Microsoft Azure Administrator Associate AZ-104 Practice Question
You are an Azure administrator for a company that requires all data stored in Azure Storage Accounts to be encrypted by customer-managed keys (CMKs) stored in Azure Key Vault. The company policy also mandates that the key be rotated every 90 days. You need to configure a new Storage Account to meet these requirements. Which of the following steps should you perform?
Enable Infrastructure Encryption for the Storage Account and select the customer-managed key from Key Vault
Create a Key Vault, generate a key, and set the Storage Account to use service-managed keys in the Key Vault
Disable encryption on the Storage Account and configure the application to encrypt data before storing it
Set the default encryption key to a customer-managed key in Key Vault and configure a key-rotation policy
Set the Storage Account's default encryption key to a customer-managed key in Azure Key Vault and configure a key-rotation policy on that key. This ensures the account uses the specified CMK for every encryption and that the key will automatically generate a new version on the required 90-day schedule. Enabling Infrastructure Encryption is optional; it adds a second layer protected by Microsoft-managed keys and does not itself configure key rotation. Disabling encryption is not permitted, and selecting Microsoft-managed keys does not meet the requirement to use CMKs.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Azure Key Vault and how does it relate to customer-managed keys?
Open an interactive chat with Bash
What are the benefits of configuring a key rotation policy in Azure Key Vault?
Open an interactive chat with Bash
What is the difference between customer-managed keys and service-managed keys in Azure?
Open an interactive chat with Bash
Microsoft Azure Administrator Associate AZ-104
Implement and manage storage
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .