exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 2 question 102 discussion

Actual exam question from Microsoft's AZ-500
Question #: 102
Topic #: 2
[All AZ-500 Questions]

HOTSPOT
-

You have an Azure subscription that contains a user named Admin1 and an Azure key vault named Vault1.

You plan to implement Microsoft Entra Verified ID.

You need to create an access policy to ensure that Admin1 has permissions to Vault1 that support the implementation of the Verified ID service. The solution must use the principle of least privilege.

Which three key permissions should you select? To answer, select the appropriate permissions in the answer area.

NOTE: Each correct selection is worth one point.

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
billo79152718
Highly Voted 1 year, 11 months ago
Given answers is correct. https://learn.microsoft.com/en-us/azure/active-directory/verifiable-credentials/verifiable-credentials-configure-tenant
upvoted 12 times
...
workhard
Most Recent 9 months, 1 week ago
By default, the account that creates a vault is the only one with access (vault creators have by default permissions to create and delete keys). The Verified ID service needs access to the key vault. You must authenticate your key vault, allowing the account used during configuration to create and delete keys. The account used during configuration also requires permissions to sign so that it can create the domain binding for Verified ID. So, if the Admin1 account is not the one that created Vault1, it will need to get the following key permissions: create, delete and sign. https://learn.microsoft.com/en-us/entra/verified-id/verifiable-credentials-configure-tenant
upvoted 4 times
...
Christof
1 year, 5 months ago
Create, Delete, Sign. "Follow these steps to create a key vault using the Azure portal. Note: By default, the account that creates a vault is the only one with access. The Verified ID service needs access to the key vault. You must configure your key vault with access policies allowing the account used during configuration to CREATE and DELETE keys. The account used during configuration also requires permissions to SIGN so that it can create the domain binding for Verified ID. If you use the same account while testing, modify the default policy to grant the account sign permission, in addition to the default permissions granted to vault creators.
upvoted 4 times
Christof
1 year, 5 months ago
Reference for above: https://learn.microsoft.com/en-us/entra/verified-id/verifiable-credentials-configure-tenant
upvoted 1 times
...
...
ErikPJordan
1 year, 7 months ago
https://learn.microsoft.com/en-us/azure/active-directory/verifiable-credentials/verifiable-credentials-configure-tenant - Go to Set access policies for the Verified ID Admin user, you can see screenshot where Get, Create, Delete, Sign is selected
upvoted 1 times
ErikPJordan
1 year, 7 months ago
Confusing ....For Key permissions, verify that the following permissions are selected: Get, Create, Delete, and Sign. By default, Create and Delete are already enabled. Sign should be the only key permission you need to update.
upvoted 2 times
...
...
fireb
1 year, 8 months ago
In all, you need these 4 permissions enabled: Get, Create, Delete, and Sign. However, by default, Create and Delete are enabled. Therefore, Sign and Get should be the only key permissions you need to update. https://learn.microsoft.com/en-us/azure/active-directory/verifiable-credentials/verifiable-credentials-configure-tenant
upvoted 2 times
...
03038b8
1 year, 9 months ago
Considering the principle of least privilege, the definite answers for the three key permissions to support the implementation of Azure Verified ID are: Sign: This permission allows the user (Admin1) to use the keys in Vault1 for signing operations, which is necessary for verifying the authenticity of the Verified ID. Verify: This permission enables the user (Admin1) to use the keys in Vault1 for verification operations, which is essential for validating the Verified ID. Get: This permission allows the user (Admin1) to retrieve the keys from Vault1. It may be required for certain operations during the implementation of Azure Verified ID, such as retrieving the public key for verification purposes. By selecting these three key permissions (Sign, Verify, and Get) for Admin1 in the access policy of Vault1, you ensure that Admin1 has the necessary permissions to support the implementation of Azure Verified ID, while following the principle of least privilege. I apologize for any confusion caused earlier, and I appreciate your patience.
upvoted 1 times
03038b8
1 year, 9 months ago
My bad, it's Create, Delete, sign. The first answer was chatgpt answer but after verification it appears to be Create, Delete, Sign
upvoted 1 times
...
timHAG
1 year, 7 months ago
I am with this answer, its to help the idverify, creat and delete are enabled by default, you will need sign get and verify in addition
upvoted 1 times
...
...
Kb80
1 year, 9 months ago
One quirk I also encountered when configuring this in the lab is that when I went to register the decentrialized ID the key vault operation failed with an error that you need to add "List" also. Then it would proceed.
upvoted 2 times
...
[Removed]
1 year, 10 months ago
Which three key permissions get create delete
upvoted 1 times
...
Ario
1 year, 10 months ago
should pick also GET https://learn.microsoft.com/en-us/azure/active-directory/verifiable-credentials/verifiable-credentials-configure-tenant
upvoted 2 times
femzy
1 year, 5 months ago
For intial setup, you will want to go with Create, Delete and Sign as 3 key permissions.First 2 are enabled by default.
upvoted 1 times
...
...
973b658
1 year, 11 months ago
create,delete,sign
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago