Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You manage an Azure Key Vault that uses the Azure role-based access control (RBAC) permission model. An Azure Function's system-assigned managed identity needs to read the value of a single secret at runtime, but it must not be able to list or modify any secrets in the vault. Which approach satisfies this requirement with the least privilege?
Create a custom Azure RBAC role that includes only the Microsoft.KeyVault/vaults/secrets/get data action and assign it to the managed identity at the scope of the required secret.
Assign the built-in Key Vault Secrets User role to the managed identity at the vault scope.
Assign the built-in Key Vault Secrets Officer role to the managed identity at the secret scope.
Switch the vault to the Vault access policy model and grant the managed identity a secrets Get permission in an access policy.
Azure RBAC permits object-level scoping, so you can grant permissions on an individual secret instead of the whole vault. Because none of the built-in roles provide only the Get data action, you create a custom role that includes Microsoft.KeyVault/vaults/secrets/get and assign it to the managed identity at the scope of the target secret. This allows the function to retrieve that secret without listing or changing any secrets. Switching to the vault access policy model would still grant permissions at the vault level, and the built-in roles (Key Vault Secrets User or Secrets Officer) all include additional actions such as list or set.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a managed identity in Azure?
Open an interactive chat with Bash
How does Azure role-based access control (RBAC) work?
Open an interactive chat with Bash
What is the Microsoft.KeyVault/vaults/secrets/get data action?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .