easymultiple choiceObjective-mapped

A development team needs a centralized service to store, rotate, and control access to encryption keys for applications. Which solution best fits?

Question 1easymultiple choice
Full question →

A development team needs a centralized service to store, rotate, and control access to encryption keys for applications. Which solution best fits?

Answer choices

Why each option matters

Good practice is not just finding the correct option. The wrong answers often show the exact trap the exam wants you to fall into.

A

Best answer

Key management service, because it centralizes key storage and rotation controls.

A key management service is designed to store, manage, rotate, and control access to cryptographic keys. It helps reduce the risk of hardcoded or poorly protected keys and gives administrators a central place to enforce lifecycle management. This is the best fit when multiple applications need secure, organized key handling.

B

Distractor review

Port forwarding rule, because it allows applications to reach the encryption system.

Port forwarding changes network paths, but it does not provide secure key storage or key rotation capabilities.

C

Distractor review

Load balancer, because it distributes encryption requests across servers.

Load balancers improve availability and performance, but they do not manage cryptographic keys or define who may access them.

D

Distractor review

Web application firewall, because it protects the keys from injection attacks.

A WAF can help protect web apps from some attacks, but it is not a key management platform and does not store or rotate keys.

Common exam trap

Common exam trap: answer the scenario, not the keyword

Many certification questions include familiar terms but test a specific constraint. Read the exact wording before choosing an answer that is generally true but wrong for this case.

Technical deep dive

How to think about this question

This question should be treated as a scenario, not a definition check. Identify the problem, the constraint and the best action. Then compare each option against those facts.

KKey Concepts to Remember

  • Read the scenario before looking for a memorised answer.
  • Find the constraint that changes the correct option.
  • Eliminate answers that are true in general but not in this case.
  • Use explanations to understand the rule behind the answer.

TExam Day Tips

  • Underline the problem statement mentally.
  • Watch for words such as best, first, most likely and least administrative effort.
  • Review why wrong options are wrong, not only why the correct option is correct.

Related practice questions

Related SY0-701 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

More questions from this exam

Keep practising from the same exam bank, or move into a focused topic page if this question exposed a weak area.

FAQ

Questions learners often ask

What does this SY0-701 question test?

Read the scenario before looking for a memorised answer.

What is the correct answer to this question?

The correct answer is: Key management service, because it centralizes key storage and rotation controls. — A key management service is the best fit for centrally storing, rotating, and controlling access to encryption keys. It gives the organization a managed way to handle key lifecycle tasks instead of spreading keys across applications or files. That reduces operational mistakes and improves security because keys can be rotated and access can be restricted from one place. The question describes exactly the kind of function a KMS is meant to provide. Why others are wrong: Port forwarding only changes network traffic flow and has nothing to do with secret key lifecycle management. A load balancer distributes traffic and improves resilience, but it does not store or rotate keys. A web application firewall filters web requests and helps with attack prevention, but it is not a key repository or key administration tool.

What should I do if I get this SY0-701 question wrong?

Then try more questions from the same exam bank and focus on understanding why the wrong options are tempting.

Discussion

Loading comments…

Sign in to join the discussion.