AZ-500 Exam Explained: Domains, Difficulty and a Study Plan
AZ-500 assumes AZ-104 skills and tests how to secure them: Entra ID, networking controls, compute and data protection, and security operations with Defender and Sentinel. Format, difficulty and an eight-week plan.
AZ-500 Exam Explained: Domains, Difficulty and a Study Plan
AZ-500 is the Azure exam that assumes you already passed AZ-104 in spirit, even though nothing enforces it. Microsoft's Azure Security Engineer exam does not teach you what a virtual network or a managed identity is; it asks how to secure them, and it asks in the language of a working security engineer: Entra ID Conditional Access policies, Key Vault access models, Defender for Cloud plans, Sentinel analytics rules.
Candidates who administer Azure daily and have touched the security tooling usually find AZ-500 a fair, dense exam. Candidates who arrive from a general security background without Azure hands-on time find the questions readable and the answers unfamiliar. This guide explains what the exam covers, what makes it difficult, and how to prepare in a way that matches the skills outline.
AZ-500 at a glance
Exam
AZ-500: Microsoft Azure Security Technologies
Certification earned
Microsoft Certified: Azure Security Engineer Associate
Time
100 minutes of exam time
Questions
40 to 60, mixed formats, including a case study
Passing score
700 on a 1 to 1000 scale
Fee
$165 USD; varies by country
Validity
One year, renewed free through an online assessment on Microsoft Learn
Prerequisites
None enforced. Microsoft recommends AZ-104 level administration skills and hands-on experience with Azure security features
What AZ-500 actually tests
The skills outline has four areas, and their weights are close to equal, so there is no domain you can afford to skim.
Manage identity and access (25 to 30 percent). Microsoft Entra ID at depth: users, groups, external identities, Privileged Identity Management, Conditional Access policies and their conditions, multifactor authentication settings, passwordless options, identity protection risk policies, application registrations and permissions, managed identities, and role-based access control for Azure resources. Roughly a quarter of the exam, and the area where wording matters most: which policy condition, which role, which scope.
Secure networking (20 to 25 percent). Network security groups and application security groups, Azure Firewall and its policy hierarchy, Web Application Firewall on Application Gateway and Front Door, DDoS Protection, private endpoints and Private Link, service endpoints, Azure Bastion, just-in-time VM access, and encryption in transit. Expect diagrams and "which control satisfies this requirement with the least exposure" questions.
Secure compute, storage, and databases (20 to 25 percent). Defender for Servers and endpoint protection, disk encryption options, container security for AKS and ACR, App Service security settings, storage account security (keys, SAS, immutability, encryption scopes), Azure SQL security (auditing, dynamic data masking, Always Encrypted, transparent data encryption), and Key Vault for keys, secrets and certificates, including access policies versus RBAC and soft delete with purge protection.
Manage security operations (25 to 30 percent). Azure Policy and initiatives for governance, Defender for Cloud (secure score, recommendations, regulatory compliance, workload protection plans), Microsoft Sentinel (data connectors, analytics rules, workbooks, automation), Azure Monitor alerts for security signals, and diagnostic logging. This is where the exam rewards candidates who have actually deployed Sentinel or turned on Defender plans.
What makes AZ-500 difficult
Depth in Entra ID. Conditional Access alone can generate a dozen questions: named locations, sign-in risk versus user risk, session controls, report-only mode, exclusion of break-glass accounts. If you have not built policies and watched them block a sign-in, the options all look plausible.
Product overlap. Defender for Cloud versus Sentinel versus Azure Monitor; Azure Firewall versus NSG versus WAF; Key Vault access policies versus RBAC. The exam sets a requirement and expects the one product that fits it precisely. Learn what each does not do.
Case studies. As on AZ-104, the case study presents a company, its current environment and a list of requirements, then a block of questions you cannot revisit. The requirements section contains the answers; read it slowly and skim the rest.
Yes/no series. Groups of statements about the same scenario, scored individually, no returning. There is nothing to do but know the material.
Try three real AZ-500 practice questions
From our AZ-500 bank, with explanations for every option behind the toggle.
How long to study
Azure administrator with security tooling exposure: 40 to 60 hours over four to five weeks, concentrated on Sentinel, Defender plans and the Entra ID features you do not use daily.
Azure administrator without security exposure: 70 to 100 hours over six to eight weeks, with a lab subscription for Conditional Access, Key Vault and Defender for Cloud.
Security professional new to Azure: 100 to 150 hours over ten to twelve weeks. Do the AZ-104 material first, even without sitting the exam; AZ-500 assumes it.
A study plan that follows the four areas
Weeks 1 and 2: identity. Build Conditional Access policies in report-only mode and read the sign-in logs. Configure PIM for a role and go through the activation. Create an app registration and a managed identity and grant each a permission. Enable Identity Protection and read the risk reports.
Weeks 3 and 4: networking. Deploy Azure Firewall with a policy, put a WAF on an Application Gateway, create a private endpoint to a storage account and confirm the public endpoint no longer answers, enable JIT access on a VM.
Weeks 5 and 6: compute, storage and data. Turn on Defender for Servers, encrypt a disk, lock down a storage account with a firewall and a SAS policy, enable auditing and masking on an Azure SQL database, and store a secret, a key and a certificate in Key Vault with RBAC rather than access policies.
Week 7: operations. Assign a policy initiative, review secure score and fix three recommendations, connect a data source to Sentinel, write an analytics rule and trigger it, and attach an automation rule. This week converts the most abstract part of the outline into memory.
Week 8: timed practice. Full sets, then review by domain. Our timed AZ-500 practice exam draws from the same bank as the free questions and scores by area.
Exam day, retakes and renewal
Pearson VUE centre or online proctoring, 100 minutes, the same pacing advice as AZ-104: roughly an hour on standard items, 25 minutes on the case study, the remainder for review. A failed attempt can be retaken after 24 hours the first time and 14 days after that, each at full price. A pass is valid for one year and renewed free online.
Is AZ-500 worth it?
For anyone responsible for securing Azure workloads, it is the credential that maps to the job, and the study process itself (Conditional Access, Defender, Sentinel, Key Vault) is the job's toolkit. The difficulty is the depth of Entra ID and the overlap between products; both are fixed by building the configurations rather than reading about them.