Microsoft Azure Security Engineer Associate AZ-500 Practice Question

An Azure Key Vault stores app connection-string secrets and an RSA key used to sign JWTs. The DevOps Azure AD group deploys the app and must add new versions of the connection-string secrets during deployments but must never read secret values or use the RSA key. Which Key Vault permissions satisfy least privilege for DevOps?

  • Secret permissions: Set; Key permissions: None

  • Secret permissions: Set and Get; Key permissions: None

  • Secret permissions: Set and List; Key permissions: None

  • Secret permissions: Set; Key permissions: Sign

Microsoft Azure Security Engineer Associate AZ-500
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot