Microsoft Azure Security Engineer Associate AZ-500 Practice Question

Your company uses an Azure Key Vault named kv-prod that contains an RSA key called sign-key. Several Azure Functions obtain the key by calling the URL https://kv-prod.vault.azure.net/keys/sign-key (no version specified). The security team requires the key to be rotated automatically every 90 days, and they do not want to modify any application code after the change is implemented. What should you do in Azure Key Vault to meet the requirement?

  • Enable soft-delete and purge protection on kv-prod so Key Vault can automatically roll over the key after 90 days.

  • Configure a rotation policy on sign-key that sets the key to expire and automatically create a new version every 90 days.

  • Create a new RSA key named sign-key-v2 every 90 days and update each Function app setting with the new key URI.

  • Export the key to an Azure Managed HSM and re-import it as a secret in Key Vault every 90 days.

Microsoft Azure Security Engineer Associate AZ-500
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot