Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You administer an Azure Key Vault named ContosoVault that contains an RSA key named AppKey. Several applications reference the key by using the base URI (https://contosovault.vault.azure.net/keys/AppKey). Compliance requires that AppKey be rotated automatically every 30 days while the existing URI remains valid. You want a solution that involves the least ongoing administrative effort. What should you do?
Set the key's activation and expiration dates so that it expires 30 days after creation.
Configure a key rotation policy on AppKey with a lifetime action of Rotate set to 30 days.
Enable soft delete and purge protection on ContosoVault.
Create an Azure Automation runbook that calls az keyvault key rotate on AppKey every 30 days.
Configuring a key rotation policy on AppKey with a lifetime action of Rotate instructs Azure Key Vault to create a new version of the key every 30 days. The key name and base URI remain unchanged, so applications that call the base identifier automatically begin using the newest version without modification. Setting only an expiration date makes the key unusable after 30 days but does not create a new version. Soft delete or purge protection protect against accidental deletion rather than perform rotation. While an Azure Automation runbook could call the rotate command on a schedule, it requires additional resources and ongoing maintenance, making it a less efficient solution for this requirement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a key rotation policy in Azure Key Vault?
Open an interactive chat with Bash
Why is using an Azure Automation runbook less efficient for key rotation?
Open an interactive chat with Bash
What is the difference between soft delete/purge protection and key rotation?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .