Microsoft Azure Security Engineer Associate AZ-500 Practice Question

Your company stores secrets in an Azure Key Vault that currently allows traffic only from selected networks. An Azure Function app is deployed in a dedicated App Service plan and is integrated with the subnet AppSubnet in VNet CorpNet. You must permit the function app to retrieve secrets while keeping all other Azure services blocked. What should you configure on the Key Vault?

  • Set Public network access to Enabled and configure the function app to use its system-assigned managed identity.

  • Add the function app's outbound IP addresses as firewall IP address rules.

  • Turn on the Allow trusted Microsoft services to bypass the firewall setting.

  • Enable a service endpoint for Microsoft.KeyVault on AppSubnet and add AppSubnet as a virtual network rule.

Microsoft Azure Security Engineer Associate AZ-500
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot