Things have changed. Now KeyVault can be in a different region or sub, but in the same tenant: https://learn.microsoft.com/en-us/azure/storage/common/customer-managed-keys-configure-existing-account?WT.mc_id=Portal-Microsoft_Azure_Storage&tabs=azure-portal
Correct! supported below
You can either create your own keys and store them in the key vault or managed HSM, or you can use the Azure Key Vault APIs to generate keys. The storage account and the key vault or managed HSM can be in different Microsoft Entra tenants, regions, and subscriptions.
Link: https://learn.microsoft.com/en-us/azure/storage/common/customer-managed-keys-overview
Still though keep in mind it's different for Azure Disk Encryption: https://learn.microsoft.com/en-us/azure/virtual-machines/windows/disk-encryption-key-vault?tabs=azure-portal#create-a-key-vault
No one has pointed out that a Standard tier keyvault does not support automatic key rotation, its only an feature offered with priemium tier pricing.
Correct answer would be A. KeyVault2 and KeyVault3 only
Answer is correct. The disk encryption part is the key:
To ensure that encryption secrets don't cross regional boundaries, you must create and use a key vault that's in the same region and tenant as the VMs to be encrypted.
Answer: D
Explanation:
Things have changed. Now KeyVault can be in a different region or sub, but in the same tenant:
https://learn.microsoft.com/en-us/azure/storage/common/customer-managed-keys-configure-existingaccount?
WT.mc_id=Portal-Microsoft_Azure_Storage&tabs=azure-portal
On reference link: The storage account and the key vault or managed HSM can be different Azure Active
Directory (Azure AD) tenants, regions, and subscriptions.
D
Things have changed. Now KeyVault can be in a different region or sub, but in the same tenant:
https://learn.microsoft.com/en-us/azure/storage/common/customer-managed-keys-configure-existingaccount?
WT.mc_id=Portal-Microsoft_Azure_Storage&tabs=azure-portal
On reference link: The storage account and the key vault or managed HSM can be different Azure Active
Directory (Azure AD) tenants, regions, and subscriptions.
Explanation:
No, the Key Vault and the Azure Storage Account do not need to be in the same region when using customer-managed keys for Azure Storage encryption1. The storage account and the Key Vault or Managed Hardware Security Module (HSM) can be in different Microsoft Entra tenants, regions, and subscriptions
D is the answer.
https://learn.microsoft.com/en-us/azure/storage/common/customer-managed-keys-configure-existing-account?tabs=azure-portal
You can use a new or existing key vault to store customer-managed keys. The storage account and key vault may be in different regions or subscriptions in the same tenant.
On reference link: The storage account and the key vault or managed HSM can be different Azure Active Directory (Azure AD) tenants, regions, and subscriptions.
You can either create your own keys and store them in the key vault or managed HSM, or you can use the Azure Key Vault APIs to generate keys. The storage account and the key vault or managed HSM can be different Azure Active Directory (Azure AD) tenants, regions, and subscriptions.
https://learn.microsoft.com/en-us/azure/storage/common/customer-managed-keys-overview
This section is not available anymore. Please use the main Exam Page.AZ-500 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
somenick
Highly Voted 2 years, 8 months agoPamban
1 year, 1 month agoazure_2563
1 year, 8 months agoDom1nation
Highly Voted 2 years, 3 months agoJaridB
Most Recent 1 year agoJimmy500
11 months, 2 weeks agodatz
1 year agojoegie00698
1 year, 6 months agoPamban
1 year, 2 months agoWilianCArias
1 year, 7 months agowardy1983
1 year, 7 months agowardy1983
1 year, 8 months ago_punky_
1 year, 8 months agoTheProfessor
1 year, 9 months agoTheProfessor
1 year, 9 months agoESAJRR
1 year, 9 months agomassnonn
2 years agozellck
2 years, 2 months agoPipas_Peladas
2 years, 3 months agotutonata
2 years, 4 months agomajstor86
2 years, 4 months agoanother2
2 years, 5 months agoOuma
2 years, 7 months ago