exam questions

Exam AZ-304 All Questions

View all questions & answers for the AZ-304 exam

Exam AZ-304 topic 2 question 38 discussion

Actual exam question from Microsoft's AZ-304
Question #: 38
Topic #: 2
[All AZ-304 Questions]

You need to create an Azure Storage account that uses a custom encryption key.
What do you need to implement the encryption?

  • A. a certificate issued by an integrated certification authority (CA) and stored in Azure Key Vault
  • B. a managed identity that is configured to access the storage account
  • C. an Azure Active Directory Premium subscription
  • D. an Azure key vault in the same Azure region as the storage account
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ab_cd
Highly Voted 4 years, 1 month ago
D The storage account and the key vault or managed HSM must be in the same region and in the same Azure Active Directory (Azure AD) tenant, but they can be in different subscriptions.
upvoted 96 times
Montrealcupid
4 years, 1 month ago
Agreed. You must use either Azure Key Vault or Azure Key Vault Managed Hardware Security Module (HSM) (preview) to store your customer-managed keys. You can either create your own keys and store them in the key vault or managed HSM, or you can use the Azure Key Vault APIs to generate keys. The storage account and the key vault or managed HSM must be in the same region and in the same Azure Active Directory (Azure AD) tenant, but they can be in different subscriptions.
upvoted 13 times
...
...
glam
Highly Voted 4 years, 1 month ago
D. an Azure key vault in the same Azure region as the storage account
upvoted 16 times
...
MARKMKENYA
Most Recent 2 years, 2 months ago
Answer is B and i have noticed many errors in discussions answers. Is the a mlantois for this exam? https://learn.microsoft.com/en-us/azure/storage/common/customer-managed-keys-configure-existing-account?tabs=azure-portal
upvoted 2 times
...
GarryK
2 years, 6 months ago
Selected Answer: B
https://learn.microsoft.com/en-us/azure/storage/common/customer-managed-keys-configure-existing-account?tabs=azure-portal When you enable customer-managed keys for an existing storage account, you must specify a managed identity that will be used to authorize access to the key vault that contains the key. The managed identity must have permissions to access the key in the key vault. You can use a new or existing key vault to store customer-managed keys. The storage account and key vault may be in different regions or subscriptions in the same tenant. To learn more about Azure Key Vault, see Azure Key Vault Overview and What is Azure Key Vault?. So B
upvoted 1 times
...
kmeena
2 years, 8 months ago
The documentation in Microsoft says - They can be in different region. https://docs.microsoft.com/en-us/azure/storage/common/customer-managed-keys-overview "You can either create your own keys and store them in the key vault or managed HSM, or you can use the Azure Key Vault APIs to generate keys. The storage account and the key vault or managed HSM must be in the same Azure Active Directory (Azure AD) tenant, but they can be in different regions and subscriptions."
upvoted 2 times
...
AubinBakana
2 years, 8 months ago
Selected Answer: D
I wonder what they'd mark us. I am pretty adamant the answer is D.
upvoted 1 times
...
silwal
2 years, 9 months ago
Selected Answer: B
When you enable customer-managed keys for a storage account, you must specify a managed identity that will be used to authorize access to the key vault that contains the key. The managed identity must have permissions to access the key in the key vault. https://docs.microsoft.com/en-us/azure/storage/common/customer-managed-keys-configure-key-vault?toc=%2Fazure%2Fstorage%2Fblobs%2Ftoc.json&tabs=portal D is wrong - Do not need to be in the same region Nothing to do with A.
upvoted 2 times
...
silwal
2 years, 9 months ago
B When you enable customer-managed keys for a storage account, you must specify a managed identity that will be used to authorize access to the key vault that contains the key. The managed identity must have permissions to access the key in the key vault. https://docs.microsoft.com/en-us/azure/storage/common/customer-managed-keys-configure-key-vault?toc=%2Fazure%2Fstorage%2Fblobs%2Ftoc.json&tabs=portal
upvoted 1 times
...
Testing6132
2 years, 10 months ago
Selected Answer: D
Nothing to do with the Cert.
upvoted 2 times
...
OCHT
2 years, 11 months ago
Had seen this kind of question on AZ-500 . Answer is D.
upvoted 2 times
...
Lyibai
2 years, 11 months ago
D. an Azure key vault in the same Azure region as the storage account
upvoted 2 times
...
AlfL
3 years, 1 month ago
Selected Answer: D
i think it's D because is it not about cert?
upvoted 2 times
...
[Removed]
3 years, 1 month ago
Selected Answer: D
D is correct
upvoted 1 times
...
plmmsg
3 years, 1 month ago
Selected Answer: D
Answer should be D. same region
upvoted 1 times
...
anthonyphuc
3 years, 1 month ago
Selected Answer: D
must be same reagion
upvoted 1 times
...
arun
3 years, 1 month ago
Selected Answer: D
https://docs.microsoft.com/en-us/azure/storage/common/customer-managed-keys-overview "You can either create your own keys and store them in the key vault or managed HSM, or you can use the Azure Key Vault APIs to generate keys. The storage account and the key vault or managed HSM must be in the same region and in the same Azure Active Directory (Azure AD) tenant, but they can be in different subscriptions."
upvoted 1 times
...
Choquito
3 years, 2 months ago
A is the answer, the key word is custom. keyvault do not need to be in the same region as the storage account
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago