Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You registered an Azure AD application named WebApp1 and created its service principal. A GitHub Actions workflow will use this service principal, authenticated by a client secret, to add and update secrets in a single Azure Key Vault. Following the principle of least privilege, which built-in Azure role and scope should you assign to the service principal?
Key Vault Secrets Officer grants permission to list, get, set, and delete secrets within a specific vault but does not allow modification of access policies, keys, or the vault itself. Assigning the role at the Key Vault scope limits the service principal to exactly the resource it must manage. Key Vault Administrator or Contributor would allow broader management capabilities that are unnecessary for the pipeline, and Key Vault Reader cannot create or update secrets.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the principle of least privilege?
Open an interactive chat with Bash
What tasks does the Key Vault Secrets Officer role allow?
Open an interactive chat with Bash
How does scoping permissions to a single Key Vault improve security?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure identity and access
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .