Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You are designing access for an Azure Virtual Machine Scale Set and an Azure App Service web app that are deployed in the same tenant. Both workloads must retrieve secrets from the same Azure Key Vault. Management wants to minimize the number of role assignments and ensure the identity persists even if either workload is redeployed. Which managed identity approach should you recommend?
Register a new application in Microsoft Entra ID, generate a client secret, and store the secret in each workload's configuration settings.
Create a separate user-assigned managed identity for each resource and grant each identity access to the Key Vault.
Create a single user-assigned managed identity, assign it to both resources, and grant it access to the Key Vault.
Enable a system-assigned managed identity on the scale set and share it with the web app.
A user-assigned managed identity is created as an independent Azure resource. Because its lifecycle is not tied to any single workload, the identity continues to exist if the scale set or the web app is deleted or redeployed. The same user-assigned identity can be attached to multiple Azure resources, allowing you to grant Key Vault access once and reuse the assignment. A system-assigned identity cannot be shared and is removed with its parent resource, and using separate identities or client secrets would increase the number of role assignments and management overhead.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the difference between a user-assigned and system-assigned managed identity?
Open an interactive chat with Bash
Why is minimizing the number of role assignments important in this scenario?
Open an interactive chat with Bash
How does Azure Key Vault handle secret access for managed identities?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure identity and access
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .