AZ-305 Design infrastructure solutions Practice Question
Exhibit
{
"properties": {
"encryption": {
"keySource": "Microsoft.Keyvault",
"keyVaultProperties": {
"keyUri": "https://mykeyvault.vault.azure.net/keys/mykey/abc123",
"identity": {
"userAssignedIdentity": "/subscriptions/.../providers/Microsoft.ManagedIdentity/userAssignedIdentities/mysi"
}
}
}
}
}Refer to the exhibit. You are analyzing a deployment of Azure Storage account with customer-managed key encryption. The deployment fails with an error indicating that the key vault is not accessible. Which of the following is the most likely cause?
⚠ Common exam trap
Many exam-takers assume the error is due to a network firewall or a naming mistake, but Azure explicitly requires the managed identity to have cryptographic permissions on the key vault, and the error message 'not accessible' is a generic wrapper for permission failures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The user-assigned managed identity does not have permissions to access the key
When using customer-managed keys (CMK) with Azure Storage encryption, the storage account must authenticate to the key vault to retrieve the key. If a user-assigned managed identity is specified in the encryption policy, that identity must have at least 'Get', 'Wrap Key', and 'Unwrap Key' permissions on the key vault. Without these permissions, the storage account cannot access the key, resulting in a deployment failure with a 'key vault not accessible' error.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The key vault name is misspelled in the keyUri
Why it's wrong here
A misspelled key vault name in the keyUri causes a DNS resolution failure or a '404 Not Found' from the Key Vault endpoint, because the URI cannot resolve to an existing resource. The observed error is an authorization failure (typically HTTP 403 Forbidden), which means the URI resolved successfully and the service reached the vault, so the vault name is valid and the issue lies in identity permission evaluation.
- ✗
The key vault has a firewall enabled and does not allow access from the storage account
Why it's wrong here
Azure Key Vault firewall restrictions are evaluated at the network layer before any authorization or key retrieval occurs. If the storage account's IP address or virtual network is blocked, the API returns a distinct error such as 'Forbidden' with details like 'Not allowed by firewall' or a network rule rejection, rather than a key-access permission error. The error in the scenario is specifically about inability to access the key due to lack of permissions, not a network connectivity or firewall policy issue.
- ✗
The key vault is in a different Azure region than the storage account
Why it's wrong here
Azure Key Vault and Azure Storage account regions are independent; a storage account can use a customer-managed key from a key vault in any Azure region. Cross-region key vault references are fully supported and do not generate access errors, though they might introduce additional latency. The authorization failure occurs against the key vault microservice itself, not as a result of regional mismatch, so this option cannot explain the reported error.
- ✓
The user-assigned managed identity does not have permissions to access the key
Why this is correct
For a storage account using a customer-managed key with a user-assigned managed identity, that identity must be explicitly granted at least get, wrapKey, and unwrapKey permissions on the key vault through an access policy or Azure RBAC (for example, the 'Key Vault Crypto Service Encryption User' role). Without these key-level permissions, Azure Storage cannot retrieve the encryption key or perform wrap/unwrap operations, resulting in a 403 Forbidden error when the storage account attempts to access the keyUri. This matches the symptom and is the correct root cause when other configuration settings like network rules and key version are verified correct.
Go deeper
Related to this question
About these practice questions
One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.