Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You have two Azure Functions running in separate Azure subscriptions. Both functions must read secrets from the same Azure Key Vault, and your solution must minimize secret-management overhead. You want a single identity that you can grant Key Vault access once and reuse from both functions without handling credential rotation. Which option should you choose?
Use a shared access signature (SAS) token stored in Azure App Configuration and reference it from both Function Apps.
Create a single user-assigned managed identity and assign it to both Function Apps, then grant that identity access to the Key Vault.
Register an Azure AD application, generate a client secret, and store the secret in each Function App's configuration.
Enable a system-assigned managed identity on each Function App and add both identities to the Key Vault access policy.
A user-assigned managed identity is an independent Azure resource that can be attached to multiple other resources, including Function Apps that reside in different subscriptions. Because the identity is managed by Azure AD, credentials are automatically rotated, so no secrets need to be stored or updated. A system-assigned managed identity is tied to a single resource and cannot be shared, so you would have to create and grant access for two separate identities. An Azure AD application with a client secret requires manual secret storage and rotation, defeating the goal of minimal secret management. Shared access signature (SAS) tokens are not used for Azure Key Vault authentication and would require manual rotation as well.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a user-assigned managed identity in Azure?
Open an interactive chat with Bash
How does Azure Key Vault manage access control?
Open an interactive chat with Bash
Why are shared access signature (SAS) tokens not suitable for Azure Key Vault authentication?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure identity and access
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .