Microsoft Azure Security Engineer Associate AZ-500 Practice Question
Your Azure Key Vault contains a software-protected RSA key named ContosoKey. The key is configured to expire 180 days after it is created. You must ensure that ContosoKey is regenerated automatically every 180 days and that the security team receives a warning 30 days before the key expires. Which configuration meets both requirements?
Assign the built-in Azure Policy definition "Key Vault keys should have an expiration date" at the subscription scope.
Configure an Event Grid subscription for the Microsoft.KeyVault.KeyNearExpiry event that triggers an Azure Automation runbook to call az keyvault key rotate every 180 days.
Create a key rotation policy on ContosoKey that includes a Rotate lifetime action with timeAfterCreate set to P180D and a Notify lifetime action with timeBeforeExpiry set to P30D.
Enable soft-delete and purge protection on the vault and rely on Key Vault to regenerate the key automatically when it expires.
A key rotation policy lets Key Vault create a new key version on a schedule and emit notifications before the current version expires. Setting a Rotate lifetime action with the trigger timeAfterCreate of P180D instructs Key Vault to generate a new version 180 days after each creation, and this emits the KeyNewVersionCreated event. Adding a Notify lifetime action with the trigger timeBeforeExpiry of P30D causes Key Vault to send the built-in KeyNearExpiry event 30 days before expiration, allowing the security team to act. Enabling soft-delete or assigning a compliance policy does not create new key versions, and relying on an Automation runbook requires additional custom logic rather than the native rotation feature.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a key rotation policy in Azure Key Vault?
Open an interactive chat with Bash
What does the P180D and P30D format mean in key rotation configuration?
Open an interactive chat with Bash
What is the difference between a Notify and Rotate lifetime action?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .