Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You are an Azure Security Engineer for Contoso. A storage account named contosodata currently relies on Microsoft-managed keys for encryption at rest. Compliance now requires Bring your own key (BYOK) encryption that uses a key your organization generated on-premises and imported into Azure Key Vault. The key's URI is https://kv-prod.vault.azure.net/keys/ContosoKey. Before you can switch contosodata to customer-managed keys, which Key Vault configuration must you complete so that the storage service can successfully access the key?
Configure the Key Vault firewall to allow access only through a private endpoint.
Enable soft-delete for keys in the Key Vault.
Upload the same key as a secret in the Key Vault and reference the secret's URI instead of the key URI.
Grant the storage service principal or managed identity Get, Wrap Key, and Unwrap Key permissions on the ContosoKey object.
When Azure Storage is configured to use a customer-managed key, the storage service needs to call Azure Key Vault to wrap and unwrap data-encryption keys. The identity that represents the storage service (Microsoft Storage service principal or the storage account's managed identity) therefore needs Key Vault permissions. Specifically, the storage service must be able to:
Read the current version of the key (Get)
Wrap and unwrap data-encryption keys (Wrap Key and Unwrap Key)
Granting these three permissions (Get, Wrap Key, Unwrap Key) via an access policy or Azure RBAC role assignment is a required step before you can select the key for BYOK. Enabling soft-delete, uploading the key as a secret, or restricting the firewall are optional or unrelated to allowing Storage to use the key, so they do not satisfy the requirement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Bring Your Own Key (BYOK) in Azure?
Open an interactive chat with Bash
How does Azure Storage use customer-managed keys for encryption?
Open an interactive chat with Bash
Why are Get, Wrap Key, and Unwrap Key permissions needed in Key Vault?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .