Cosmos DB Customer-Managed Key Rotation
You are designing a solution for a healthcare application that stores patient data in Azure Cosmos DB. The data must be encrypted at rest using a customer-managed key stored in Azure Key Vault. You need to ensure that the key can be rotated without downtime. Which approach should you recommend?
Quick Answer
The correct approach is to enable automatic key rotation on the Key Vault key and use the key's versionless identifier in Cosmos DB. This works because Cosmos DB’s customer-managed key encryption supports automatic detection of new key versions when you reference the key by its versionless URI, meaning the service seamlessly picks up the rotated key without any manual intervention or downtime. On the AZ-204 exam, this scenario tests your understanding of how Azure Cosmos DB integrates with Azure Key Vault for encryption at rest, and the common trap is assuming you must manually update the Cosmos DB account or regenerate keys—neither is required when using a versionless identifier. Remember the memory tip: “Versionless is effortless”—if you omit the version from the Key Vault key identifier, Cosmos DB handles rotation automatically.
⚠ Common exam trap
Many exam-takers confuse Cosmos DB account key rotation (for authentication) with customer-managed key rotation (for encryption at rest), leading candidates to incorrectly select Option C.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable automatic key rotation on the Key Vault key and use the key's versionless identifier in Cosmos DB.
Using a versionless key identifier in Azure Cosmos DB allows the service to automatically use the latest version of the customer-managed key stored in Azure Key Vault. When the key is rotated in Key Vault, Cosmos DB picks up the new version without any manual intervention, ensuring zero downtime and continuous encryption at rest.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure Azure Security Center to automatically rotate the key.
Why it's wrong here
Microsoft Defender for Cloud (Security Center) generates security recommendations and alerts; it holds no mechanism to rotate a Key Vault key or rewrap a Cosmos DB account's encryption key. It would be chosen when centralised security posture assessment and threat protection across subscriptions is the actual requirement.
- ✗
After rotating the key in Key Vault, manually update the Cosmos DB account with the new key version.
Why it's wrong here
Manually updating the account to a new key version requires a second update and can cause brief unavailability while Cosmos DB re-wraps the data encryption key. Referencing the Key Vault key without a version lets rotation occur automatically. Manual version pinning suits scenarios needing strict control over exactly when a specific version activates.
- ✗
Use the Cosmos DB account key rotation feature to regenerate the key.
Why it's wrong here
Cosmos DB account keys authenticate clients; they are not the customer-managed encryption key held in Key Vault, so rotating them leaves the data-encryption key untouched. Account-key regeneration suits credential compromise response, whereas CMK rotation requires updating the Key Vault key version referenced by the account.
- ✓
Enable automatic key rotation on the Key Vault key and use the key's versionless identifier in Cosmos DB.
Why this is correct
Automatic rotation in Key Vault creates new key versions on schedule, and the versionless key identifier lets Cosmos DB always resolve the latest version, so rotation occurs without reconfiguration or downtime. Pinning a specific version would require manual updates.
Go deeper
Related to this question
Learn chapter
Key Vault References in App Service and Functions
Key term
Key Vault Secrets
Key Vault Secrets are secure containers in Microsoft Azure that store sensitive information like passwords, connection strings, and API keys, keeping them encrypted and accessible only to authorized applications and users.
About these practice questions
Courseiva writes every AZ-204 question from scratch — 883 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on AZ-204
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization has a custom application that stores customer data in Azure Cosmos DB. You need to encrypt the data at rest using a customer-managed key stored in Azure Key Vault. Which type of Cosmos DB encryption should you configure?
easy- A.Enable Azure Disk Encryption on the Cosmos DB instance
- B.Enable Transparent Data Encryption (TDE)
- ✓ C.Use customer-managed keys (CMK) with Azure Key Vault
- D.Implement client-side encryption using the SDK
Why C: Azure Cosmos DB supports customer-managed keys (CMK) integrated with Azure Key Vault to encrypt data at rest. This allows you to bring your own key (BYOK) and control key rotation, revocation, and access policies, meeting the requirement for a customer-managed key stored in Azure Key Vault.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.