Microsoft Azure Security Engineer Associate AZ-500 Practice Question

Your Azure tenant has two Conditional Access policies: PolicyA: grant access only if the user completes multi-factor authentication. PolicyB: block access when the sign-in risk level is High. Both policies are enabled and target all cloud apps and all users. A user whose sign-in is assessed as High risk successfully completes MFA and tries to open the Azure portal.

What will happen?

  • The sign-in is allowed because Conditional Access evaluates grant policies before block policies when policies have equal priority.

  • The sign-in is blocked because a block decision overrides any grant decision when multiple Conditional Access policies apply.

  • The sign-in is allowed because completing MFA satisfies the requirements of PolicyA and mitigates the high-risk sign-in.

  • The sign-in is allowed only if the device is compliant; otherwise, it is blocked.

Microsoft Azure Security Engineer Associate AZ-500
Secure identity and access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot