Microsoft AZ-500 (Azure Security)

Security Operations & Monitoring

39 practice questions with explanations — 15 free to try

PassNova has 39 Microsoft AZ-500 (Azure Security) practice questions on Security Operations & Monitoring, each with a clear explanation. A 15-question taster is free with no sign-up; the full bank is part of PassNova Premium. Updated for 2026.

Sample questions

Security Operations & Monitoring: example questions & answers

3 worked examples with answers and explanations below. Try 15 Microsoft AZ-500 (Azure Security) questions free in the browser; the full 39-question Security Operations & Monitoring bank is part of PassNova Premium.

  1. Which Microsoft service provides a unified secure score, security recommendations, and regulatory compliance assessments across your Azure subscriptions?

    • AMicrosoft Defender for Cloud
    • BAzure Monitor Workbooks
    • CMicrosoft Entra ID Protection
    • DMicrosoft Sentinel

    Answer: Microsoft Defender for Cloud is the cloud security posture management and workload protection platform that surfaces secure score, recommendations, and compliance assessments. Microsoft Sentinel is the SIEM for threat detection and response.

  2. You want a cloud-native SIEM and SOAR solution to collect security logs from Azure and third-party sources, run analytics rules, and automate response with playbooks. Which service should you deploy?

    • AMicrosoft Sentinel
    • BAzure Network Watcher
    • CAzure Monitor metrics
    • DMicrosoft Defender for Cloud

    Answer: Microsoft Sentinel is the cloud-native SIEM and SOAR that ingests data via connectors, applies analytics rules to generate incidents, and automates response with Logic Apps playbooks. Defender for Cloud focuses on posture and workload protection rather than SIEM correlation.

  3. In Microsoft Sentinel, which component allows you to ingest sign-in and audit logs from Microsoft Entra ID?

    • AA data connector
    • BA workbook
    • CA hunting query
    • DA watchlist

    Answer: Data connectors are the configurable integrations that bring logs, such as Microsoft Entra ID sign-in and audit logs, into the Sentinel workspace. Workbooks visualize data and hunting queries proactively search it once it is ingested.

Start practising Security Operations & Monitoring →