AZ-500: Microsoft Azure Security Technologies
Mid-level Microsoft Azure €165
Examenoverzicht
| Slagingsdrempel | 700/1000 |
| Duur | 120 minuten |
| Vragen | 40–60 |
| Aanbevolen voorkennis | AZ-900, SC-900, of Azure-werkervaring |
| Geldigheid | 1 jaar |
Examendomeinen
| Domein | Gewicht |
|---|---|
| Manage identity & access | 25–30% |
| Secure networking | 20–25% |
| Secure compute, storage & databases | 20–25% |
| Manage security operations | 25–30% |
Kernconcepten
Identity & Access
- Entra ID RBAC: built-in rollen (Owner, Contributor, Reader), custom roles, scope (management group → subscription → resource group → resource)
- Managed Identities: system-assigned vs. user-assigned — geen credentials in code
- Service Principals: app-registraties, certificaat vs. client secret
- PIM in Azure: tijdgebonden activatie van Azure RBAC-rollen
- Azure Policy: deny, audit, modify, deployIfNotExists — compliance afdwingen
- Microsoft Entra ID Governance: access reviews voor Azure-resources
Secure Networking
- Azure Firewall: Premium vs. Standard, DNAT/SNAT-regels, threat intelligence feed
- Azure DDoS Protection: Basic (gratis) vs. Standard (bescherming + SLA)
- Network Security Groups (NSG): inbound/outbound regels, effectieve regels debuggen
- Azure Bastion: RDP/SSH zonder publiek IP op VM’s
- Private Endpoints & Private Link: service bereikbaar via privénetwerk
- Azure Front Door + WAF: Layer 7 beveiliging, geo-filtering, rate limiting
- VNet peering & Hub-Spoke: netwerkisolatie en segmentatie
Compute, Storage & Databases
- Azure Key Vault: secrets, keys, certificates — access policies vs. RBAC
- Disk encryption: Azure Disk Encryption (BitLocker/DM-Crypt) vs. Server-Side Encryption
- VM security: JIT-toegang (just-in-time VM access), endpoint protection
- Container security: Azure Container Registry (ACR) — content trust, vulnerability scanning
- AKS security: pod identity, network policies, RBAC
- Storage security: SAS tokens, storage firewall, immutable blob, Defender for Storage
- SQL security: Azure Defender for SQL, Transparent Data Encryption, auditing, Always Encrypted
Security Operations
- Microsoft Defender for Cloud: Secure Score, aanbevelingen, workload protections
- Defender CSPM: attack paths, cloud security explorer
- Microsoft Sentinel integratie: data connectors voor Azure-services
- Azure Monitor: Log Analytics, diagnostic settings, alerts
- Microsoft Defender for Cloud regulatory compliance: CIS, NIST, PCI-DSS
- Incident response in Azure: isoleren van VM’s, NSG-blokkades, Key Vault-revocatie
Oefenvragen
Je wilt dat een Azure Function toegang heeft tot secrets in Key Vault zonder dat credentials in de code staan. Wat is de beste aanpak?
A) Hardcode de client secret in de applicatiecode B) Gebruik een system-assigned managed identity + Key Vault RBAC ✓ C) Sla de secret op in een environment variable D) Gebruik een service principal met client secret in app settings
Uitleg: Managed Identity elimineert credential-beheer volledig. De Function krijgt automatisch een identiteit; Key Vault RBAC kent de rol “Key Vault Secrets User” toe. Geen secret in code, geen rotatieproblemen.
Een VM is gecompromitteerd. Je wilt verdere schade beperken zonder de VM direct te stoppen (forensisch bewijs bewaren). Wat doe je als eerste?
A) VM onmiddellijk dealloceren B) NSG-regel toevoegen die al inbound/outbound verkeer blokkeert ✓ C) VM-snapshot maken D) Defender for Cloud alert sluiten
Uitleg: NSG-isolatie stopt communicatie (inclusief C2) zonder de VM te stoppen, waardoor geheugeninhoud en lopende processen bewaard blijven voor forensisch onderzoek. Snapshot daarna.
Studiestrategie
Tijdsinvestering: 8–12 weken
- Week 1-3 — Microsoft Learn AZ-500 leerpad (officieel, gratis)
- Week 4-6 — Hands-on labs in Azure (free account €200 credit of Pay-As-You-Go)
- Week 7-9 — John Savill AZ-500 Study Cram + oefenexamens
- Week 10-12 — Whizlabs of MeasureUp, focus op zwakke domeinen
Aanbevolen labs om zelf te bouwen: - Key Vault + Managed Identity + Function App - Hub-Spoke netwerk met Azure Firewall - Defender for Cloud inschakelen op een subscription - JIT VM Access configureren en testen
Azure free account is voldoende. De meeste AZ-500-labs draaien op gratis-tier resources (B1s VM’s, free Key Vault operations, gratis Log Analytics 5GB). Budget €5–15 voor de labs die net buiten de free tier vallen.