Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You deployed an Azure Key Vault named KV1 and set the firewall default action to Deny. You need to allow (1) requests that originate from the subnet AppSubnet in the virtual network VNet1 and (2) Azure Disk Encryption operations that protect your virtual machines. Which network configuration satisfies both requirements without granting broader access?
Create a private endpoint for KV1 in VNet1 and disable public network access for the vault.
Enable the Microsoft.KeyVault service endpoint on AppSubnet, create a virtual-network rule for that subnet, and enable the option that allows trusted Microsoft services to bypass the firewall.
Enable a Microsoft.KeyVault service endpoint on VNet1 and change the firewall default action to Allow (no additional rules).
Add an IP firewall rule for the address range of AppSubnet and enable network policies on the subnet's private endpoint.
Granting subnet traffic requires two steps: first enable the Microsoft.KeyVault service endpoint on the subnet, then create a virtual-network rule for that subnet. Enabling the "Allow trusted Microsoft services to bypass this firewall" option lets Azure Disk Encryption-a trusted Microsoft service-retrieve keys even when the firewall default action is Deny. Changing the default action to Allow, adding IP rules, or replacing the public endpoint with a private endpoint would either open wider access than necessary or block Azure Disk Encryption.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the purpose of the Microsoft.KeyVault service endpoint?
Open an interactive chat with Bash
How does 'Allow trusted Microsoft services to bypass this firewall' work?
Open an interactive chat with Bash
Why is enabling a virtual-network rule more secure than using IP firewall rules?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .