Azure Mastery

Microsoft Certification AZ-500

Predict your score. Pass with proof.

On-device AI scores your readiness, builds an adaptive study plan, and flags topics fading from memory — before they cost you the exam.

346 practice questions AI score prediction 100% offline
Download free iPhone & iPad · Free to start

AZ-500 Practice Questions & SC-500 Next Step — Microsoft Azure Security Engineer

Get exam-ready for AZ-500 (Microsoft Azure Security Engineer) on iPhone or iPad before it retires on 31 August 2026, or continue with its SC-500 successor. Azure Mastery predicts your readiness across all four AZ-500 domains, builds a personalised study plan from your weak spots, and keeps core study private and available offline.

The exam

What is the AZ-500 exam?

AZ-500 is the Microsoft Certified: Azure Security Engineer Associate exam — the credential hiring managers expect when posting "Cloud Security Engineer", "Azure Security Specialist", or "Cloud Security Operations" roles. It's the natural next step after AZ-104 for anyone administering Azure environments who's now responsible for the security posture of those environments. It also pairs with SC-900 on the way up to the SC-100 Cybersecurity Architect Expert credential.

AZ-500 is hands-on and operational. It validates that you can manage identity and access (Microsoft Entra ID, Conditional Access, PIM, application access); secure networking (NSGs, Azure Firewall, DDoS Protection, Private Link); secure compute, storage, and databases (encryption, key management, Defender plans for SQL / Storage / Containers); and run a live security operation using Microsoft Defender for Cloud and Microsoft Sentinel — including KQL queries, analytics rules, and incident triage. Expect scenario questions that show you a config snippet or attack signal and ask what you'd do next.

Microsoft updated the AZ-500 skills outline on 22 January 2026. Every question in Azure Mastery's AZ-500 bank is mapped to the current outline — no leftover questions on retired services. Read the official outline at learn.microsoft.com.

AZ-500 retires on 31 August 2026. Microsoft is transitioning the role to SC-500: Cloud and AI Security Engineer Associate. Sit AZ-500 before retirement if you want the Azure Security Engineer Associate credential; start with SC-500 if you are planning the longer-term cloud and AI security route.

Skills measured · January 2026

AZ-500 exam objectives

Four domains, with weights set by Microsoft's January 2026 update. Every domain summary below is paraphrased from the official skills outline; bullet-level objectives in Azure Mastery are tagged so you always know which domain you're being tested on and where your weak spots cluster.

Aura presents a visual map of identity, compute, networking, and Azure operations skills.
Azure skill map

Secure identity and access15–20%

Explore key topics

The Microsoft Entra surface end-to-end. Cover identity types (members, guests, hybrid identities), authentication (passwordless, MFA, password protection), Conditional Access design (named locations, sign-in risk, session controls), Privileged Identity Management (just-in-time activation, access reviews, eligibility), and Microsoft Entra ID Protection (risky users, risky sign-ins). Plus securing access to Azure resources via RBAC, Azure ABAC, custom roles, and managed identities. Around 6–12 questions per sitting.

Secure networking20–25%

Explore key topics

Defence-in-depth at the network layer. Configure perimeter security with Azure Firewall (rules, threat intelligence, hierarchies via Firewall Manager), Azure DDoS Protection, Web Application Firewall on Application Gateway and Front Door. Network segmentation with NSGs, application security groups, service tags. Private connectivity via Private Link, Private Endpoints, and service endpoints. Plus Azure Bastion, JIT VM access, ExpressRoute and VPN security. Around 8–15 questions.

Secure compute, storage, and databases20–25%

Explore key topics

Harden the workload tier. Compute: VM updates and disk encryption (host encryption, ADE, customer-managed keys), Azure Kubernetes Service security (network policies, Microsoft Entra integration, secrets), App Service network restrictions and authentication, container registry signing and scanning. Storage: SAS tokens, stored access policies, customer-managed keys, immutable storage. Databases: SQL TDE, Always Encrypted, dynamic data masking, Microsoft Defender for SQL. Plus Azure Key Vault as the cross-cutting story — keys, secrets, certificates, access policies vs RBAC. Around 8–15 questions.

Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel30–35%

Explore key topics

The largest domain by weight, and the operational core of the role. Microsoft Defender for Cloud: Secure Score, regulatory compliance (Azure Security Benchmark, custom standards), workload protection plans (Servers, App Service, Storage, SQL, Containers), security recommendations and exemptions, and the Cloud Security Posture Management surface. Microsoft Sentinel: data connectors (Azure activity, Microsoft 365, Defender XDR), analytics rules and watchlists, incident investigation, hunting with KQL, automation via playbooks (Logic Apps), workbooks. Plus security alert lifecycle and Defender for Cloud → Sentinel integration. Around 12–20 questions.

Designed for AZ-500

How Azure Mastery helps you pass AZ-500

Azure Mastery ships with 346 AZ-500 practice questions, every one written specifically against the current (January 2026) skills outline. Each question carries a domain tag mapped to the official four domains (identity and access, networking, compute/storage/databases, Defender for Cloud + Sentinel), so you always know which area you're being tested on and where your weak spots are clustered. KQL snippets, Conditional Access JSON, and Defender plan scenarios appear in roughly a third of the questions — matching the format of the live exam.

The on-device Exam IQ engine predicts your AZ-500 score before you sit the exam. After roughly 30 questions it has enough signal to give a confidence-scored prediction (e.g. "786 ±37, 68% confidence") — and tells you the specific topics that are dragging your readiness down. No vague "study more" advice; just a ranked list of objectives where improvement would move your score the furthest.

The adaptive study plan rebuilds itself from your answer history. Get a Conditional Access scenario wrong? You'll see another Entra access-management question in the next session. Master "Defender for SQL vs Defender for Storage" three sessions running and the engine backs off, surfacing fresh Sentinel KQL or Key Vault scenarios. The plan optimises for the gap between where you are and the 700 pass score, not for blind volume.

Knowledge decay tracking matters more for AZ-500 than for foundational exams — four security domains span a lot of surface area, and the topic you mastered three weeks into your study window is the topic you'll forget by exam day if you stop revising. Azure Mastery tracks every topic's decay curve and flags topics approaching expiry. The padlock icon on the Today screen is your "revisit before you forget" cue, and weak-spot drills automatically pull from decayed topics first.

Real exam simulation mode runs at AZ-500's actual length and time pressure: a randomised 40–60-question set drawn from the full 346-question bank, weighted by domain percentages from the January 2026 outline, with the 100-minute timer running and no jumping back to flag-and-review. It's the closest you can get to the live Pearson VUE / online-proctored experience without sitting the exam.

Answer Coach turns each missed answer into a private, grounded lesson: the misconception, key distinction, and rule to remember. It always uses authored certification guidance; on supported devices, an optional on-device model may rewrite the note only when it passes grounding checks.

During your first week, Aura adapts the next step as you go. Every session ends with a concise recap of what changed, what to focus on, and the best follow-up.

Everything essential runs on-device. Your answer history, readiness gauge, and coaching stay private. Optional sync uses your private iCloud account; there is no Azure Mastery account, tracking, or external processing server.

6-week study plan

Suggested AZ-500 study plan

Most candidates pass AZ-500 after four to eight weeks of focused study, depending on prior Azure security experience. The six-week plan below maps onto the four AZ-500 domains, Azure Mastery's adaptive sessions, and the in-app exam simulator. Adjust pace to taste — the readiness gauge tells you when you're done, not the calendar.

  1. Identity and networking foundations

    • Days 1–3: Microsoft Entra identity types, authentication methods, password protection, MFA, passwordless. Conditional Access rules — named locations, sign-in risk, session controls.
    • Days 4–6: Privileged Identity Management (eligibility, activation, access reviews), Microsoft Entra ID Protection (risky users, risky sign-ins), application access (enterprise apps, app registrations, app proxy).
    • Days 7–10: Azure RBAC, custom roles, Azure ABAC, managed identities. Then network segmentation: NSGs, ASGs, service tags. Azure Bastion, JIT VM access.
    • Days 11–14: Azure Firewall (rules, threat intelligence, Firewall Manager), DDoS Protection, Web Application Firewall on App Gateway and Front Door. Private Link / Private Endpoints / service endpoints.
  2. Workload protection and Key Vault

    • Days 15–17: Compute hardening — VM updates, disk encryption (host encryption, ADE, customer-managed keys), AKS security (network policies, Microsoft Entra integration, secrets management).
    • Days 18–20: App Service security (network restrictions, authentication, custom domains/TLS), Container Registry (signing, scanning), Container Apps and Container Instances security.
    • Days 21–23: Storage security — SAS tokens, stored access policies, customer-managed keys, immutable storage. Database security — TDE, Always Encrypted, dynamic data masking, Defender for SQL.
    • Days 24–28: Azure Key Vault end-to-end — keys, secrets, certificates, access policies vs RBAC, soft-delete and purge protection. The cross-cutting story — every other workload depends on it.
  3. Defender for Cloud, Sentinel, simulate

    • Days 29–32: Microsoft Defender for Cloud — Secure Score, regulatory compliance, workload protection plans (Servers, App Service, Storage, SQL, Containers), recommendations and exemptions, just-in-time VM access.
    • Days 33–37: Microsoft Sentinel — data connectors, analytics rules and watchlists, KQL hunting queries, incident investigation, automation via Logic App playbooks, workbooks.
    • Days 38–40: Run Focus Weak Spots every morning — the app surfaces the highest-leverage questions for your weakest domains. Defender + Sentinel is 30–35% of the exam, so weight your time accordingly.
    • Days 41–42: Two end-to-end Exam Simulator runs at full 100-minute length. Review carefully after each. If readiness gauge is 750+ with reasonable confidence, schedule the exam.

Inside the app

Every Microsoft question type, on iPhone

AZ-500's question bank uses the same formats Microsoft puts on the live exam — not just multiple choice. Each visualisation below is a faithful mock of how the type renders inside Azure Mastery on iPhone and iPad. Exam-simulator mode runs all of them at full 100-minute length with no flag-and-review jumps, mirroring Pearson VUE.

Multiple choice

A real AZ-500 question-bank example with one correct answer. The app explains every option after you answer.

Exam-specific sample

Multi-select

A real AZ-500 multi-select item. Every required selection must be correct to earn the mark.

All-or-nothing

Drag-and-drop

A real AZ-500 interactive-format prompt, rendered for touch on iPhone and iPad.

Interactive item

Hotspot

A real AZ-500 prompt that tests recognition inside a visual or contextual interface.

Tap target

Case studies

A real AZ-500 case-study scenario with linked questions that share the same requirements and environment.

Multi-question

Answer Coach

Answer Coach uses the bank's authored rationale to explain the misconception, key distinction, and rule to remember. On supported devices, an optional on-device model may rewrite the note only when it passes grounding checks.

App exclusive

Frequently asked

AZ-500 FAQs

How much does the AZ-500 exam cost?

The AZ-500 voucher is USD $165 in the United States, with regional pricing. AZ-500 retires on 31 August 2026, so only book it if you can prepare and sit before that date; candidates starting a longer study plan should use SC-500, the current Cloud and AI Security Engineer exam.

Does the AZ-500 certification expire?

AZ-500 and the Azure Security Engineer Associate certification retire on 31 August 2026. Microsoft states that renewal assessments are no longer available after a certification retires. If you are starting now and cannot sit AZ-500 before retirement, prepare for SC-500 instead.

What is the AZ-500 retake policy if I fail?

The first retake is allowed after 24 hours. Second and third retakes each require a 14-day wait. Microsoft caps retakes at five attempts per 12-month rolling period. Each attempt requires a new voucher purchase.

How long should I study for AZ-500?

If you intend to sit AZ-500 before 31 August 2026, focus on identity and access, platform protection, security operations, and data and application security across Azure. Build hands-on familiarity with Entra, Defender for Cloud, Sentinel, Key Vault, Azure networking, and workload protection. Otherwise start with SC-500, its current successor.

AZ-500 vs AZ-104 — should I do AZ-104 first?

Microsoft strongly recommends AZ-104 first, and it shows. AZ-500 assumes you already know how Azure compute, networking, and storage work day-to-day — it's the security overlay on top of that knowledge. If you've never deployed a VM or configured a VNet outside of fundamentals, take AZ-104 (Microsoft Azure Administrator) first; you'll save weeks on AZ-500 prep. If you have a year or more of hands-on Azure ops, you can skip AZ-104 and go straight in. Some employers want both anyway.

AZ-500 vs SC-200 — which next on the security track?

Different roles. AZ-500 is the Azure Security Engineer cert — it's about hardening Azure resources end-to-end. SC-200 is the Security Operations Analyst cert — it's about running Microsoft Defender XDR and Sentinel as a SOC analyst, with much heavier focus on M365 and incident triage workflows. If your day job is securing Azure workloads, AZ-500. If it's running detection-and-response across the Microsoft estate, SC-200. Many Cybersecurity Architect Expert candidates hold both, with SC-900 as the connective fundamentals.

Where AZ-500 fits

Certification paths that include AZ-500

AZ-500 is the Azure-specific security Associate cert. It pairs with SC-900 on the way into security work, and feeds into the SC-100 Cybersecurity Architect Expert credential alongside SC-200 / SC-300. Tap any linked exam below to see its dedicated study app page.

Cybersecurity Architect Expert path

Expert tier
  1. SC-900 Fundamentals (optional)
  2. AZ-500 prereq option
  3. or SC-200 prereq option
  4. SC-100 Cybersecurity Architect exam
  5. Cybersecurity Architect Expert credential

Ready to pass AZ-500?

Download Azure Mastery free. 346 AZ-500 practice questions across all four domains, AI score prediction, full-length exam simulator, adaptive study plan. iPhone & iPad.

Download Azure Mastery — free iPhone & iPad · Free to start · No account required