AZ-500 — Frequently Asked Questions
Community-vetted answers to 10 common questions about this exam.
Questions from real practice questions
Each Q&A comes from a specific community question — follow the link for its full analysis.
Entra Permissions Management Highly Privileged Roles
No. While powerful, Exchange Administrator is not listed as a highly privileged role for the Azure AD Insights tab.
User Administrator is an administrative role but is not classified as 'highly privileged' in the context of Entra Permissions Management insights.
Azure DDoS Protection Plan Resource Eligibility
No. Web Apps are PaaS services and do not have their own public IP address managed by the user. They must be protected via an Application Gateway with WAF.
Yes. Although the plan itself is created in a specific region, it can protect VNets across multiple regions and subscriptions within the same tenant.
Defender for Cloud Protected Resources
Yes, Defender for Cloud monitors network traffic and configurations within Azure Virtual Networks to detect anomalies and threats.
Yes, Defender for Cloud provides threat protection for Key Vaults, detecting unusual access patterns and potential vulnerabilities.
Azure Defender for Servers Adaptive Application Controls Support
Server Core lacks a Graphical User Interface (GUI), which is required for the feature to present allowlist recommendations and manage settings.
No, they are incompatible. If AppLocker is enabled, Defender for Servers disables Adaptive Application Controls to prevent policy conflicts.
Azure Functions VNET Integration and NSG Control
No. Only Basic, Standard, Premium, Premium v2, Premium v3, and Elastic Premium tiers support Virtual Network Integration. Free and Basic (older) may not.
If a Function App uses VNET integration, its outbound traffic enters the specified subnet. NSGs attached to that subnet then filter this traffic.