Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You are securing an Azure Key Vault that stores encryption keys for Azure Backup. Only virtual machines located in the Prod subnet of a virtual network named VNet1 should be able to access the vault. Azure Backup must continue retrieving keys during backups. Which network configuration meets both requirements?
Configure the firewall to Allow selected networks, add the Prod subnet of VNet1, and enable the Allow trusted Microsoft services to bypass firewall option.
Set Public network access to Disabled and deploy a private endpoint for the vault in the Prod subnet.
Enable a Microsoft.KeyVault service endpoint on VNet1 and keep the firewall default action set to Allow.
Add the public IP addresses of the virtual machines to the vault firewall and clear the Allow trusted Microsoft services option.
Selecting Allow selected networks restricts public access to the vault and enforces the firewall. Adding the Prod subnet of VNet1 lets only the virtual machines in that subnet reach the vault over the service endpoint. Because Azure Backup is on Microsoft-managed addresses, it will be blocked unless the Allow trusted Microsoft services to bypass firewall setting is enabled. Enabling that bypass grants Azure Backup the access it needs, while traffic from any other location remains denied. Disabling public network access would also block Azure Backup, enabling only a service endpoint without changing the default Allow action would leave the vault open to the internet, and listing VM public IPs would not cover their managed service traffic and still block Azure Backup.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Azure Key Vault, and why is it important for securing encryption keys?
Open an interactive chat with Bash
What does the 'Allow trusted Microsoft services to bypass firewall' option do in Azure Key Vault?
Open an interactive chat with Bash
How do service endpoints function in Azure virtual networks?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .