer: D

Explanation: Azure Firewall provides centralized network traffic filtering, including FQDN-based application rules for supported protocols and configurations. Routing is essential: traffic that bypasses the firewall will not be inspected by it. NSGs primarily filter based on network attributes such as source and destination IP addresses, ports, and protocols.


Question 11 — Azure SQL security at rest and in use

Match each Azure SQL security control to its primary purpose.

ControlPrimary purpose
1. Transparent Data Encryption (TDE)A. Records selected database events for auditing and investigation
2. SQL auditingB. Helps identify potential database vulnerabilities and insecure configurations
3. Microsoft Defender for Databases vulnerability assessmentC. Encrypts supported database data at rest
4. Microsoft Entra authenticationD. Authenticates users or applications using Microsoft Entra identity

Choose the correct mapping.

A. 1-A, 2-C, 3-D, 4-B

B. 1-C, 2-A, 3-B, 4-D

C. 1-D, 2-B, 3-A, 4-C

D. 1-C, 2-D, 3-B, 4-A

Correct answer: B

Explanation: TDE protects database data at rest. SQL auditing records configured database events. Defender for Databases vulnerability assessment helps identify potential weaknesses and misconfigurations. Microsoft Entra authentication provides an identity-based authentication mechanism. These controls are complementary, not interchangeable.


Question 12 — Network security group troubleshooting

A virtual machine can connect to an application server, but connections to a database subnet fail. An NSG is associated with both a subnet and a network interface. The team needs to determine whether the intended source-to-destination flow is denied by an effective rule.

Which action should the engineer take first?

A. Enable Defender for Storage on the database subnet.

B. Create a ReadOnly lock on the virtual network.

C. Use Azure Network Watcher’s IP flow verify for the relevant source, destination, protocol, and port, then inspect effective security rules if further analysis is needed.

D. Enable SQL auditing and use it to identify the NSG rule that blocked the packet.

Correct answer: C

Explanation: IP flow verify tests a specified flow and reports whether it is allowed or denied and which security rule determines the result. Effective security rules provide a broader view of rules applied to the network interface. SQL auditing records database activity; it does not identify an NSG rule that prevented a connection.


Question 13 — Protect storage from suspicious file uploads

A storage account receives files from multiple external partners. The security team wants to detect suspicious storage activity and scan uploaded blobs for malware where supported. The team does not want to expose the files publicly.

Which approach is best?

A. Enable anonymous access so Defender can inspect every file.

B. Assign every partner the Storage Blob Data Owner role.

C. Configure an Azure resource lock and assume it will detect malicious files.

D. Configure Microsoft Defender for Storage’s applicable threat detection and malware-scanning capabilities, while separately enforcing appropriate storage authorization and network restrictions.

Correct answer: D

Explanation: Defender for Storage offers security monitoring and, where supported and configured, malware scanning for uploaded blobs. Storage authorization and network controls still determine who can access the data and from where. Malware scanning does not require making blobs public, and a resource lock does not detect malicious content.


Question 14 — Azure VPN Gateway and Microsoft Entra Private Access

A company has two different connectivity requirements:

  • Connect an on-premises network to an Azure virtual network using a site-to-site network tunnel.
  • Allow individual remote employees to access specific private enterprise applications without giving them broad network access.

Which mapping is most appropriate?

A. Use Azure VPN Gateway for the site-to-site connection, and Microsoft Entra Private Access for identity-aware access to supported private applications.

B. Use Azure Bastion for the site-to-site tunnel, and an NSG for user identity verification.

C. Use Azure Private Link for the site-to-site tunnel, and Azure Firewall for all employee authentication.

D. Use Microsoft Entra Private Access for the virtual network gateway, and Azure Policy to authenticate employees.

Correct answer: A

Explanation: Azure VPN Gateway provides VPN connectivity, including site-to-site connectivity between networks. Microsoft Entra Private Access supports identity-aware access to supported private resources and applications. Bastion is designed for secure VM management connectivity, while NSGs and Azure Policy do not replace identity-aware application access.


Question 15 — Key Vault secret detection and remediation

A security engineer discovers that a developer accidentally committed a production credential to a source repository. The company wants to identify exposed secrets across supported cloud resources and reduce the chance that discovered credentials can be abused.

Which response is most appropriate?

A. Apply a CanNotDelete lock to the repository’s resource group.

B. Use Defender CSPM’s supported secret-scanning capabilities to identify relevant exposures, then rotate or revoke the exposed credential and remediate its storage location.

C. Enable TDE on all SQL databases and consider the incident resolved.

D. Disable all Key Vault diagnostic logs to prevent the secret from appearing in monitoring systems.

Correct answer: B

Explanation: Supported secret-scanning capabilities in Defender CSPM can help identify exposed credentials in applicable environments. Detection is only the first step: a leaked credential should be treated as compromised, rotated or revoked, and removed from inappropriate locations. Resource locks and database encryption do not invalidate an exposed secret.


Section 3 — Secure compute


Question 16 — Protecting a virtual machine’s boot chain

A security baseline requires supported Azure VMs to verify boot components and provide a virtualized hardware root of trust. The baseline also requires the organization to validate whether a VM image and size support these features before rollout.

Which approach best meets the requirement?

A. Enable JIT VM access and treat it as a replacement for boot integrity.

B. Enable Azure Disk Encryption alone.

C. Deploy supported VMs with Trusted Launch, enable Secure Boot and vTPM as appropriate, and validate compatibility before deployment.

D. Assign the VM a managed identity and enable a resource lock.

Correct answer: C

Explanation: Trusted Launch provides supported VM security features such as Secure Boot and vTPM. Secure Boot helps prevent unauthorized boot components from loading, while vTPM supports virtualized hardware-root-of-trust scenarios. Disk encryption and JIT access protect different parts of the VM security posture.


Question 17 — Disk encryption and key management

A company must protect data stored on supported VM disks and maintain control over the keys used for the selected encryption design. The security team also requires access to keys to be restricted and audited.

What should the engineer do?

A. Select an appropriate supported VM disk-encryption design, configure the required key management through the supported service, and apply least-privilege access and monitoring to the keys.

B. Enable a network security group and assume that all disk data is encrypted.

C. Give all VM administrators unrestricted Key Vault access to simplify recovery.

D. Disable encryption and rely on storage-account firewall rules.

Correct answer: A

Explanation: Disk encryption protects data at rest, while the selected encryption method determines how keys are managed. Key access should be restricted to required identities and monitored. The exact configuration depends on the VM, operating system, disk type, and supported encryption method; an NSG is not a disk-encryption control.


Question 18 — Secure access to Azure VMs

A security policy prohibits public IP addresses on management VMs. Administrators must connect to Windows and Linux VMs over RDP or SSH through the Azure portal or supported client workflows without exposing those management ports directly to the internet.

Which solution is most appropriate?

A. Allow inbound RDP and SSH from all IP addresses but require strong passwords.

B. Assign all administrators permanent Contributor access to the subscription.

C. Enable public IP addresses on every VM and use Azure Policy to record connections.

D. Deploy Azure Bastion in the appropriate virtual network design and restrict direct inbound management access to the VMs.

Correct answer: D

Explanation: Azure Bastion provides secure RDP and SSH connectivity to supported VMs without requiring a public IP address on each target VM. Direct inbound management ports should be restricted so the Bastion path is the intended access route. Bastion does not replace identity governance or OS-level security.


Question 19 — Azure Machine Configuration

A security team wants to assess supported operating-system settings on Azure VMs and Arc-enabled servers against required configurations. It also wants to enforce supported settings and track compliance.

Complete the statement:

Azure __________ can audit and enforce supported machine configuration settings.

A. Network Watcher

B. Machine Configuration

C. Private Link

D. Azure Firewall Manager

Correct answer: B — Machine Configuration

Explanation: Azure Machine Configuration supports auditing and enforcement of supported machine settings on applicable Azure and Arc-enabled machines. It can help detect configuration drift and maintain compliance with defined requirements. The other services focus on network diagnostics, private connectivity, or firewall management.


Question 20 — AI Gateway governance

A company has several AI applications calling models in Microsoft Foundry. It wants to centralize governance of model traffic, apply supported access restrictions, and monitor usage for signs of misuse rather than implementing separate gateway controls in every application.

Which approach is most appropriate?

A. Place a resource lock on every model deployment.

B. Configure only Microsoft Purview retention policies and assume they enforce runtime model access.

C. Configure the applicable AI Gateway in Microsoft Foundry, apply its supported access controls and monitoring, and ensure the applications route model traffic through the governed gateway.

D. Allow direct model access from every application and rely exclusively on Azure Activity Logs.

Correct answer: C

Explanation: AI Gateway provides a centralized approach to governing and monitoring AI model traffic. Its supported access restrictions and monitoring help apply consistent controls. Applications that bypass the gateway will not receive gateway-level enforcement, so the architecture must direct relevant traffic through it.


Question 21 — Copilot Studio agent protection

An organization deploys Copilot Studio agents that can interact with users and organizational data. The security team wants supported real-time protection to identify potentially risky interactions and help prevent harmful or malicious content from being processed.

Which approach is most appropriate?

A. Disable all authentication for the agents so that the protection service can inspect every request.

B. Use an Azure resource lock on the agent environment and assume it blocks prompt injection.

C. Use SQL auditing as the primary control for agent conversations.

D. Configure the applicable Microsoft Defender protection for Copilot Studio agents and validate the supported real-time protection settings, alongside appropriate identity and data-access controls.

Correct answer: D

Explanation: The relevant Defender capabilities can provide supported real-time protection for Copilot Studio agents. The available protection depends on the environment, configuration, and supported features. Identity permissions and data controls remain important because content inspection alone cannot eliminate all agent risks.


Question 22 — Managed identity in Azure Functions

An Azure Function must retrieve a secret from Key Vault and write results to a specific blob container. The organization wants to avoid credentials in code and minimize the blast radius if the Function is compromised.

Which design is best?

A. Use one shared service principal with subscription-level Owner access for both services.

B. Use a managed identity for the Function and grant only the required Key Vault secret-read and container-scoped storage data permissions, where supported.

C. Store the storage account key and Key Vault secret in the same environment variable.

D. Make the container public and remove the Function’s identity.

Correct answer: B

Explanation: Managed identities avoid storing application credentials. Separate, narrowly scoped permissions for Key Vault and Blob Storage reduce the impact of compromise. The identity should receive only the required data-plane permissions, not broad subscription management rights.


Question 23 — AI guardrails and data security

A team is deploying a generative AI application. It must reduce unsafe model responses and limit the risk that the model exposes sensitive organizational data. The team also wants visibility into AI-related security risks.

Which TWO measures address distinct parts of this requirement?

A. Configure appropriate model guardrails and content-safety controls for supported input and output risks.

B. Give the model identity broad read access to every SharePoint site so it can answer more questions.

C. Use a resource lock as the sole control for prompt injection and data leakage.

D. Use Microsoft Purview DSPM for AI and applicable Defender for Cloud AI security capabilities to identify and assess relevant data exposure and AI workload risks.

Correct answers: A and D

Explanation: Guardrails and content-safety controls can help mitigate specified unsafe input and output patterns. Purview DSPM for AI and Defender for Cloud’s applicable AI security capabilities provide complementary visibility into data exposure and AI workload risks. Neither makes broad data permissions safe, and no single safeguard guarantees prevention of all prompt-injection or data-leakage scenarios.


Section 4 — Manage and monitor security posture


Question 24 — Microsoft Sentinel data collection architecture

Match each collection method to the most appropriate description.

Collection methodDescription
1. Windows event collection with Azure Monitor AgentA. Ingest supported appliance logs formatted in a common security-event format using the supported forwarding architecture
2. CEF ingestionB. Collect selected Windows event channels or events using configured data collection
3. Syslog ingestionC. Collect supported syslog messages from configured Linux-based log sources or forwarders

Choose the correct mapping.

A. 1-A, 2-C, 3-B

B. 1-C, 2-B, 3-A

C. 1-B, 2-A, 3-C

D. 1-B, 2-C, 3-A

Correct answer: C

Explanation: Azure Monitor Agent and Data Collection Rules support Windows event collection and other supported collection scenarios. CEF and syslog ingestion use supported forwarding architectures, often involving a Linux-based log forwarder and the relevant Sentinel connector configuration. The data source’s format and collection requirements determine the correct setup.


Question 25 — Microsoft Defender for Cloud multicloud posture

An organization uses Azure and another cloud provider. Its security team wants a consolidated view of security posture, applicable recommendations, and supported workload protection across environments.

Which approach is most appropriate?

A. Connect the supported multicloud environment to Microsoft Defender for Cloud using the appropriate cloud connector and configuration, then enable the relevant posture and workload-protection capabilities.

B. Install Azure Bastion in the other cloud and assume it imports all security findings.

C. Create a single Azure Policy assignment and assume it governs resources in every cloud provider without a connector or supported integration.

D. Export only Azure Activity Logs and treat them as a complete view of all cloud posture risks.

Correct answer: A

Explanation: Defender for Cloud supports multicloud security posture and workload protection through supported connectors and configuration. Coverage depends on the cloud provider, plan, and enabled capabilities. Azure Policy alone does not automatically govern all resources in another cloud provider, and activity logs do not provide a complete security posture assessment.


Question 26 — Microsoft Defender Vulnerability Management

A security team needs to identify vulnerable software on supported Azure VMs, prioritize findings, and track remediation. The team does not simply need to confirm that the VMs are reachable or that network rules are configured.

Which solution is the best fit?

A. Azure Network Watcher.

B. Azure Resource Health.

C. Azure Private DNS.

D. Configure the applicable Microsoft Defender for Servers and Defender Vulnerability Management capabilities, then review supported vulnerability findings and remediation recommendations.

Correct answer: D

Explanation: Defender for Servers and the applicable vulnerability-management capabilities help identify software vulnerabilities and prioritize remediation on supported machines. Network Watcher diagnoses network behavior, Resource Health reports service and resource availability, and Private DNS provides name resolution.


Question 27 — Sentinel automation and playbooks

A SOC wants to automatically assign newly generated incidents to the correct team based on incident properties. For incidents matching a high-priority condition, it also wants to invoke a workflow that notifies responders and performs supported response actions.

Which configuration is most appropriate?

A. Use an Azure Policy assignment to assign Sentinel incidents and configure a resource lock to execute the workflow.

B. Configure a Sentinel automation rule for the incident-handling logic and use a playbook for the required workflow actions.

C. Use a Data Collection Rule to assign incidents and an NSG to send notifications.

D. Use Defender EASM to classify every Sentinel incident and directly run Azure Backup.

Correct answer: B

Explanation: Sentinel automation rules can apply incident-management logic, such as assignment and status changes, based on configured conditions. Playbooks, commonly implemented using Azure Logic Apps, execute workflows such as notifications or supported response actions. The automation rule and playbook complement each other.


Question 28 — Attack path versus individual recommendation

Defender for Cloud reports several findings:

  • A virtual machine is publicly accessible.
  • The VM has a vulnerable software package.
  • Its managed identity can access a sensitive storage resource.

The security team needs to understand how these conditions might combine into a path to a sensitive resource, rather than treating every finding independently.

Which capability should the team use?

A. Microsoft Sentinel workspace retention settings.

B. Azure Resource Health.

C. Defender for Cloud attack path analysis and related cloud security posture management tools.

D. Azure Key Vault certificate renewal.

Correct answer: C

Explanation: Attack path analysis helps connect exposures, vulnerabilities, identity permissions, and reachable resources to reveal potentially significant risk chains. It helps prioritize remediation based on the relationships between findings. Individual recommendations remain useful, but they may not show the combined path to a sensitive asset.


Question 29 — Security Copilot plugins and workspace permissions

A company allows security analysts to use Microsoft Security Copilot to investigate incidents. Some plugins can access sensitive security data or perform actions in connected services. The security team wants to ensure analysts receive only the capabilities required for their responsibilities.

Which approach is best?

A. Give every analyst unrestricted access to all plugins and agents so that investigations are never delayed.

B. Share one Global Administrator account for all Security Copilot investigations.

C. Disable audit logging and use the analysts’ team membership as the only security control.

D. Configure workspace roles and access according to least privilege, and review plugin and agent permissions and enablement before making capabilities available.

Correct answer: D

Explanation: Security Copilot governance requires appropriate workspace access controls and review of connected plugins and agents. The permissions available to a plugin or agent affect what it can access or do, so these capabilities should be enabled and assigned deliberately. Shared privileged accounts and unrestricted access weaken accountability and increase risk.


Question 30 — Data retention and audit investigation

An organization uses Microsoft Sentinel and Log Analytics to investigate security incidents. A policy requires selected security logs to be retained for an extended period, while keeping the cost of frequently queried data under control. Investigators must still be able to retrieve retained records when necessary.

Which approach is most appropriate?

A. Delete all records after seven days and rely on incident summaries.

B. Configure appropriate table-level retention and, where suitable and supported, long-term retention or archive settings for the relevant data, validating the retrieval and query limitations.

C. Apply a ReadOnly lock to the Log Analytics workspace and assume the lock enforces retention.

D. Turn off data collection after an incident so that the existing records remain available indefinitely.

Correct answer: B

Explanation: Retention should be configured according to the applicable policy, data table, and supported Log Analytics retention options. Long-term retention or archive options can help reduce the cost of keeping data that is accessed less frequently, but retrieval and query behavior may differ from interactive analytics. Resource locks do not define log retention, and stopping collection does not guarantee indefinite retention.


Final preparation advice:

Across all four exams and exam topics, prioritize understanding why a control is appropriate and what it does not do. For example, encryption does not replace authorization, a security recommendation does not necessarily enforce a configuration, and a detection tool does not automatically remediate the underlying issue.


Go to the SC-500 Exam Prep Hub main page

Exam Prep Hub for SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads

Welcome to the SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads Exam Prep Hub!

Welcome to the one-stop hub with information for preparing for the SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads certification exam. The content for this exam helps prepare you to be “a security engineer who protects organizational systems and data across cloud and hybrid environments by implementing comprehensive security controls that proactively help prevent unauthorized access and mitigate risks. Your role spans multiple security domains, including identity, network, application, data, and compute. You also help ensure that platforms, data, identities, and infrastructure used by AI workloads are securely implemented and monitored.”.
Upon successful completion of the exam, you earn the Microsoft Certified: Cloud and AI Security Engineer Associate certification.

This hub provides information directly here (topic-by-topic as outlined in the official study guide), links to a number of external resources, tips for preparing for the exam, practice tests, and section questions to help you prepare. Bookmark this page and use it as a guide to ensure that you are fully covering all relevant topics for the SC-500 exam and making use of as many of the resources available as possible.


Audience profile (from Microsoft’s site)

As a candidate for this Microsoft Certification, you’re a security engineer who protects organizational systems and data across cloud and hybrid environments by implementing comprehensive security controls that proactively help prevent unauthorized access and mitigate risks. Your role spans multiple security domains, including identity, network, application, data, and compute. You also help ensure that platforms, data, identities, and infrastructure used by AI workloads are securely implemented and monitored.
In this role, your responsibilities include:
- Securing access to resources by using Microsoft Entra ID and Azure Key Vault.
- Enforcing security and regulatory compliance.
- Securing storage, databases, and networking.
- Securing compute.
- Securing AI solutions.
- Managing and monitoring security posture.
You work closely with architects, administrators, engineers, analysts, and developers responsible for Azure, Microsoft 365, identity and access, information protection, security operations, DevOps, application development, database platforms, and networks.
For this exam, you should have practical experience in administration of Azure and hybrid environments, including compute, network, and storage. You need strong familiarity with Microsoft Entra ID and familiarity with Microsoft 365 administration.

Skills at a glance

  • Manage identity, access, and governance (20–25%)
  • Secure storage, databases, and networking (25–30%)
  • Secure compute (20–25%)
  • Manage and monitor security posture (20–25%)

Topic-by-Topic Exam Content

[click a topic link to access the content and practice questions for that topic]

Manage identity, access, and governance (20–25%)

Secure access to resources by using Microsoft Entra ID

Secure secrets and keys by using Azure Key Vault

Implement governance to enforce security and regulatory compliance

Secure storage, databases, and networking (25–30%)

Implement security for storage accounts

Implement security for databases

Implement security for Azure network services

Secure compute (20–25%)

Implement security for AI

Implement security for servers and virtual machines (VMs)

Implement security for application platform services

Manage and monitor security posture (20–25%)

Manage security posture by using Defender for Cloud

Implement activity and event collection in Microsoft Sentinel

Implement Microsoft Security Copilot


SC-500 Practice Exams

SC-500 Practice Exam #1 (30 questions)

SC-500 Practice Exam #2 (30 questions)

SC-500 Practice Exam #3 (30 questions)

SC-500 Practice Exam #4 (30 questions)


Important SC-500 Resources

Link to the free, comprehensive, self-paced course on Microsoft Learn:

Implement end‑to‑end security controls for cloud and AI workloads

This course has 12 learning paths.

Link to the certification page:

Link to the “Microsoft Certified: Cloud and AI Security Engineer Associate” certification page.

Link to the study guide:

Link to the Study Guide for SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads.

A few highly rated SC-500 related courses on Udemy:

YouTube Video Series


Good luck to you passing the SC-500 Exam!
However, the more preparation you have, the less luck you will need. 🙂

Visit this post to see the list of all the certification preparation hubs available on The Data Community.

Implement resource locks (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Manage identity, access, and governance (20–25%)
   --> Implement governance to enforce security and regulatory compliance
      --> Implement resource locks


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Azure resource locks are an important governance mechanism for protecting critical Azure resources from accidental or unauthorized deletion or modification.

For the SC-500 exam, you should understand:

  • What Azure resource locks are
  • The two types of locks
  • Where locks can be applied
  • How locks are inherited
  • How locks interact with Azure RBAC
  • The difference between control-plane and data-plane operations
  • When to use CanNotDelete versus ReadOnly
  • How to create and manage locks
  • Important limitations and operational considerations

Resource locks are especially useful for protecting critical infrastructure such as production resource groups, databases, storage accounts, networking components, and other resources that should not be accidentally removed or modified.


1. What Are Azure Resource Locks?

An Azure resource lock is a management control that prevents users from accidentally deleting or modifying Azure resources.

Locks can be applied at several scopes, including:

  • Subscription
  • Resource group
  • Individual resource

When a lock is applied to a parent scope, resources contained within that scope can inherit the lock.

Resource locks are implemented through Azure Resource Manager and are sometimes referred to as management locks.

The key purpose of a resource lock is:

Protect important Azure resources from accidental deletion or modification, even when the user otherwise has sufficient permissions to perform the operation.

This makes resource locks different from ordinary Azure RBAC permissions.


2. Resource Locks vs. Azure RBAC

This distinction is extremely important for the SC-500 exam.

Azure RBAC determines what actions a user, group, service principal, or managed identity is authorized to perform.

A resource lock imposes an additional restriction on operations against the locked resource.

For example, suppose a user has the Owner role on a resource group.

Normally, the user has sufficient permissions to delete resources in that resource group.

If the resource group has a CanNotDelete lock, however, the user cannot delete the locked resource until the lock is removed.

Therefore:

A resource lock can restrict an operation even when the user has sufficient RBAC permissions to perform that operation.

This is one of the most important concepts to remember.

Simple comparison

CapabilityAzure RBACResource Lock
Determines who has permissionsYesNo
Grants permissionsYesNo
Restricts deletionIndirectly, through permissionsYes
Restricts modificationThrough permissionsYes, with ReadOnly
Applies to all users/roles at the locked scopeNoYes
Protects against accidental deletionIndirectlySpecifically designed for this
Replaces RBACNoNo

Resource locks and RBAC are therefore complementary, not competing, security controls.


3. The Two Primary Resource Lock Types

Azure provides two primary management lock levels:

  1. CanNotDelete
  2. ReadOnly

The names used in the Azure portal are:

  • Delete
  • Read-only

The underlying Azure Resource Manager lock levels are:

  • CanNotDelete
  • ReadOnly

Understanding exactly what each does is essential for the exam.


4. CanNotDelete Lock

A CanNotDelete lock prevents the locked resource from being deleted.

Authorized users can still:

  • Read the resource
  • Modify the resource

They simply cannot delete it while the lock remains in place.

Example

Suppose a production SQL database has a CanNotDelete lock.

An administrator can still change supported configuration settings.

However, an attempt to delete the database will fail because the resource is locked.

Think of it as:

“You can change it, but you cannot delete it.”

This is generally the less restrictive of the two lock types.


5. ReadOnly Lock

A ReadOnly lock is more restrictive.

It prevents users from:

  • Modifying the resource
  • Deleting the resource

Users can still read the resource.

Think of it as:

“You can look at it, but you cannot change or delete it.”

A ReadOnly lock is conceptually similar to restricting authorized users to read-only access for control-plane operations.

However, there are important nuances involving data-plane operations, discussed later.


6. CanNotDelete vs. ReadOnly

This comparison should be memorized for the exam.

Lock TypeReadModifyDelete
No lockYesYes*Yes*
CanNotDeleteYesYesNo
ReadOnlyYesNoNo

* Subject to the user’s normal RBAC permissions and other governance controls.

Easy memory trick

CanNotDelete:

Change it, but don’t delete it.

ReadOnly:

Read it, but don’t change or delete it.


7. Where Can Resource Locks Be Applied?

Resource locks can be applied at several scopes.

Subscription

A lock can be applied to an entire Azure subscription.

This can protect resources throughout the subscription.

However, a subscription-level lock can have a very broad impact and should therefore be used carefully.


Resource Group

A lock can be applied to a resource group.

This is a common approach for protecting a collection of related production resources.

For example:

Production Resource Group
│
├── Web App
├── Application Gateway
├── SQL Database
├── Storage Account
└── Key Vault

A CanNotDelete lock on the resource group can protect the resources from deletion.


Individual Resource

A lock can also be applied directly to a specific resource.

For example:

Production Resource Group
│
├── Web App
├── SQL Database ← CanNotDelete
├── Storage Account
└── Key Vault

Only the targeted resource is protected by the lock, subject to lock inheritance and scope rules.

This can be preferable when only a particularly critical resource needs protection.


8. Lock Inheritance

Locks can be inherited from a parent scope.

For example:

Subscription
│
└── Resource Group
│
├── VM
├── Storage Account
└── SQL Database

If a lock is applied to the resource group, the resources contained within that resource group inherit the lock.

This also means that resources added to the resource group later can inherit the applicable lock.

Exam scenario

Suppose:

  • Resource group ProductionRG has a CanNotDelete lock.
  • A new storage account is created in ProductionRG.

The storage account inherits the applicable lock.

The protection isn’t limited only to resources that existed when the lock was originally created.


9. The Most Restrictive Lock Takes Precedence

Multiple locks can exist within an inheritance hierarchy.

When multiple locks apply, the most restrictive lock takes precedence.

For example:

Resource Group
CanNotDelete
↓
Storage Account
ReadOnly

The storage account is effectively protected by the more restrictive ReadOnly behavior.

Therefore, when evaluating a scenario, don’t look only at a resource’s direct lock.

Consider:

  1. The resource’s own lock
  2. The parent resource group’s lock
  3. The subscription-level lock
  4. Which applicable lock is most restrictive

10. Resource Locks Are Control-Plane Controls

One of the most important technical details for the SC-500 exam is that resource locks apply to Azure Resource Manager control-plane operations.

They do not universally protect data-plane operations.

Control plane

The control plane manages Azure resources themselves.

Examples include operations such as:

  • Creating resources
  • Deleting resources
  • Updating resource configuration
  • Changing resource properties

These operations generally go through Azure Resource Manager.

Data plane

The data plane operates on the data contained within a resource.

Examples include:

  • Reading blob data
  • Writing blob data
  • Reading database records
  • Modifying database records

A resource lock does not automatically prevent all data-plane operations.


11. Example: Storage Account Lock

Consider a storage account containing:

Storage Account
│
├── Blob Container
│ ├── File A
│ └── File B
│
├── Queue
└── Table

You apply a CanNotDelete lock to the storage account.

The lock protects the storage account resource against deletion.

However, it does not automatically prevent someone with appropriate data-plane permissions from deleting Blob File A.

Why?

Because:

The lock protects Azure Resource Manager control-plane operations; it isn’t a general-purpose data protection mechanism.

This is a very common exam trap.


12. Resource Locks Do Not Replace Data Protection

Suppose an organization wants to protect important data stored in Azure Storage.

A resource lock can help prevent someone from deleting the storage account itself.

But it should not be treated as a replacement for:

  • Data access controls
  • Microsoft Entra authentication
  • Azure RBAC
  • Storage authorization
  • Backup
  • Soft delete
  • Versioning
  • Immutable storage where appropriate
  • Data-plane security controls

The lock protects the resource management operation.

Other controls protect the data.


13. Why Use CanNotDelete?

CanNotDelete is useful when:

  • Administrators need to continue modifying the resource
  • The resource must not be accidentally deleted
  • Normal operational management must continue
  • A production resource is business-critical

Example

A company has a production database that needs regular configuration updates.

The organization wants administrators to continue making approved changes but wants to prevent accidental deletion.

A CanNotDelete lock is appropriate.

The administrator can modify the resource but cannot delete it.


14. Why Use ReadOnly?

ReadOnly is appropriate when the resource should not be changed through the Azure Resource Manager control plane.

Examples might include:

  • A highly stable production resource
  • A critical networking component during a controlled period
  • A resource that should be temporarily frozen
  • A resource where configuration changes must be prevented

However, ReadOnly should be used carefully.

It is significantly more restrictive than CanNotDelete.


15. ReadOnly Can Break Operations

A common mistake is to assume that a ReadOnly lock is harmless because it only prevents direct modifications.

Some Azure operations that appear to be read or indirectly related to a resource can require control-plane write operations.

Consequently, applying ReadOnly can interfere with normal service functionality.

For example, some service operations may need to update configuration, create child resources, or perform other control-plane operations.

Therefore:

Use ReadOnly only when you understand the operational consequences for the service.

This is an important real-world security principle and can appear in scenario-based exam questions.


16. Resource Locks and Resource Groups

Resource-group-level locks require particular attention.

Suppose:

ProductionRG
│
├── VM
├── Storage Account
├── Key Vault
└── SQL Server

You apply:

CanNotDelete

to ProductionRG.

The resources inherit the protection.

An attempt to delete the resource group is blocked because deleting the resource group would require deleting its contained resources.

Importantly, the deletion operation doesn’t simply delete everything that isn’t individually locked while leaving locked resources behind.

The lock blocks the overall deletion operation.


17. Resource Locks and Resource Group Deletion

Consider:

ProductionRG
│
├── Resource A
├── Resource B
└── Resource C

If the resource group has a CanNotDelete lock, attempting to delete ProductionRG is blocked.

This is true even if some individual resources don’t have their own locks.

The parent-level lock protects the scope and its resources.

Exam takeaway

If a scenario says:

“Prevent the resource group and all resources within it from being accidentally deleted.”

A CanNotDelete lock at the resource-group level is a strong candidate.


18. Resource Locks and RBAC Assignments

A particularly important operational consideration is that a CanNotDelete lock can also prevent deletion of Azure RBAC role assignments associated with the locked resource or scope.

This is another reason resource locks should be planned carefully.

A lock isn’t simply a protection mechanism for the resource itself; it can affect related control-plane operations.

Therefore, before applying a lock, administrators should understand what operations are required to manage the resource and its associated configuration.


19. Resource Locks and Azure Backup

Resource locks can also affect Azure Backup operations.

For example, a CanNotDelete lock on a resource group created by Azure Backup can prevent the service from deleting old restore points.

This can cause backup-related operational problems because the service may be unable to perform its normal cleanup.

Exam lesson

Don’t assume:

“A resource lock can always be safely applied to any resource group.”

Instead, consider:

  • What services manage resources in the scope?
  • Do those services need to delete resources?
  • Do they need to modify resources?
  • Will the lock interfere with lifecycle operations?

Security controls must be designed with service dependencies in mind.


20. Resource Locks and Azure Machine Learning

Another example of an operational consequence involves Azure Machine Learning.

A CanNotDelete lock on a resource group containing an Azure Machine Learning workspace can interfere with autoscaling of compute clusters.

The service may need to remove unused nodes, and the lock can prevent the required deletion operations.

This can result in unused compute resources remaining active.

The broader lesson is:

A lock can protect resources but can also interfere with automated service operations that require deletion or modification.


21. Resource Locks and Deployment History

A CanNotDelete lock on a resource group or subscription can also affect automatic cleanup of Azure Resource Manager deployment history.

Azure Resource Manager can automatically remove older deployment records.

If the applicable scope has a CanNotDelete lock, the deployment history cannot be automatically deleted in the normal way.

This can eventually cause deployment problems if deployment history reaches its limit.

Therefore, locks can have consequences beyond the obvious “prevent resource deletion” behavior.


22. Who Can Create or Delete Resource Locks?

Resource locks are themselves Azure resources and require appropriate authorization.

Permissions to create or delete management locks are associated with actions such as:

Microsoft.Authorization/*

or

Microsoft.Authorization/locks/*

Roles such as Owner and User Access Administrator have the required permissions in the relevant contexts.

Specialized roles may also provide the necessary permissions.

Important distinction

Having permission to modify a resource does not necessarily mean that you can remove a resource lock.

Lock management requires appropriate authorization to manage locks.

This helps prevent a normal resource administrator from simply bypassing the protection.


23. Removing a Resource Lock

A resource lock must be removed before a protected operation can be performed when the lock blocks that operation.

For example:

CanNotDelete Lock
↓
Delete resource
↓
Operation blocked
↓
Authorized administrator removes lock
↓
Delete resource

The ability to remove the lock itself requires appropriate permissions.

This creates an additional administrative boundary around highly sensitive resources.


24. Creating Resource Locks in the Azure Portal

A resource lock can be configured through the Azure portal.

For a resource or resource group, the general process is:

  1. Open the resource or resource group.
  2. Select Locks.
  3. Select Add.
  4. Enter a lock name.
  5. Select the lock type:
    • Delete
    • Read-only
  6. Optionally provide notes.
  7. Create the lock.

The portal terminology maps to the Azure Resource Manager lock levels:

PortalARM Lock Level
DeleteCanNotDelete
Read-onlyReadOnly

25. Creating Locks with Azure CLI

Resource locks can also be managed through Azure CLI.

For example, a CanNotDelete lock on a resource can be created with a command conceptually similar to:

az resource lock create \
--lock-type CanNotDelete \
--name ProductionLock \
--resource-group ProductionRG \
--resource MyStorageAccount \
--resource-type Microsoft.Storage/storageAccounts

A read-only lock can similarly be created by specifying:

--lock-type ReadOnly

The important exam concept isn’t memorizing every CLI parameter.

Instead, understand that Azure CLI supports both:

  • CanNotDelete
  • ReadOnly

and can apply them at appropriate scopes.


26. Creating Locks with Azure PowerShell

Azure PowerShell also supports resource locks.

For example:

New-AzResourceLock `
-LockName ProductionLock `
-LockLevel CanNotDelete `
-ResourceGroupName ProductionRG

You can use PowerShell commands such as:

  • New-AzResourceLock
  • Get-AzResourceLock
  • Remove-AzResourceLock

to manage locks.

Again, for SC-500, understanding the purpose and behavior is generally more important than memorizing every command parameter.


27. Resource Locks with ARM Templates and Bicep

Resource locks can also be deployed programmatically using infrastructure as code.

The resource type is:

Microsoft.Authorization/locks

For example, a Bicep resource can conceptually specify:

resource createRgLock 'Microsoft.Authorization/locks@2016-09-01' = {
name: 'productionLock'
properties: {
level: 'CanNotDelete'
notes: 'Protect production resources from accidental deletion.'
}
}

This allows resource-lock configuration to become part of a repeatable infrastructure deployment process.

However, teams should carefully consider lifecycle management.

For example, if the same deployment is responsible for creating the lock and later modifying or deleting the protected resource, the deployment process must have the necessary permissions and be designed to account for the lock.


28. Resource Locks and Infrastructure as Code

Resource locks can be useful as part of a defense-in-depth strategy.

For example:

Infrastructure as Code
↓
Azure Policy
↓
RBAC
↓
Resource Lock
↓
Protected Resource

Each control addresses a different concern.

Infrastructure as code

Provides repeatable and controlled deployments.

Azure Policy

Enforces organizational configuration requirements.

RBAC

Controls who can perform actions.

Resource locks

Prevent deletion or modification at the locked scope.

No single control should be treated as a complete security solution.


29. Resource Locks Are Not a Replacement for Azure Policy

Resource locks and Azure Policy solve different problems.

Resource lock

Protects a specific scope from deletion or modification.

Azure Policy

Evaluates resources against organizational rules and can audit or enforce compliance.

For example:

Requirement:

All storage accounts must use approved network configurations.

Azure Policy is appropriate because the requirement needs to be evaluated across resources.

Requirement:

Prevent accidental deletion of this production storage account.

A resource lock is appropriate.

Easy distinction

Policy asks: “Does this resource meet the required configuration?”

Lock asks: “Can this resource be deleted or modified?”


30. Resource Locks and Tags

Tags and resource locks serve very different purposes.

Tags

Provide metadata for:

  • Organization
  • Cost management
  • Ownership
  • Environment classification
  • Automation

Locks

Restrict control-plane operations.

A tag such as:

Environment = Production

doesn’t protect a resource from deletion.

A CanNotDelete lock does.


31. Resource Locks and Resource Health

Resource locks also shouldn’t be confused with resource health or monitoring capabilities.

A lock doesn’t:

  • Detect attacks
  • Detect malware
  • Monitor availability
  • Encrypt data
  • Back up data
  • Detect vulnerabilities
  • Replace security monitoring

Its purpose is much narrower:

Prevent specified management operations against a resource or scope.


32. Choosing the Correct Lock

A useful decision framework is:

Requirement 1

“Administrators must be able to modify the resource, but nobody should be able to delete it.”

Use: CanNotDelete


Requirement 2

“The resource should not be modified or deleted.”

Use: ReadOnly


Requirement 3

“Only this one resource must be protected.”

Apply the lock directly to the resource.


Requirement 4

“All resources in this resource group should be protected from deletion.”

Apply a CanNotDelete lock to the resource group.


Requirement 5

“Prevent resources from being deployed with insecure configurations.”

Consider Azure Policy rather than a resource lock.


Requirement 6

“Protect blob data from unauthorized deletion.”

Don’t rely solely on a resource lock.

Use appropriate data-plane controls and data-protection features.


33. Common Resource Lock Exam Traps

Trap 1: “Owner can always delete the resource.”

Not necessarily.

A resource lock can prevent deletion even when the user has sufficient RBAC permissions.


Trap 2: “CanNotDelete prevents modifications.”

Incorrect.

CanNotDelete permits authorized users to modify the resource.

It prevents deletion.


Trap 3: “ReadOnly only prevents deletion.”

Incorrect.

ReadOnly prevents both modification and deletion through applicable control-plane operations.


Trap 4: “A storage account lock prevents users from deleting blobs.”

Not necessarily.

Resource locks apply to control-plane operations and aren’t a universal data-plane protection mechanism.


Trap 5: “A resource-group lock protects only the resource group.”

Not exactly.

Locks applied at a parent scope can be inherited by resources within that scope.


Trap 6: “Locks are inherited upward.”

Incorrect.

Inheritance flows downward from a parent scope to child resources.


Trap 7: “Resource locks replace RBAC.”

Incorrect.

RBAC controls authorization.

Locks impose additional management restrictions.


Trap 8: “ReadOnly is always better because it provides stronger security.”

Not necessarily.

ReadOnly can interfere with legitimate service operations.

The appropriate lock depends on the required operational behavior.


Trap 9: “Resource locks protect against every kind of deletion.”

Incorrect.

The lock applies to Azure Resource Manager control-plane operations. Data-plane operations can behave differently.


Trap 10: “A resource lock automatically protects backups.”

Incorrect.

Locks can actually interfere with Azure Backup lifecycle operations if the backup service needs to delete or modify resources.


34. Best Practices for Resource Locks

1. Use CanNotDelete for critical resources that still require routine administration

This provides protection against accidental deletion without preventing normal configuration changes.

2. Use ReadOnly sparingly

ReadOnly is highly restrictive and can interfere with service operations.

3. Apply locks at the narrowest practical scope

Don’t automatically lock an entire subscription when protecting one resource is sufficient.

4. Document locks

Use meaningful lock names and notes explaining why the lock exists.

5. Consider service dependencies

Before locking a resource group, determine whether Azure services need to create, modify, or delete resources within it.

6. Don’t use locks as a substitute for data protection

Combine locks with appropriate:

  • RBAC
  • Data-plane authorization
  • Backup
  • Soft delete
  • Versioning
  • Immutability
  • Monitoring

7. Combine locks with Azure Policy

Use Policy for configuration governance and locks for resource protection.

8. Review locks periodically

An outdated lock can become an operational problem.

9. Establish a controlled lock-removal process

Because removing a lock can enable destructive operations, lock removal should be appropriately governed.

10. Use infrastructure as code when appropriate

For environments where locks are part of the intended architecture, consider managing them consistently through deployment automation.


35. Resource Locks: Quick Reference

RequirementRecommended Approach
Prevent resource deletionCanNotDelete
Prevent resource modification and deletionReadOnly
Allow normal configuration changes but prevent deletionCanNotDelete
Protect an entire resource groupLock the resource group
Protect a single critical resourceLock the resource
Protect resources across a subscriptionSubscription-level lock, used carefully
Prevent insecure configurationsAzure Policy
Control who can manage resourcesAzure RBAC
Protect data from data-plane deletionData-plane security/data protection controls
Protect against accidental resource deletionResource lock
Allow users to read but not modify the resourceReadOnly

36. SC-500 Exam Review

Before taking the exam, make sure you can answer the following questions.

What is a resource lock?

A management control that prevents deletion or modification of Azure resources at a specified scope.

What are the two lock types?

  • CanNotDelete
  • ReadOnly

What does CanNotDelete do?

Allows authorized users to read and modify the resource but prevents deletion.

What does ReadOnly do?

Allows reading but prevents modification and deletion through applicable control-plane operations.

Does a resource lock override RBAC permissions?

A lock can restrict operations even when a user otherwise has sufficient RBAC permissions.

Where can locks be applied?

At subscription, resource group, or resource scope.

Are locks inherited?

Yes. Locks applied at a parent scope can be inherited by child resources.

Which lock takes precedence if multiple locks apply?

The most restrictive applicable lock.

Do locks protect data-plane operations?

No. Resource locks primarily apply to Azure Resource Manager control-plane operations.

Does CanNotDelete allow modifications?

Yes.

Does ReadOnly prevent deletion?

Yes.

Should ReadOnly be used everywhere?

No. It can interfere with legitimate service operations.

Do locks replace Azure Policy?

No.

Do locks replace RBAC?

No.

Do locks replace backup and data-protection controls?

No.


Practice Exam Questions

Question 1

A company has a production Azure SQL database that must remain available for administrators to modify its configuration. However, the company wants to prevent the database from being accidentally deleted.

Which resource lock should you apply?

A. ReadOnly

B. CanNotDelete

C. Audit

D. Deny

Correct Answer: B

Explanation

A CanNotDelete lock allows authorized users to read and modify the resource while preventing deletion.

A ReadOnly lock would also prevent configuration modifications, making it too restrictive for this scenario.


Question 2

An administrator has the Owner role on an Azure resource group. The resource group has a CanNotDelete management lock.

The administrator attempts to delete the resource group.

What happens?

A. The resource group is deleted because Owner always overrides locks

B. The administrator is prompted to provide a second MFA credential

C. The deletion succeeds, but the resources inside the resource group remain

D. The deletion is blocked by the resource lock

Correct Answer: D

Explanation

A management lock can restrict operations even when the user has sufficient RBAC permissions.

The CanNotDelete lock prevents deletion of the locked scope.

An Owner role does not automatically bypass a resource lock.


Question 3

A security engineer wants to protect a critical production resource from both accidental modification and accidental deletion through Azure Resource Manager.

Which lock should be used?

A. ReadOnly

B. CanNotDelete

C. AuditIfNotExists

D. Deny

Correct Answer: A

Explanation

A ReadOnly lock prevents both modification and deletion of the resource through applicable control-plane operations while allowing it to be read.

CanNotDelete would still allow authorized users to modify the resource.


Question 4

An organization applies a CanNotDelete lock to a resource group containing several production resources.

What is the expected effect?

A. Only the resource group name becomes read-only

B. Users can no longer read any resources in the resource group

C. Resources within the resource group inherit the applicable deletion protection

D. Azure Policy is automatically assigned to every resource

Correct Answer: C

Explanation

Resource locks applied to a parent scope can be inherited by child resources.

A CanNotDelete lock on a resource group therefore protects resources within that scope from applicable deletion operations.

It doesn’t prevent reading, and it doesn’t automatically create an Azure Policy assignment.


Question 5

A security administrator applies a CanNotDelete lock to an Azure Storage account. A user with appropriate data-plane permissions subsequently deletes a blob stored in the account.

Why can this occur?

A. CanNotDelete locks only work for virtual machines

B. The lock protects Azure Resource Manager control-plane operations, not all data-plane operations

C. Storage accounts cannot have resource locks

D. Blob deletion always bypasses Azure RBAC

Correct Answer: B

Explanation

Resource locks primarily protect control-plane operations.

Blob operations are data-plane operations and are governed by data-plane authorization and data-protection mechanisms.

Therefore, a resource lock should not be considered a universal mechanism for protecting data stored inside the resource.


Question 6

A company has a resource group containing resources managed by Azure Backup. An administrator wants to apply a CanNotDelete lock to the resource group.

What should the administrator consider before applying the lock?

A. The lock automatically increases backup storage capacity

B. The lock converts all backup data to immutable storage

C. The lock has no effect on Azure Backup

D. The lock can interfere with backup lifecycle operations that require deletion of resources such as old restore points

Correct Answer: D

Explanation

A CanNotDelete lock can prevent Azure Backup from performing required cleanup operations.

Therefore, resource locks must be evaluated for operational side effects before being applied to resource groups managed by Azure services.


Question 7

A company has a CanNotDelete lock on a resource group. Administrators can still modify resources within the group, but they cannot delete them.

The security team now wants to prevent configuration changes as well.

What should they do?

A. Replace the lock with a ReadOnly lock

B. Add an Azure tag

C. Change the RBAC role to Reader for every resource

D. Enable Microsoft Sentinel

Correct Answer: A

Explanation

A ReadOnly lock prevents both modification and deletion through applicable control-plane operations.

A CanNotDelete lock only prevents deletion.


Question 8

A security engineer is designing governance controls for an Azure environment.

The organization has two requirements:

  1. Prevent developers from deploying resources that violate required security configurations.
  2. Prevent accidental deletion of a critical production database.

Which combination should the engineer consider?

A. Resource lock for both requirements

B. Microsoft Sentinel for both requirements

C. Azure Policy for the first requirement and a resource lock for the second

D. RBAC alone for both requirements

Correct Answer: C

Explanation

Azure Policy is appropriate for evaluating and enforcing resource configuration requirements.

A resource lock is appropriate for protecting a critical resource against deletion.

The two controls address different governance problems and can be used together.


Question 9

A resource has a CanNotDelete lock directly applied to it. Its parent resource group has a ReadOnly lock.

Which lock behavior applies to the resource?

A. CanNotDelete because the resource-level lock always overrides the parent

B. No lock because multiple locks cancel each other

C. ReadOnly because the most restrictive applicable lock takes precedence

D. The resource becomes unlocked because only subscription locks are inherited

Correct Answer: C

Explanation

Locks can be inherited from parent scopes, and when multiple locks apply, the most restrictive lock takes precedence.

ReadOnly is more restrictive than CanNotDelete because it prevents both modification and deletion.


Question 10

A security team wants to protect an Azure resource from accidental deletion. The team also wants administrators to be able to perform normal configuration changes.

Which solution best meets the requirement?

A. Apply a ReadOnly lock

B. Apply a CanNotDelete lock

C. Assign the Reader role to administrators

D. Apply an Azure Policy with a Deny effect to the resource

Correct Answer: B

Explanation

A CanNotDelete lock is specifically designed for this scenario.

It prevents deletion while allowing authorized users to modify the resource.

A ReadOnly lock would prevent the required configuration changes. The Reader role would also prevent administrators from making those changes. Azure Policy with Deny is primarily intended for enforcing configuration rules rather than simply protecting a particular resource from deletion.


Final SC-500 Takeaways

The most important concepts to remember for Implement resource locks are:

  1. Resource locks protect Azure resources from accidental deletion or modification.
  2. Locks can be applied at the subscription, resource group, or resource scope.
  3. The two primary lock types are CanNotDelete and ReadOnly.
  4. CanNotDelete allows reading and modification but prevents deletion.
  5. ReadOnly allows reading but prevents modification and deletion.
  6. Resource locks can restrict operations even when the user has sufficient RBAC permissions.
  7. Locks applied at a parent scope can be inherited by child resources.
  8. When multiple locks apply, the most restrictive lock takes precedence.
  9. Resource locks primarily affect control-plane operations.
  10. A resource lock does not automatically protect data-plane data such as blobs or database records.
  11. Resource locks do not replace Azure RBAC.
  12. Resource locks do not replace Azure Policy.
  13. Use Azure Policy to govern resource configurations and use resource locks to protect resources from deletion or modification.
  14. Use CanNotDelete when administrators must continue modifying the resource.
  15. Use ReadOnly when both modification and deletion must be prevented.
  16. Apply locks carefully because they can interfere with automated Azure service operations.
  17. In particular, locks can affect services such as Azure Backup and other services that need to modify or delete resources.
  18. A resource-group-level lock can prevent deletion of the entire resource group and its contents.
  19. Managing locks requires appropriate authorization to manage Azure management locks.
  20. Resource locks are one component of a broader defense-in-depth governance strategy.

The key exam rule to remember

CanNotDelete = Read + Modify, but NO Delete

ReadOnly = Read, but NO Modify and NO Delete

And perhaps the most important conceptual distinction:

Azure Policy governs what configurations are allowed; RBAC controls who is authorized to perform actions; resource locks prevent specified management operations on protected scopes.


Go to the SC-500 Exam Prep Hub main page

Manage Azure built-in role assignments (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Manage identity, access, and governance (20–25%)
   --> Implement governance to enforce security and regulatory compliance
      --> Manage Azure built-in role assignments


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Overview

Azure role-based access control (Azure RBAC) is the authorization system used to control access to Azure resources. It answers three fundamental questions:

  • Who can access a resource?
  • What can they do?
  • Where can they do it?

For the SC-500 exam, understanding how to select and manage Azure built-in roles is especially important because effective security depends on assigning the minimum permissions at the narrowest practical scope.

Azure provides many predefined, or built-in, roles for common administrative and workload scenarios. Examples include Reader, Contributor, Owner, Storage Blob Data Reader, Virtual Machine Contributor, Key Vault Secrets User, and many others.

A role assignment connects a security principal to a role at a particular scope.

The basic model is:

Security principal + Role definition + Scope = Role assignment


1. What Is Azure RBAC?

Azure RBAC provides fine-grained authorization for Azure resources.

For example, an organization might want:

  • Developers to manage resources in a development resource group.
  • Database administrators to manage Azure SQL resources.
  • Security administrators to manage security-related configurations.
  • Auditors to view resources but not modify them.
  • An application to read data from a specific storage account.
  • A managed identity to access secrets in a particular Key Vault.

Rather than giving everyone unrestricted access to an entire subscription, Azure RBAC allows permissions to be assigned according to job responsibilities.

This supports the principle of least privilege.

The three core components

Every Azure RBAC role assignment involves:

  1. Security principal
  2. Role definition
  3. Scope

Security principal

The security principal is the identity receiving the permissions.

It can be:

  • User
  • Group
  • Service principal
  • Managed identity

Using groups instead of assigning roles individually to many users is generally preferred because it simplifies administration and makes access easier to review.

Role definition

The role definition specifies the permissions granted.

For example:

  • Reader allows viewing resources.
  • Contributor allows managing resources but does not allow assigning Azure RBAC roles.
  • Owner provides full resource management access and can assign Azure RBAC roles.

Scope

Scope determines where the permissions apply.

Azure supports four primary scope levels:

  1. Management group
  2. Subscription
  3. Resource group
  4. Individual resource

Permissions assigned at a parent scope are inherited by child scopes.


2. Role Definitions vs. Role Assignments

This distinction is frequently tested.

Role definition

A role definition describes what permissions a role contains.

For example, a role definition might specify that a principal can:

  • Read virtual machines
  • Start and stop virtual machines
  • Restart virtual machines

A role definition is essentially the permission set.

Role assignment

A role assignment applies that role to a particular principal at a particular scope.

For example:

Assign the Virtual Machine Contributor role to the VM-Admins group at the Production-RG resource-group scope.

The role is the Virtual Machine Contributor role definition.

The group is the security principal.

The resource group is the scope.

Together, they form the role assignment.

Exam tip

Think:

Role definition = What can be done?

Role assignment = Who can do it and where?


3. What Are Azure Built-in Roles?

Azure built-in roles are predefined role definitions provided by Microsoft.

They are designed for common administrative and workload scenarios.

Azure has built-in roles covering areas such as:

  • General resource management
  • Compute
  • Networking
  • Storage
  • Databases
  • Containers
  • AI and machine learning
  • Security
  • Monitoring
  • Identity
  • Management and governance
  • Hybrid and multicloud environments

Built-in roles should generally be considered before creating custom roles.

Examples include:

Built-in roleGeneral purpose
OwnerFull access, including ability to assign Azure RBAC roles
ContributorManage Azure resources, but cannot assign Azure RBAC roles
ReaderView Azure resources without making changes
User Access AdministratorManage user access to Azure resources
Role Based Access Control AdministratorManage Azure RBAC role assignments
Virtual Machine ContributorManage virtual machines
Network ContributorManage networking resources
Storage Account ContributorManage storage account resources
Key Vault ReaderRead Key Vault metadata
Storage Blob Data ReaderRead blob data

The exact permissions of a role should always be evaluated rather than relying solely on the role’s name.


4. Owner vs. Contributor vs. Reader

These three roles are particularly important.

Owner

The Owner role grants full access to manage resources, including the ability to assign Azure RBAC roles.

This makes Owner a highly privileged role.

For example:

A user with Owner at the subscription scope can manage resources throughout that subscription and can grant Azure RBAC access to other principals.

Because of its power, the number of Owner assignments should be minimized.


Contributor

The Contributor role grants broad resource-management permissions.

A Contributor can generally create and manage resources but cannot assign Azure RBAC roles.

This distinction is extremely important.

For example:

A user who needs to create, modify, and delete virtual machines but should not be able to grant other users access may be a candidate for Contributor or a more narrowly scoped compute-specific role.

Common exam trap

Contributor ≠ Owner

Contributor does not have the permission to manage Azure RBAC role assignments.


Reader

The Reader role provides read-only access to Azure resources.

A Reader can inspect resources and their configurations but cannot modify them.

For example:

A security auditor needs to inspect the configuration of resources throughout a subscription but should not be able to make changes.

Reader may be appropriate, subject to whether additional permissions are needed for the specific data or security information being examined.


5. User Access Administrator

The User Access Administrator role is designed to manage access to Azure resources.

It can assign Azure RBAC roles.

This is different from Contributor.

Consider the following:

RoleManage resourcesAssign Azure RBAC roles
ReaderNoNo
ContributorYesNo
OwnerYesYes
User Access AdministratorAccess-management focusedYes

Therefore, if a user needs to manage access but doesn’t need broad resource-management permissions, User Access Administrator can be more appropriate than Owner.


6. Role Based Access Control Administrator

The Role Based Access Control Administrator role is another important role for the SC-500 exam.

It is designed specifically for managing user access to Azure resources through Azure RBAC.

It can:

  • Create role assignments
  • Delete role assignments
  • Manage Azure RBAC access

It provides a more focused access-management capability than Owner.

Microsoft specifically describes Role Based Access Control Administrator as a role designed for delegating role-assignment management.

Why this matters

Suppose an organization has a team responsible for administering Azure RBAC assignments.

Giving that team Owner permissions would provide much more power than necessary.

A security-conscious design could instead use Role Based Access Control Administrator, with an appropriately limited scope.

This better supports least privilege.


7. Built-in Roles Are Not the Same as Microsoft Entra Roles

Another important distinction is between:

Azure RBAC roles

and

Microsoft Entra roles

Azure RBAC controls access to Azure resources.

Microsoft Entra roles control administrative access to Microsoft Entra resources and directory functionality.

For example:

  • Azure RBAC can control who can manage an Azure Storage account.
  • Microsoft Entra roles can control directory administration activities.

Do not automatically assume that an Azure RBAC role controls Microsoft Entra directory administration.

They are related security concepts but are different authorization systems.


8. Understanding Scope

Scope is one of the most important concepts when assigning built-in roles.

The four Azure RBAC scopes are:

1. Management group

The broadest common scope.

Permissions can apply to subscriptions and resources contained within the management group hierarchy.

2. Subscription

Permissions apply throughout the subscription.

3. Resource group

Permissions apply to resources contained within that resource group.

4. Resource

Permissions apply to a specific resource.

The hierarchy is:

Management group → Subscription → Resource group → Resource

A role assignment at a parent scope is inherited by child scopes.


9. Why Scope Matters for Least Privilege

Consider an application that needs to read blobs from one storage account.

There are several possible ways to assign permissions.

Poor design

Assign a broad storage-related role at the subscription level.

The application may receive access to far more resources than necessary.

Better design

Assign the appropriate data-access role at the storage-account or even more narrowly applicable scope, when supported.

The principle is:

Use the smallest scope that satisfies the requirement.

Microsoft recommends limiting both the role and scope because doing so reduces the resources that could be affected if a security principal is compromised.


10. Role Inheritance

Suppose you assign:

Reader → Subscription A

The assignment is inherited by resources and resource groups beneath that subscription.

Similarly:

Contributor → Resource Group A

is inherited by resources inside Resource Group A.

This means that you don’t have to create individual role assignments for every resource.

However, inheritance can also create unexpected access if administrators aren’t careful.

Exam scenario

A user unexpectedly has Contributor access to a virtual machine.

You discover that the user does not have a Contributor assignment directly on the VM.

The user might have inherited Contributor permissions from:

  • The resource group
  • The subscription
  • A management group

Always investigate inherited assignments when troubleshooting access.


11. Choosing the Appropriate Built-in Role

A good process is:

Step 1: Identify the principal

Who needs access?

  • User?
  • Group?
  • Service principal?
  • Managed identity?

Step 2: Determine what the principal needs to do

For example:

  • View resources
  • Manage virtual machines
  • Manage networking
  • Read blob data
  • Manage Azure RBAC
  • Manage all resources

Step 3: Select the least-privileged suitable role

Prefer an appropriate built-in role over a broader role.

For example:

If someone only needs to read resources, don’t assign Contributor.

Step 4: Determine the narrowest practical scope

Ask:

What is the smallest scope at which this role can satisfy the requirement?

Step 5: Assign the role

The role can be assigned through:

  • Azure portal
  • Azure CLI
  • Azure PowerShell
  • Azure SDKs
  • REST APIs

12. Example: Developer Access

Suppose developers need to manage resources in a development resource group.

A possible design is:

Principal: Developers group

Role: Contributor

Scope: Development resource group

This gives developers broad resource-management capabilities within that resource group while avoiding unnecessary access to the rest of the subscription.

However, if developers only need to manage a particular resource type, a more narrowly scoped built-in role may be preferable.


13. Example: Security Auditor

Suppose a security auditor needs to inspect Azure resources but should not modify them.

A possible assignment is:

Principal: Security Auditors group

Role: Reader

Scope: Appropriate subscription or resource group

The scope should be limited to the resources the auditors actually need to review.

If they require specialized security information or data-plane access, additional permissions may be necessary.


14. Example: Application Access to Storage

Suppose an application uses a managed identity and needs to read blob data from one storage account.

A common mistake would be to grant a broad management role such as Contributor.

That is excessive because the application doesn’t need to manage the storage account.

Instead, consider a data-plane role such as:

Storage Blob Data Reader

at the narrowest suitable scope.

This illustrates an important security principle:

Management-plane access and data-plane access are different.

A role that lets someone manage a storage account does not necessarily mean they should be granted unrestricted access to the data stored within it.


15. Control Plane vs. Data Plane

Azure permissions can involve two broad areas.

Control plane

The control plane concerns management of Azure resources.

Examples include:

  • Creating a storage account
  • Changing resource configuration
  • Creating a virtual machine
  • Deleting a resource

Azure RBAC Actions and NotActions primarily describe control-plane operations.

Data plane

The data plane concerns access to the actual data contained within a service.

Examples include:

  • Reading blobs
  • Writing blobs
  • Reading Key Vault secrets
  • Accessing database data

Azure RBAC role definitions can also contain DataActions and NotDataActions for supported services.

Exam warning

Don’t assume:

“The user can manage the resource, therefore the user can access all of its data.”

That is not necessarily true.


16. Role Definition Permissions

A role definition can contain permission categories such as:

  • Actions
  • NotActions
  • DataActions
  • NotDataActions

Actions

Control-plane operations that the role permits.

NotActions

Control-plane operations excluded from the permissions represented by Actions.

DataActions

Data-plane operations that the role permits.

NotDataActions

Data-plane operations excluded from the permissions represented by DataActions.

For exam questions, pay attention to whether the requirement involves managing a resource or accessing the data within that resource.


17. When a Built-in Role Isn’t Enough

Azure provides many built-in roles, but sometimes none provides exactly the required permissions.

For example, suppose an organization needs a role that can:

  • Read specific resources
  • Perform several specific management operations
  • Not perform certain administrative operations
  • Be assigned only within particular organizational scopes

A custom Azure role may be appropriate.

However, the general strategy should be:

Start with built-in roles and create a custom role only when the built-in roles cannot satisfy the requirement with appropriate least privilege.


18. Built-in Roles Have Broad Availability

Built-in Azure roles are designed to be reusable across Azure environments.

Built-in role definitions have an AssignableScopes value of /, meaning they are available for assignment throughout Azure’s scope hierarchy.

This differs from custom roles, whose assignable scopes can be restricted to particular management groups, subscriptions, or resource groups.


19. Who Can Assign Azure RBAC Roles?

Having the ability to manage Azure resources does not automatically mean you can assign Azure RBAC roles.

For example:

Contributor

can manage resources but cannot assign Azure RBAC roles.

Permissions needed to create role assignments include:

Microsoft.Authorization/roleAssignments/write

Permissions needed to delete role assignments include:

Microsoft.Authorization/roleAssignments/delete

Roles such as:

  • Owner
  • User Access Administrator
  • Role Based Access Control Administrator

can provide the appropriate role-assignment management permissions, depending on scope and configuration.


20. Assign Roles to Groups When Practical

For organizations with multiple users performing the same job function, assigning roles to Microsoft Entra groups is generally preferable to creating separate assignments for every individual.

For example:

Security-Readers group → Reader → Security subscription scope

When users join or leave the security team, group membership can be managed without repeatedly changing Azure RBAC assignments.

This can improve:

  • Manageability
  • Consistency
  • Auditing
  • Access reviews
  • Least-privilege governance

Azure RBAC best practices recommend assigning roles to groups rather than individual users when practical.


21. Avoid Excessive Owner Assignments

Owner is one of the most powerful Azure RBAC roles.

An Owner can:

  • Manage Azure resources
  • Assign Azure RBAC roles

Because a compromised Owner account could have substantial impact, organizations should minimize the number of permanent Owner assignments.

Microsoft’s Azure RBAC guidance recommends limiting subscription Owner assignments.

For privileged administrative access, organizations should also consider Microsoft Entra Privileged Identity Management (PIM) where appropriate.


22. Azure RBAC and PIM

Azure RBAC answers:

What permissions does this principal have?

Microsoft Entra PIM helps answer:

When and under what conditions should a person receive privileged access?

For example, instead of permanently assigning an administrator a highly privileged role, an organization can use an eligible assignment and require activation when privileged work is needed.

This reduces standing privileged access.

Exam concept

Least privilege and just-in-time privileged access complement each other.


23. Azure RBAC vs. Azure Policy

These technologies serve different purposes.

Azure RBAC

Controls:

Who can perform which actions on Azure resources?

Azure Policy

Controls:

Which resource configurations are allowed, required, or evaluated?

For example:

RBAC requirement:

Only the Network Administrators group can modify virtual networks.

Azure Policy requirement:

Storage accounts must use a specified security configuration.

Do not use Azure RBAC as a replacement for Azure Policy.

Likewise, don’t use Azure Policy as a replacement for identity authorization.


24. Azure RBAC vs. Resource Locks

Resource locks and RBAC are also different.

Azure RBAC

Controls who can perform authorized operations.

Resource locks

Protect resources against certain management operations such as deletion or modification.

For example:

  • RBAC determines who is authorized to manage a resource.
  • A CanNotDelete lock can prevent deletion even when a principal otherwise has sufficient resource-management permissions.

Therefore, security governance may use both controls together.


25. Common SC-500 Exam Traps

Trap 1: Contributor can assign roles

False.

Contributor can manage resources but cannot assign Azure RBAC roles.


Trap 2: Owner is always the best administrator role

False.

Owner provides extensive permissions and should not be used when a more narrowly privileged role is sufficient.


Trap 3: Reader can modify resources

False.

Reader is intended for read-only access.


Trap 4: A resource-level assignment automatically gives subscription-wide access

False.

The assignment applies to the specified scope and does not automatically expand upward.


Trap 5: A subscription-level assignment applies only to the subscription object

False.

Permissions assigned at subscription scope are inherited by resources beneath the subscription.


Trap 6: Azure RBAC and Microsoft Entra roles are interchangeable

False.

They govern different areas of authorization.


Trap 7: Managing a storage account means automatically having data access

False.

Management-plane and data-plane permissions are distinct.


Trap 8: Custom roles should always be used for least privilege

False.

Start with built-in roles. Create custom roles when built-in roles don’t provide the appropriate permissions.


Trap 9: Contributor is always preferable to a specialized role

False.

A specialized role may provide significantly narrower permissions.


Trap 10: Role assignment and role definition mean the same thing

False.

The role definition describes permissions; the role assignment applies those permissions to a principal at a scope.


26. Exam-Focused Decision Guide

When faced with a scenario, use this mental checklist:

RequirementLikely approach
View Azure resourcesReader
Manage Azure resources without managing RBACContributor or a more specialized role
Full resource management plus RBAC managementOwner
Manage Azure RBAC assignmentsRole Based Access Control Administrator or User Access Administrator, depending on requirements
Manage only a particular workload typeSpecialized built-in role
Application needs blob read accessStorage Blob Data Reader or another appropriate data-plane role
Access should apply only to one resourceResource-level scope
Access should apply to resources in one resource groupResource-group scope
Access should span an entire subscriptionSubscription scope
Access should span multiple subscriptionsManagement-group scope
Built-in role is too broad or doesn’t meet requirementsConsider a custom role
Need to prevent insecure configurationsAzure Policy
Need to protect against accidental deletionResource lock
Need temporary privileged accessConsider PIM

27. Key Takeaways

For the SC-500 exam, remember these principles:

  1. Azure RBAC controls access to Azure resources.
  2. A role assignment consists of a principal, role definition, and scope.
  3. Built-in roles provide predefined permissions for common scenarios.
  4. Owner provides full resource management and can assign Azure RBAC roles.
  5. Contributor can manage resources but cannot assign Azure RBAC roles.
  6. Reader provides read-only resource access.
  7. User Access Administrator and Role Based Access Control Administrator are designed for access-management scenarios.
  8. Azure RBAC scopes are management group, subscription, resource group, and resource.
  9. Permissions assigned at a parent scope are inherited by child resources.
  10. Follow least privilege by selecting the narrowest appropriate role and scope.
  11. Assign roles to groups when practical.
  12. Distinguish control-plane permissions from data-plane permissions.
  13. Use a specialized built-in role when it provides the required permissions more precisely than Contributor or Owner.
  14. Consider custom roles only when built-in roles cannot meet the requirement appropriately.
  15. Use PIM to reduce standing privileged access.
  16. Don’t confuse Azure RBAC, Microsoft Entra roles, Azure Policy, and resource locks—they solve different security problems.

Practice Exam Questions

Question 1

A company has a security operations group that needs to view Azure resources throughout a subscription. The group must not be able to create, modify, or delete resources.

Which built-in Azure RBAC role should you assign?

A. Reader

B. Contributor

C. Owner

D. User Access Administrator

Correct Answer: A. Reader

Explanation:
Reader provides read-only access to Azure resources. Contributor and Owner provide substantially more permissions, while User Access Administrator is designed primarily for managing access rather than simply viewing resources.


Question 2

A developer needs to create, modify, and delete resources in a specific resource group. The developer must not be able to grant Azure RBAC permissions to other users.

Which role is the best choice if no more specialized built-in role meets the requirement?

A. Owner at the subscription scope

B. Contributor at the resource-group scope

C. User Access Administrator at the resource-group scope

D. Reader at the resource-group scope

Correct Answer: B. Contributor at the resource-group scope

Explanation:
Contributor can manage Azure resources but cannot assign Azure RBAC roles. Assigning it at the resource-group scope limits the developer’s access to that resource group rather than unnecessarily extending it to the subscription.


Question 3

An application uses a managed identity. It needs to read blob data from one Azure Storage account but does not need to modify the storage account configuration.

Which approach best follows least privilege?

A. Assign Owner at the subscription scope

B. Assign Contributor at the storage-account scope

C. Assign Reader at the resource-group scope

D. Assign an appropriate blob-data reader role at the narrowest suitable scope

Correct Answer: D. Assign an appropriate blob-data reader role at the narrowest suitable scope

Explanation:
The application needs access to blob data, not broad resource-management permissions. A data-plane role such as Storage Blob Data Reader is more appropriate than Owner, Contributor, or a general management-plane Reader assignment.


Question 4

A security administrator is responsible for creating and removing Azure RBAC role assignments but should not receive unnecessary permissions to manage Azure resources.

Which built-in role is specifically designed for Azure RBAC assignment management?

A. Contributor

B. Reader

C. Role Based Access Control Administrator

D. Storage Account Contributor

Correct Answer: C. Role Based Access Control Administrator

Explanation:
Role Based Access Control Administrator is specifically designed for managing access to Azure resources through Azure RBAC. Contributor cannot assign Azure RBAC roles.


Question 5

A user has the Reader role assigned at the subscription scope. What happens to that user’s Reader permissions for resources within that subscription?

A. The permissions are inherited by child resource groups and resources

B. The permissions apply only to the subscription object

C. The permissions apply only to resources created after the assignment

D. The permissions automatically become Contributor on child resources

Correct Answer: A. The permissions are inherited by child resource groups and resources

Explanation:
Azure RBAC uses hierarchical scopes. Role assignments at a parent scope are inherited by child scopes. A Reader assignment at subscription scope therefore provides Reader permissions to resources beneath that subscription.


Question 6

An organization wants developers to manage only virtual machines and related operations rather than all resource types in a resource group.

Which approach best follows the principle of least privilege?

A. Assign Owner to the developers

B. Assign Contributor at the subscription scope

C. Assign Reader at the VM scope

D. Use an appropriate VM-specific built-in role at the narrowest practical scope

Correct Answer: D. Use an appropriate VM-specific built-in role at the narrowest practical scope

Explanation:
A specialized built-in role can provide more focused permissions than Contributor or Owner. The assignment should also be scoped as narrowly as practical.


Question 7

An administrator has the Contributor role on a subscription. The administrator attempts to create an Azure RBAC role assignment and receives an authorization error.

Why?

A. Contributor cannot assign Azure RBAC roles

B. Contributor cannot manage resources at subscription scope

C. Contributor is a Microsoft Entra role rather than an Azure RBAC role

D. Contributor provides only read access

Correct Answer: A. Contributor cannot assign Azure RBAC roles

Explanation:
Contributor provides broad resource-management permissions but does not include permission to assign Azure RBAC roles. Role-assignment creation requires the appropriate Microsoft.Authorization/roleAssignments/write permission.


Question 8

A company has five subscriptions under a management group. A security team needs the same read-only Azure resource access across all five subscriptions.

Which scope could provide the access without creating separate Reader assignments for every subscription?

A. Individual resource

B. Resource group

C. Management group

D. Individual virtual machine

Correct Answer: C. Management group

Explanation:
A management group is above the subscription level in the Azure hierarchy. A Reader assignment at the appropriate management-group scope can be inherited by subscriptions and resources beneath it.


Question 9

A company needs to grant a team permissions that are not adequately provided by any existing built-in role. The team needs only a specific subset of management operations.

What should the administrator consider?

A. Assign Owner instead

B. Create an appropriate custom Azure role

C. Assign Contributor and rely on Azure Policy to remove permissions

D. Assign User Access Administrator

Correct Answer: B. Create an appropriate custom Azure role

Explanation:
Built-in roles should generally be preferred, but when they cannot provide the required permissions at the appropriate level, a custom role can be created. The custom role should contain only the permissions required.


Question 10

A company wants to minimize standing privileged access for administrators who occasionally need highly privileged Azure RBAC permissions.

Which solution best addresses this requirement?

A. Assign permanent Owner access to every administrator

B. Replace all administrators with Reader assignments

C. Use Microsoft Entra Privileged Identity Management to provide eligible or just-in-time privileged access

D. Assign Contributor at the management-group scope

Correct Answer: C. Use Microsoft Entra Privileged Identity Management to provide eligible or just-in-time privileged access

Explanation:
PIM can reduce standing privileged access by allowing privileged roles to be activated when needed rather than permanently assigning highly privileged access. This complements least-privilege RBAC design.


Final Thought

An important exam habit is to ask: “What is the minimum role, for the minimum scope, that satisfies the requirement?”


Go to the SC-500 Exam Prep Hub main page