{"id":1629,"date":"2021-01-19T02:21:59","date_gmt":"2021-01-19T02:21:59","guid":{"rendered":"https:\/\/reviewnprep.com\/blog\/?p=1629"},"modified":"2021-10-15T02:24:49","modified_gmt":"2021-10-15T02:24:49","slug":"preparation-guide-microsoft-security-technologies","status":"publish","type":"post","link":"https:\/\/reviewnprep.com\/blog\/preparation-guide-microsoft-security-technologies\/","title":{"rendered":"Preparation Guide for AZ-500: Microsoft Azure Security Technologies"},"content":{"rendered":"\n<p class=\"has-text-color, has-very-dark-gray-color\">After doing AZ-104, I started AZ-500. I was able to pass in my first attempt. I&#8217;m sharing with you all my preparation journey in this blog.<\/p>\n\n\n\n<p>Candidates for this exam should have subject matter expertise implementing security controls and threat protection, managing identity and access, and protecting data, applications, and networks. <\/p>\n\n\n\n<p>Responsibilities for an Azure Security Engineer include maintaining the security posture, identifying and remediating vulnerabilities by using a variety of security tools, implementing threat protection, and responding to security incident escalations.<\/p>\n\n\n\n<p>Azure Security Engineers often serve as part of a larger team dedicated to cloud-based management and security and may also secure hybrid environments as part of an end-to-end infrastructure.<\/p>\n\n\n\n<p class=\"has-text-color, has-very-dark-gray-color\">If your job role is to manage security for Azure, then you can take the&nbsp;<strong>AZ-500: Microsoft Azure Security Technologies&nbsp;<\/strong>which makes you a certified&nbsp;<strong>Azure Security Engineer Associate<\/strong>. <\/p>\n\n\n\n<p class=\"has-text-color, has-very-dark-gray-color\">However, the AZ-500&nbsp;exam&nbsp;is not equivalent to expert-level certification in Azure.<em> There is no pre-requisite for taking AZ-500 but in my opinion, take AZ-900 at a bare minimum.<\/em> It will prepare you with what format of questions you can expect.&nbsp;<\/p>\n\n\n\n<p class=\"has-text-color, has-very-dark-gray-color\">I got around 50 Exam questions in total: <strong>1 case study and the rest were MCQ questions<\/strong>. I did <strong><span style=\"text-decoration: underline;\">not<\/span><\/strong> get any labs.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What does AZ-500 expects from you?<\/h2>\n\n\n\n<p class=\"has-text-color, has-very-dark-gray-color\">AZ-500 Azure Security Engineer Exam expects you to know how to implement security controls, maintain the security posture, manages identity and access, and protect data, applications, and networks.&nbsp;If you do not want to spend too much money on this cert, check out the following free content that really helped me understand the concepts as opposed to only reading. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">AZ-500 Exam Details<\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>Number of questions in AZ-500 : <strong>40-60<\/strong><\/li><li>You will have <strong>150 minutes<\/strong> to complete the AZ-500 exam. In order to pass this exam, you will need:<\/li><li>A minimum score of <strong>70 percent<\/strong> on the overall exam<\/li><li>A minimum score of <strong>35 percent on each exam domain<\/strong><\/li><li>AZ-500 certification will cost you <strong>$165 USD<\/strong> including the additional taxes.<\/li><li>Exam will contain one or more case study with multiple questions including multiple choices and drag-and-drop items.<\/li><li>Question types include:<ol><li>Single-choice questions which may not be skipped or reviewed. You only get to answer these questions ONCE.<\/li><li>Single-choice questions (True\/False or Yes\/No)<\/li><li>Multiple-choice questions<\/li><li>Arrange in the correct sequence questions.<\/li><\/ol><\/li><\/ul>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Resources for AZ-500 Certification Exam&nbsp;<\/h2>\n\n\n\n<ol class=\"has-text-color, has-very-dark-gray-color has-black-color has-text-color wp-block-list\"><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/learn\/certifications\/exams\/az-500\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft official link<\/a><\/li><li><a href=\"https:\/\/www.pluralsight.com\/partners\/microsoft\/azure\" target=\"_blank\" rel=\"noreferrer noopener\">Free Pluralsight<\/a> &#8211; You can register and start for free. <\/li><li>I got a free offer for <a href=\"https:\/\/www.linkedin.com\/learning\/paths\/become-an-azure-security-engineer\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn learning<\/a> but IMO, it isn&#8217;t as effective as Pluralsight. You can create another account if you don&#8217;t want to pay. <\/li><li>Good old <a href=\"https:\/\/www.youtube.com\/playlist?list=PLlVtbbG169nGccbp8VSpAozu3w9xSQJoY\" target=\"_blank\" rel=\"noreferrer noopener\">Youtube<\/a> videos from John Savill.<\/li><li>Check out <a href=\"https:\/\/reviewnprep.com\/marketplace\/details\/microsoft-azure-az-500-certification-exam-practice-tests\/20\/EXAM\" target=\"_blank\" rel=\"noreferrer noopener\">Practice Exams here<\/a>. <\/li><\/ol>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><strong>Practice Exams on AZ-500 from ReviewNPrep for just $7.5 <a href=\"https:\/\/reviewnprep.com\/marketplace\/details\/microsoft-azure-az-500-certification-exam-practice-tests\/20\/EXAM\" target=\"_blank\" rel=\"noreferrer noopener\">Click here<\/a>.<\/strong> <\/p><\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">Important Pointers for AZ-500 Certification Exam&nbsp;<\/h2>\n\n\n\n<p class=\"has-text-color, has-very-dark-gray-color\">1. Manage your time well. If you do not know the answer, move on. There are some questions that you cannot revisit again. These are the ones where you have to suggest an implementation technique.&nbsp;<\/p>\n\n\n\n<p class=\"has-text-color, has-very-dark-gray-color\">2. I used the process of elimination for the ones I wasn&#8217;t sure of. In essence, remove the options you know for sure are wrong and then go with your gut feeling on the remaining left options.&nbsp;<\/p>\n\n\n\n<p class=\"has-black-color has-text-color\">3. You don&#8217;t have to go through all of the links provided in this study guide but highly recommended if you want to prepare to be a better security engineer.&nbsp;<\/p>\n\n\n\n<p class=\"has-text-color, has-very-dark-gray-color\">4. If you go through the exam contents, you&#8217;d find that most common keyword used is &#8220;configure&#8221;. This means the bare minimum expectation is that you know how to do it in the portal. There is nothing that beats hands-on. So, get your hands dirty in the Azure portal.&nbsp;<\/p>\n\n\n\n<p class=\"has-black-color has-text-color\">5. Few areas from which I got questions were NSG&#8217;s, Tags, conditional Policies, PIM, Azure monitor, alerts, resource locks, AD groups, MFA, Azure Bastion, SAS, KeyVault.&nbsp;There were a number of questions that required understanding of policies, lifecycles, access control, and more relating to Key Vault.<\/p>\n\n\n\n<p class=\"has-black-color has-text-color\">6. Many questions do not test you on one thing alone. It&#8217;s almost a combination of few services taken together. Example Azure Storage with RBAC. <\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><strong>NOTE: <strong>The content of this exam was updated on September 29, 2021<\/strong>.<\/strong><\/p><\/blockquote>\n\n\n\n<p class=\"has-text-color, has-very-dark-gray-color\">You may find the below links all over the internet, but this is my guide reading from MS documentation and hunting for links from other blogs and websites. I started with this in parallel with the official Microsoft training mentioned above.&nbsp;<\/p>\n\n\n\n<h2 class=\"has-text-color, has-very-dark-gray-color wp-block-heading\">Manage Identity and Access (30-35%)<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Manage Azure Active Directory identities<\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/develop\/app-objects-and-service-principals\" target=\"_blank\" rel=\"noreferrer noopener\" title=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/develop\/app-objects-and-service-principals\">Create and manage a managed identity for Azure resources<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/learn\/modules\/manage-users-and-groups-in-aad\/4-groups\" target=\"_blank\" rel=\"noreferrer noopener\">Manage Azure AD groups<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/learn\/modules\/manage-users-and-groups-in-aad\/3-users\" target=\"_blank\" rel=\"noreferrer noopener\">Manage Azure AD users<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/develop\/app-objects-and-service-principals\" target=\"_blank\" rel=\"noreferrer noopener\">Add or delete users using Azure Active Directory<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/develop\/app-objects-and-service-principals\" target=\"_blank\" rel=\"noreferrer noopener\">Assign or remove licenses in the Azure Active Directory portal<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/external-identities\/\" target=\"_blank\" rel=\"noreferrer noopener\">Manage external identities by using Azure AD<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/roles\/administrative-units\" target=\"_blank\" rel=\"noreferrer noopener\">Manage administrative units<\/a><\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Manage secure access by using Azure AD<\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/privileged-identity-management\/pim-resource-roles-overview-dashboards\" target=\"_blank\" rel=\"noreferrer noopener\" title=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/privileged-identity-management\/pim-resource-roles-overview-dashboards\">Configure Azure AD Privileged Identity Management (PIM)<\/a><\/li><li>Implement Conditional Access policies including Multi-Factor Authentication (MFA)<ul><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/conditional-access\/overview\" target=\"_blank\" rel=\"noreferrer noopener\">Conditional Access<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/privileged-identity-management\/pim-resource-roles-overview-dashboards\" target=\"_blank\" rel=\"noreferrer noopener\">Configure Azure Multi-Factor Authentication settings<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/privileged-identity-management\/pim-resource-roles-overview-dashboards\" target=\"_blank\" rel=\"noreferrer noopener\">Manage user settings for Azure Multi-Factor Authentication<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/privileged-identity-management\/pim-resource-roles-overview-dashboards\" target=\"_blank\" rel=\"noreferrer noopener\">Change your two-factor verification method and settings<\/a><\/li><\/ul><ul><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/conditional-access\/overview\" target=\"_blank\" rel=\"noreferrer noopener\">Plan a Conditional Access deployment<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/conditional-access\/overview\" target=\"_blank\" rel=\"noreferrer noopener\">Best practices<\/a><\/li><\/ul><\/li><li>Impliment Azure AD Identity Protection<ul><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/identity-protection\/overview-identity-protection\" target=\"_blank\" rel=\"noreferrer noopener\">What is Azure Active Directory Identity Protection?<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/identity-protection\/howto-identity-protection-configure-mfa-policy\" target=\"_blank\" rel=\"noreferrer noopener\">How To: Configure the Azure Multi-Factor Authentication registration policy<\/a><\/li><\/ul><\/li><li><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/identity-access-management\/passwordless-authentication\" target=\"_blank\" rel=\"noreferrer noopener\">Implement passwordless authentication<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/governance\/create-access-review\" target=\"_blank\" rel=\"noreferrer noopener\">Configure access reviews<\/a><\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Manage application access<\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/manage-apps\/add-application-portal-setup-sso\" target=\"_blank\" rel=\"noreferrer noopener\">Integrate single sign-on (SSO) and multiple identity providers for authentication<\/a><\/li><li>Create App Registration<ul><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/develop\/howto-create-service-principal-portal\" target=\"_blank\" rel=\"noreferrer noopener\">How to: Use the portal to create an Azure AD application and service principal that can access resources<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/develop\/howto-create-service-principal-portal\" target=\"_blank\" rel=\"noreferrer noopener\">Quickstart: Register an application with the Microsoft identity platform<\/a><\/li><\/ul><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/develop\/v2-permissions-and-consent\" target=\"_blank\" rel=\"noreferrer noopener\">Configure app registration permission scopes<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/develop\/howto-create-service-principal-portal\" target=\"_blank\" rel=\"noreferrer noopener\">Configure App Registration permission scopes<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/develop\/howto-create-service-principal-portal\" target=\"_blank\" rel=\"noreferrer noopener\">Manage App Registration permission consent<\/a><\/li><li>Manage API permission to Azure subscriptions and resources<ul><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/develop\/howto-create-service-principal-portal\" target=\"_blank\" rel=\"noreferrer noopener\">Authentication flows and application scenarios<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/develop\/howto-create-service-principal-portal\" target=\"_blank\" rel=\"noreferrer noopener\">Add or remove Azure role assignments using the REST API<\/a><\/li><\/ul><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure-sphere\/deployment\/authenticate-service-principal\" target=\"_blank\" rel=\"noreferrer noopener\">Configure an authentication method for a service principal<\/a><\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Manage access control<\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security-center\/security-center-management-groups\" target=\"_blank\" rel=\"noreferrer noopener\">Configure Azure role permissions for management groups, subscriptions, resource groups, and resources<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/role-based-access-control\/role-definitions\" target=\"_blank\" rel=\"noreferrer noopener\">Interpret role and resource permissions<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/role-based-access-control\/built-in-roles#:~:text=Azure%20role%2Dbased%20access%20control%20(Azure%20RBAC)%20has%20several,control%20access%20to%20Azure%20resources.\" target=\"_blank\" rel=\"noreferrer noopener\">Assign built-in Azure AD roles<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/role-based-access-control\/role-assignments-list-portal\" target=\"_blank\" rel=\"noreferrer noopener\">Interpret role and resource permissions<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/roles\/custom-create\" target=\"_blank\" rel=\"noreferrer noopener\">Create and assign custom roles, including Azure roles and Azure AD roles<\/a><\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Implement Platform Protection (15-20%)<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Implement advanced network security<\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li>Secure the connectivity of hybrid networks <ul><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/vpn-gateway\/vpn-gateway-about-vpngateways\" target=\"_blank\" rel=\"noreferrer noopener\">What is VPN Gateway?<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/vpn-gateway\/vpn-gateway-about-vpngateways\" target=\"_blank\" rel=\"noreferrer noopener\">Configure Azure Active Directory authentication for User VPN<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/vpn-gateway\/vpn-gateway-about-vpngateways\" target=\"_blank\" rel=\"noreferrer noopener\">What is Azure ExpressRoute?<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/vpn-gateway\/vpn-gateway-about-vpngateways\" target=\"_blank\" rel=\"noreferrer noopener\">ExpressRoute encryption<\/a><\/li><\/ul><\/li><li>Secure the connectivity of virtual network<ul><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/vpn-gateway\/vpn-gateway-about-vpngateways\" target=\"_blank\" rel=\"noreferrer noopener\">Create, change, or delete a network security group<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/vpn-gateway\/vpn-gateway-about-vpngateways\" target=\"_blank\" rel=\"noreferrer noopener\">Application security groups<\/a><\/li><\/ul><\/li><li>create and configure Azure Firewall Manager<ul><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/firewall\/overview\" target=\"_blank\" rel=\"noreferrer noopener\">What is Azure Firewall?<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/firewall\/overview\" target=\"_blank\" rel=\"noreferrer noopener\">Tutorial: Deploy and configure Azure Firewall using the Azure portal<\/a><\/li><\/ul><\/li><li>implement Azure Firewall Manager<ul><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/firewall-manager\/overview\" target=\"_blank\" rel=\"noreferrer noopener\">What is Azure Firewall Manager?<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/firewall-manager\/secure-cloud-network\" target=\"_blank\" rel=\"noreferrer noopener\">Tutorial: Secure your virtual hub using Azure Firewall Manager<\/a><\/li><\/ul><\/li><li>Create and configure Azure Application Gateway <ul><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/frontdoor\/front-door-overview\" target=\"_blank\" rel=\"noreferrer noopener\">What is Azure Front Door?<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/frontdoor\/front-door-overview\" target=\"_blank\" rel=\"noreferrer noopener\">Quickstart: Create a Front Door for a highly available global web application<\/a><\/li><\/ul><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/frontdoor\/quickstart-create-front-door\" target=\"_blank\" rel=\"noreferrer noopener\">Create and configure Azure Front Door<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/web-application-firewall\/ag\/ag-overview\" target=\"_blank\" rel=\"noreferrer noopener\" title=\"https:\/\/docs.microsoft.com\/en-us\/azure\/web-application-firewall\/ag\/ag-overview\">Create and configure a Web Application Firewall (WAF) <\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/key-vault\/general\/network-security\" target=\"_blank\" rel=\"noreferrer noopener\">Configure a resource firewall, including  storage account, Azure SQL, Azure Key Vault, or Azure App Service<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/azure-functions\/functions-networking-options\" target=\"_blank\" rel=\"noreferrer noopener\">Configure network isolation for Web Apps and Azure Functions<\/a><\/li><li>Implement Azure Service Endpoints<ul><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/storage\/common\/storage-network-security\" target=\"_blank\" rel=\"noreferrer noopener\">Virtual Network service endpoints<\/a><\/li><\/ul><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/private-link\/private-endpoint-overview\" target=\"_blank\" rel=\"noreferrer noopener\">Implement Azure Private Endpoints, including integrating with other services<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/private-link\/create-private-link-service-powershell\" target=\"_blank\" rel=\"noreferrer noopener\">Implement Azure Private Links<\/a><\/li><li>Implement DDoS protection<ul><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/storage\/common\/storage-network-security\" target=\"_blank\" rel=\"noreferrer noopener\">Azure DDoS Protection Standard overview<\/a><\/li><\/ul><\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Configure advanced security for compute<\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li>Configure Azure Endpoint protection for virtual machines (VMs)<ul><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security\/fundamentals\/antimalware\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Anti malware for Azure Cloud Services and Virtual Machines<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security\/fundamentals\/virtual-machines-overview\" target=\"_blank\" rel=\"noreferrer noopener\">Azure Virtual Machines security overview<\/a><\/li><\/ul><\/li><li>Implement and manage security updates for VMs<ul><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security\/fundamentals\/virtual-machines-overview\" target=\"_blank\" rel=\"noreferrer noopener\">Update Management overview<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security\/fundamentals\/virtual-machines-overview\" target=\"_blank\" rel=\"noreferrer noopener\">Manage updates and patches for your Azure VMs<\/a><\/li><\/ul><\/li><li>Configure security for container services<ul><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security-center\/container-security\" target=\"_blank\" rel=\"noreferrer noopener\">Container security in Security Center<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security-center\/container-security\" target=\"_blank\" rel=\"noreferrer noopener\">Security considerations for Azure Container Instances<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security-center\/container-security\" target=\"_blank\" rel=\"noreferrer noopener\">Security concepts for applications and clusters in Azure Kubernetes Service (AKS)<\/a><\/li><\/ul><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/container-registry\/container-registry-roles?tabs=azure-cli\" target=\"_blank\" rel=\"noreferrer noopener\">Manage access to Azure Container Registry<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/architecture\/serverless-quest\/functions-app-security\" target=\"_blank\" rel=\"noreferrer noopener\">Configure security for serverless compute<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/app-service\/overview-security\" target=\"_blank\" rel=\"noreferrer noopener\">Configure security for an Azure App Service<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security\/fundamentals\/encryption-atrest\" target=\"_blank\" rel=\"noreferrer noopener\">Configure encryption at rest<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security\/fundamentals\/encryption-overview#encryption-of-data-in-transit\" target=\"_blank\" rel=\"noreferrer noopener\">Configure encryption in transit<\/a><\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Manage Security Operations (25-30%)<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Configure centralized policy management<\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security-center\/custom-security-policies?pivots=azure-portal\" target=\"_blank\" rel=\"noreferrer noopener\">Configure a custom security policy<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/governance\/policy\/concepts\/initiative-definition-structure\" target=\"_blank\" rel=\"noreferrer noopener\">Create a policy initiative<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security-center\/policy-reference\" target=\"_blank\" rel=\"noreferrer noopener\">Configure security settings and auditing by using Azure Policy<\/a><\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Configure and manage threat protection<\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security-center\/enable-azure-defender\" target=\"_blank\" rel=\"noreferrer noopener\" title=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security-center\/enable-azure-defender\">Configure Azure Defender for Servers (not including Microsoft Defender for Endpoint)<\/a><\/li><li>Evaluate vulnerability scans from Azure Defender<ul><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security-center\/built-in-vulnerability-assessment\" target=\"_blank\" rel=\"noreferrer noopener\">Integrated vulnerability scanner for virtual machines (Standard tier only)<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security-center\/security-center-vulnerability-assessment-recommendations\" target=\"_blank\" rel=\"noreferrer noopener\">Vulnerability assessments for your Azure Virtual Machines<\/a><\/li><\/ul><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security-center\/defender-for-sql-usage\" target=\"_blank\" rel=\"noreferrer noopener\" title=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security-center\/defender-for-sql-usage\">Configure Azure Defender for SQL<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security\/develop\/threat-modeling-tool\" target=\"_blank\" rel=\"noreferrer noopener\">Use the Microsoft Threat Modeling Tool<\/a><\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Configure and manage security monitoring solutions<\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li>Create and customize alerts rules by using Azure Monitor<ul><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/tutorial-detect-threats-built-in\" target=\"_blank\" rel=\"noreferrer noopener\">Tutorial: Detect threats out-of-the-box<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/tutorial-detect-threats-built-in\" target=\"_blank\" rel=\"noreferrer noopener\">What is Azure Sentinel?&nbsp;<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/tutorial-detect-threats-built-in\" target=\"_blank\" rel=\"noreferrer noopener\">Tutorial: Set up automated threat responses in Azure Sentinel<\/a><\/li><\/ul><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/azure-monitor\/essentials\/diagnostic-settings?tabs=CMD\" target=\"_blank\" rel=\"noreferrer noopener\">Configure diagnostic logging and log retention by using Azure Monitor<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/azure-monitor\/logs\/data-platform-logs\" target=\"_blank\" rel=\"noreferrer noopener\" title=\"https:\/\/docs.microsoft.com\/en-us\/azure\/azure-monitor\/logs\/data-platform-logs\">Monitor security logs by using Azure Monitor<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/customize-alert-details\" target=\"_blank\" rel=\"noreferrer noopener\" title=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/customize-alert-details\">Create and customize alert rules in  Azure Sentinel<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/connect-data-sources\" target=\"_blank\" rel=\"noreferrer noopener\">Configure connectors in Azure Sentinel<\/a><\/li><li>Evaluate alerts and incidents in Azure Sentinel<ul><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/tutorial-monitor-your-data\" target=\"_blank\" rel=\"noreferrer noopener\">Tutorial: Visualize and monitor your data<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/tutorial-monitor-your-data\" target=\"_blank\" rel=\"noreferrer noopener\">Tutorial: Investigate incidents with Azure Sentinel<\/a><\/li><\/ul><\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Secure Data and Applications (25-30%)<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Configure security for storage<\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li>Configure access control for storage accounts<ul><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/storage\/common\/storage-auth\" target=\"_blank\" rel=\"noreferrer noopener\">Authorizing access to data in Azure Storage<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/storage\/common\/storage-auth\" target=\"_blank\" rel=\"noreferrer noopener\">Authorize access to blobs and queues using Azure Active Directory<\/a><\/li><\/ul><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/storage\/common\/storage-auth\" target=\"_blank\" rel=\"noreferrer noopener\">Configure storage accounts<\/a> access keys<\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/storage\/common\/storage-auth-aad\" target=\"_blank\" rel=\"noreferrer noopener\">Configure Azure AD authentication for Azure Storage<\/a> and Azure files<\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/governance\/entitlement-management-delegate\" target=\"_blank\" rel=\"noreferrer noopener\">Configure delegated access<\/a><\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Configure security for data<\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li>Enable database authentication by using Azure AD <ul><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/app-service\/app-service-web-tutorial-connect-msi\" target=\"_blank\" rel=\"noreferrer noopener\">Tutorial: Secure Azure SQL Database connection from App Service using a managed identity<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/app-service\/app-service-web-tutorial-connect-msi\" target=\"_blank\" rel=\"noreferrer noopener\">Configure and manage Azure Active Directory authentication with SQL<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/app-service\/app-service-web-tutorial-connect-msi\" target=\"_blank\" rel=\"noreferrer noopener\">Use Azure Active Directory Authentication for authentication with SQL<\/a><\/li><\/ul><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/app-service\/app-service-web-tutorial-connect-msi\" target=\"_blank\" rel=\"noreferrer noopener\">Enable database auditing<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/azure-sql\/database\/dynamic-data-masking-overview\" title=\"https:\/\/docs.microsoft.com\/en-us\/azure\/azure-sql\/database\/dynamic-data-masking-overview\" target=\"_blank\" rel=\"noreferrer noopener\">Configure dynamic masking on SQL workloads<\/a><\/li><li>Implement database encryption for Azure SQL Database<ul><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sql-database\/sql-database-security-overview\" target=\"_blank\" rel=\"noreferrer noopener\">Transparent data encryption for SQL Database and Azure Synapse<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sql-database\/sql-database-security-overview\" target=\"_blank\" rel=\"noreferrer noopener\">An overview of Azure SQL Database security capabilities<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sql-database\/sql-database-security-overview\" target=\"_blank\" rel=\"noreferrer noopener\">Azure encryption overview<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sql-database\/sql-database-security-overview\" target=\"_blank\" rel=\"noreferrer noopener\">An overview of Azure SQL Database security capabilities<\/a><\/li><\/ul><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/learn\/modules\/secure-and-isolate-with-nsg-and-service-endpoints\/\" target=\"_blank\" rel=\"noreferrer noopener\">Implement network isolation for data solutions, including Azure Synapse Analytics and Azure Cosmos DB<\/a><\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Configure and manage Azure Key Vault<\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/key-vault\/general\/quick-create-portal#:~:text=.azure.com.-,Create%20a%20vault,Key%20Vault%20section%2C%20choose%20Create.\" target=\"_blank\" rel=\"noreferrer noopener\">Create and configure Key Vault<\/a><\/li><li>Configure access to Key Vault<ul><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/key-vault\/general\/overview\" target=\"_blank\" rel=\"noreferrer noopener\">About Azure Key Vault<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/key-vault\/general\/secure-your-key-vault\" target=\"_blank\" rel=\"noreferrer noopener\">Secure access to a key vault<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/key-vault\/general\/secure-your-key-vault\" target=\"_blank\" rel=\"noreferrer noopener\">Provide Key Vault authentication with a managed identity<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/key-vault\/general\/secure-your-key-vault\" target=\"_blank\" rel=\"noreferrer noopener\">Provide Key Vault authentication with an access control policy<\/a><\/li><\/ul><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/key-vault\/certificates\/certificate-scenarios\" target=\"_blank\" rel=\"noreferrer noopener\">Manage certificates<\/a> , secrets, and keys<\/li><li>Configure key rotation<ul><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/key-vault\/secrets\/key-rotation-log-monitoring?WT.mc_id=thomasmaurer-blog-thmaure\" target=\"_blank\" rel=\"noreferrer noopener\">Set up Azure Key Vault with key rotation and auditing<\/a><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/learn\/modules\/manage-secrets-with-azure-key-vault\" target=\"_blank\" rel=\"noreferrer noopener\">Tutorial: Configure certificate auto-rotation in Key Vault<\/a><\/li><\/ul><\/li><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/key-vault\/general\/backup?tabs=azure-cli\" target=\"_blank\" rel=\"noreferrer noopener\">Configure backup and recovery of certificates, secrets, and keys<\/a><\/li><\/ul>\n\n\n\n<p class=\"has-black-color has-text-color\"><strong>Good Luck with your exams.<\/strong><\/p>\n\n\n\n<p>Author: Ralph Bryant loves working on Azure and helping others succeed in their career. You can connect with him on <a href=\"https:\/\/www.linkedin.com\/in\/ralph-bryant-6b3677168\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>. <\/p>\n\n\n\n<p class=\"has-black-color has-text-color\">ReviewNPrep is a community-based website. Follow us on <a href=\"https:\/\/www.linkedin.com\/company\/35671994\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a> to stay in touch with the certification community. <\/p>\n\n\n\n<p class=\"has-black-color has-text-color\">Need help from the community in preparation. Join our <a href=\"https:\/\/reviewnprep.com\/forums\" target=\"_blank\" rel=\"noreferrer noopener\">Forums<\/a>.<\/p>\n\n\n\n<p class=\"has-black-color has-text-color\">Check out <a href=\"https:\/\/reviewnprep.com\/marketplace\/details\/microsoft-azure-az-500-certification-exam-practice-tests\/20\/EXAM\" target=\"_blank\" rel=\"noreferrer noopener\">AZ-500 Certification Practice Exams<\/a> on <a href=\"http:\/\/marketplace.reviewnprep.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">ReviewNPrep Marketplace<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I got around 50 Exam questions in total: 1 case study, and the rest were MCQ questions. I did not get any labs. <\/p>\n","protected":false},"author":1,"featured_media":2523,"comment_status":"open","ping_status":"open","sticky":true,"template":"","format":"standard","meta":{"footnotes":""},"categories":[30,150,3],"tags":[152,32,151],"class_list":["post-1629","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-azure","category-azure-security","category-reviewnprep","tag-az-500","tag-azure","tag-azure-security"],"_links":{"self":[{"href":"https:\/\/reviewnprep.com\/blog\/wp-json\/wp\/v2\/posts\/1629"}],"collection":[{"href":"https:\/\/reviewnprep.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/reviewnprep.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/reviewnprep.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/reviewnprep.com\/blog\/wp-json\/wp\/v2\/comments?post=1629"}],"version-history":[{"count":21,"href":"https:\/\/reviewnprep.com\/blog\/wp-json\/wp\/v2\/posts\/1629\/revisions"}],"predecessor-version":[{"id":2750,"href":"https:\/\/reviewnprep.com\/blog\/wp-json\/wp\/v2\/posts\/1629\/revisions\/2750"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/reviewnprep.com\/blog\/wp-json\/wp\/v2\/media\/2523"}],"wp:attachment":[{"href":"https:\/\/reviewnprep.com\/blog\/wp-json\/wp\/v2\/media?parent=1629"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/reviewnprep.com\/blog\/wp-json\/wp\/v2\/categories?post=1629"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/reviewnprep.com\/blog\/wp-json\/wp\/v2\/tags?post=1629"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}