Microsoft Azure Security Engineer Associate AZ-500 Practice Question
Your company uses an Azure Key Vault named kv-prod that contains an RSA key called sign-key. Several Azure Functions obtain the key by calling the URL https://kv-prod.vault.azure.net/keys/sign-key (no version specified). The security team requires the key to be rotated automatically every 90 days, and they do not want to modify any application code after the change is implemented. What should you do in Azure Key Vault to meet the requirement?
Enable soft-delete and purge protection on kv-prod so Key Vault can automatically roll over the key after 90 days.
Configure a rotation policy on sign-key that sets the key to expire and automatically create a new version every 90 days.
Create a new RSA key named sign-key-v2 every 90 days and update each Function app setting with the new key URI.
Export the key to an Azure Managed HSM and re-import it as a secret in Key Vault every 90 days.
When a client requests a key by using its base URI without a version, Azure Key Vault always returns the latest version. By defining a key rotation policy on sign-key with an expiry period and a 90-day lifetime action, Key Vault can automatically create a new key version at the configured interval. Because the URI without a version remains unchanged, the Azure Functions continue to retrieve the newest version without code updates. Enabling soft-delete or purge protection increases resiliency but does not create new versions. Manually creating a separate key or exporting to another service would still require the applications to reference a different URI, defeating the requirement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is key rotation in Azure Key Vault?
Open an interactive chat with Bash
How does Azure Key Vault handle versioning of keys?
Open an interactive chat with Bash
What is the role of soft-delete and purge protection in Azure Key Vault?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .