Microsoft has been changing up the Azure exams recently, and the other day I
Below you will find a list of what is going to be tested in the new AZ-500 Azure Security Engineer exam and a link to a resource that I think will help you learn and pass the exam. It is a work in progress at the moment and I will keep updating it. If you do find a link that is not working, or I have linked to the wrong resource. Please let me know.
Another good resource to learn about Azure Security is the Microsoft Learn site. you can reach the Secure your cloud data path using this link
https://docs.microsoft.com/en-us/learn/paths/secure-your-cloud-data/
Advice
At the time of writing this exam it is not live.
Skills measured from AZ-500: Microsoft Azure Security Technologies
Manage Identity and Access (20-25%)
Configure Microsoft Azure Active Directory for workloadsA
Create App Registration, configure App Registration permission scopes, manage App Registration permission consent
- https://docs.microsoft.com/en-us/azure/active-directory/develop/quickstart-v1-add-azure-ad-app
- https://docs.microsoft.com/en-us/azure/active-directory/develop/v1-permissions-and-consent
- https://docs.microsoft.com/en-us/azure/active-directory/develop/v2-permissions-and-consent
Configure Multi-Factor Authentication settings
Manage Microsoft Azure AD directory groups
Manage Microsoft Azure AD users
Install and configure Microsoft Azure AD Connect, configure authentication methods
- https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-install-custom
- https://docs.microsoft.com/en-us/azure/security/azure-ad-choose-authn
Implement Conditional Access policies
Configure Microsoft Azure AD identity protection
Configure Microsoft Azure AD Privileged Identity Management
Monitor privileged access, configure Access Reviews, activate Privileged Identity Management
- https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-getting-started
- https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-deployment-plan
- https://docs.microsoft.com/en-us/azure/active-directory/governance/access-reviews-overview
Configure Microsoft Azure tenant security
ransfer Microsoft Azure subscriptions between Microsoft Azure AD tenants, manage API access to Microsoft Azure subscriptions and resources
- https://docs.microsoft.com/en-us/azure/billing/billing-subscription-transfer
- https://docs.microsoft.com/en-us/azure/api-management/api-management-howto-aad
- https://docs.microsoft.com/en-us/azure/azure-resource-manager/resource-manager-api-authentication
- https://docs.microsoft.com/en-us/azure/active-directory/develop/active-directory-graph-api
Implement Platform Protection (35-40%)
Implement network security
Configure virtual network connectivity
Configure Network Security Groups (NSGs)
Create and configure Microsoft Azure Firewall
Create and configure application security groups
Configure remote access management
Configure baseline
Configure resource firewall
- https://docs.microsoft.com/en-us/azure/storage/common/storage-network-security
- https://docs.microsoft.com/en-us/azure/sql-database/sql-database-firewall-configure
Implement host security
Configure endpoint security within the VM
Configure VM security
Harden VMs in Microsoft Azure
Configure system updates for VMs in Microsoft Azure
Configure Baseline
Configure container security
Configure network
Configure authentication
Configure container isolation
Configure AKS security
Configure container registry
Configure container instance security
Implement vulnerability management
Implement Microsoft Azure Resource management security
Create Microsoft Azure resource locks
Manage resource group security
Configure Microsoft Azure policies
Configure custom RBAC roles
Configure subscription and resource permissions
Manage Security Operations (15-20%)
Configure security services
Configure Microsoft Azure Monitor
Configure Microsoft Azure Log Analytics
Configure diagnostic logging and log retention
Configure vulnerability scanning
Configure security policies
Configure centralized policy management by using Microsoft Azure Security Center
Configure Just in Time VM access by using Microsoft Azure Security Center
Manage security alerts
Create and customize alerts
Review and respond to alerts and recommendations
- https://docs.microsoft.com/en-us/azure/security-center/security-center-managing-and-responding-alerts
- https://docs.microsoft.com/en-us/azure/security-center/security-center-recommendations
Configure a playbook for a security event by using Microsoft Azure Security Center
Investigate escalated security incidents
Secure Data and Applications (30-35%)
Configure security policies to manage data
Configure data classification
Configure data retention
- https://docs.microsoft.com/en-us/rest/api/storageservices/setting-a-storage-analytics-data-retention-policy
- https://docs.microsoft.com/en-us/azure/kusto/management/retention-policy
Configure data sovereignty
Configure security for data infrastructure
Enable database authentication
Enable database auditing
Configure Microsoft Azure SQL Database threat detection
Configure access control for storage accounts
Configure key management for storage accounts
Create and manage Shared Access Signatures (SAS)
Configure security for HDInsights
Configure security for Cosmos DB
Configure security for Microsoft Azure Data Lake
- https://docs.microsoft.com/en-us/azure/data-lake-store/data-lake-store-network-security
- https://docs.microsoft.com/en-us/azure/storage/common/storage-data-lake-storage-security-guide
Configure encryption for data at rest
Implement Microsoft Azure SQL Database Always Encrypted
Implement database encryption
Implement Storage Service Encryption
Implement disk encryption
Implement backup encryption
Implement security for application delivery
Implement security validations for application development
Configure synthetic security transactions
Configure application security
Configure SSL/TLS certs
Configure Microsoft Azure services to protect web apps
Create an application security baseline
Configure and manage Key Vault
Manage access to Key Vault
Manage permissions to secrets, certificates, and keys
Manage certificates, manage secrets, configure key rotation
I hope you found this helpful and Good Luck in your exams!
6 Comments
Paul Bendall · March 27, 2019 at 9:18 pm
Thanks for sharing this information once again, as well as providing links to the associated documentation, super useful!
Trying to keep up with the Microsoft certification and exams is becoming as challenging as keeping up with Azure and Office 365 ever changing features.
Paul
Deiva · April 3, 2019 at 5:38 am
Thanks, Richard.
Gerrit · June 20, 2019 at 8:13 am
Thanks for the information.
muhammad sikander · January 6, 2020 at 3:01 pm
Thanks a lot for your work and effort.it helped me a lot.
Dan · August 24, 2020 at 3:10 am
There is a typo in the yellow header block just fyi. “clod” should be “cloud” Otherwise great content and thanks for contributing to help others!
Pixel Robots. · August 25, 2020 at 12:29 pm
Thanks for That. Good spot. Updated now.