3Secure Compute, Storage, and Databases
- 3.1Key Vault and Encryption
Understand Azure Key Vault for safely storing keys/secrets/certificates and the basics of encryption at rest. Combined with managed identity, keeping no credentials in code is core to AZ-500.
- 3.2Securing Storage and Databases
Understand storage account access control (SAS, disabling keys, Entra authorization) and network restrictions, plus Azure SQL authentication, firewall, Transparent Data Encryption (TDE), and Always Encrypted. Defend the data layer in depth.
- 3.3Securing Compute and Defender for Cloud
Understand secure VM operations (Just-In-Time VM access, disk encryption, update management) and Microsoft Defender for Cloud (secure score, workload protection) for visualizing and strengthening cloud-wide posture.

