exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 11 question 2 discussion

Actual exam question from Microsoft's AZ-500
Question #: 2
Topic #: 11
[All AZ-500 Questions]

You need to encrypt storage1 to meet the technical requirements.
Which key vaults can you use?

  • A. KeyVault2 and KeyVault3 only
  • B. KeyVault1 only
  • C. KeyVault1 and KeyVault3 only
  • D. KeyVault1, KeyVault2, and KeyVault3
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
somenick
Highly Voted 2 years, 8 months ago
Selected Answer: D
Things have changed. Now KeyVault can be in a different region or sub, but in the same tenant: https://learn.microsoft.com/en-us/azure/storage/common/customer-managed-keys-configure-existing-account?WT.mc_id=Portal-Microsoft_Azure_Storage&tabs=azure-portal
upvoted 24 times
Pamban
1 year, 1 month ago
Correct! supported below You can either create your own keys and store them in the key vault or managed HSM, or you can use the Azure Key Vault APIs to generate keys. The storage account and the key vault or managed HSM can be in different Microsoft Entra tenants, regions, and subscriptions. Link: https://learn.microsoft.com/en-us/azure/storage/common/customer-managed-keys-overview
upvoted 3 times
...
azure_2563
1 year, 8 months ago
Correct
upvoted 2 times
...
...
Dom1nation
Highly Voted 2 years, 3 months ago
Still though keep in mind it's different for Azure Disk Encryption: https://learn.microsoft.com/en-us/azure/virtual-machines/windows/disk-encryption-key-vault?tabs=azure-portal#create-a-key-vault
upvoted 9 times
...
JaridB
Most Recent 1 year ago
Selected Answer: A
No one has pointed out that a Standard tier keyvault does not support automatic key rotation, its only an feature offered with priemium tier pricing. Correct answer would be A. KeyVault2 and KeyVault3 only
upvoted 4 times
Jimmy500
11 months, 2 weeks ago
Fake information, you can enable key rotation for Standard tier as well. Answer is D
upvoted 2 times
...
datz
1 year ago
You are right sir, questions clearly asks meet technical requirements...meaning automatic key rotations...
upvoted 1 times
...
...
joegie00698
1 year, 6 months ago
Answer is correct. The disk encryption part is the key: To ensure that encryption secrets don't cross regional boundaries, you must create and use a key vault that's in the same region and tenant as the VMs to be encrypted.
upvoted 1 times
Pamban
1 year, 2 months ago
it is not regarding vm, it is storage right?
upvoted 1 times
...
...
WilianCArias
1 year, 7 months ago
D for sure
upvoted 2 times
...
wardy1983
1 year, 7 months ago
Answer: D Explanation: Things have changed. Now KeyVault can be in a different region or sub, but in the same tenant: https://learn.microsoft.com/en-us/azure/storage/common/customer-managed-keys-configure-existingaccount? WT.mc_id=Portal-Microsoft_Azure_Storage&tabs=azure-portal On reference link: The storage account and the key vault or managed HSM can be different Azure Active Directory (Azure AD) tenants, regions, and subscriptions.
upvoted 2 times
...
wardy1983
1 year, 8 months ago
D Things have changed. Now KeyVault can be in a different region or sub, but in the same tenant: https://learn.microsoft.com/en-us/azure/storage/common/customer-managed-keys-configure-existingaccount? WT.mc_id=Portal-Microsoft_Azure_Storage&tabs=azure-portal On reference link: The storage account and the key vault or managed HSM can be different Azure Active Directory (Azure AD) tenants, regions, and subscriptions.
upvoted 1 times
...
_punky_
1 year, 8 months ago
Selected Answer: D
Explanation: No, the Key Vault and the Azure Storage Account do not need to be in the same region when using customer-managed keys for Azure Storage encryption1. The storage account and the Key Vault or Managed Hardware Security Module (HSM) can be in different Microsoft Entra tenants, regions, and subscriptions
upvoted 1 times
...
TheProfessor
1 year, 9 months ago
Selected Answer: D
The storage account and the key vault or managed HSM can be in different Azure Active Directory (Azure AD) tenants, regions, and subscriptions.
upvoted 3 times
TheProfessor
1 year, 9 months ago
Ref link: https://learn.microsoft.com/en-us/azure/storage/common/customer-managed-keys-overview
upvoted 2 times
...
...
ESAJRR
1 year, 9 months ago
Selected Answer: B
B. KeyVault1 only
upvoted 1 times
...
massnonn
2 years ago
it's D: keyvault it's same geographical area and subscription
upvoted 1 times
...
zellck
2 years, 2 months ago
Selected Answer: D
D is the answer. https://learn.microsoft.com/en-us/azure/storage/common/customer-managed-keys-configure-existing-account?tabs=azure-portal You can use a new or existing key vault to store customer-managed keys. The storage account and key vault may be in different regions or subscriptions in the same tenant.
upvoted 4 times
...
Pipas_Peladas
2 years, 3 months ago
Selected Answer: D
On reference link: The storage account and the key vault or managed HSM can be different Azure Active Directory (Azure AD) tenants, regions, and subscriptions.
upvoted 3 times
...
tutonata
2 years, 4 months ago
Selected Answer: D
You can either create your own keys and store them in the key vault or managed HSM, or you can use the Azure Key Vault APIs to generate keys. The storage account and the key vault or managed HSM can be different Azure Active Directory (Azure AD) tenants, regions, and subscriptions. https://learn.microsoft.com/en-us/azure/storage/common/customer-managed-keys-overview
upvoted 2 times
...
majstor86
2 years, 4 months ago
Selected Answer: D
D. KeyVault1, KeyVault2, and KeyVault3
upvoted 4 times
...
another2
2 years, 5 months ago
Selected Answer: D
You can use all the key Vaultes in the same Tenant, answer is D
upvoted 2 times
...
Ouma
2 years, 7 months ago
Selected Answer: D
Confirmed - ttps://learn.microsoft.com/en-us/azure/storage/common/customer-managed-keys-configure-existing-account?WT.mc_id=Portal-Microsoft_Azure_Storage&tabs=azure-portal
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...