Courseiva

AZ-305 Design infrastructure solutions Practice Question

Exhibit

{
  "properties": {
    "encryption": {
      "keySource": "Microsoft.Keyvault",
      "keyVaultProperties": {
        "keyUri": "https://mykeyvault.vault.azure.net/keys/mykey/abc123",
        "identity": {
          "userAssignedIdentity": "/subscriptions/.../providers/Microsoft.ManagedIdentity/userAssignedIdentities/mysi"
        }
      }
    }
  }
}

Refer to the exhibit. You are analyzing a deployment of Azure Storage account with customer-managed key encryption. The deployment fails with an error indicating that the key vault is not accessible. Which of the following is the most likely cause?

⚠ Common exam trap

Many exam-takers assume the error is due to a network firewall or a naming mistake, but Azure explicitly requires the managed identity to have cryptographic permissions on the key vault, and the error message 'not accessible' is a generic wrapper for permission failures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The user-assigned managed identity does not have permissions to access the key

When using customer-managed keys (CMK) with Azure Storage encryption, the storage account must authenticate to the key vault to retrieve the key. If a user-assigned managed identity is specified in the encryption policy, that identity must have at least 'Get', 'Wrap Key', and 'Unwrap Key' permissions on the key vault. Without these permissions, the storage account cannot access the key, resulting in a deployment failure with a 'key vault not accessible' error.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The key vault name is misspelled in the keyUri

    Why it's wrong here

    A misspelled key vault name in the keyUri causes a DNS resolution failure or a '404 Not Found' from the Key Vault endpoint, because the URI cannot resolve to an existing resource. The observed error is an authorization failure (typically HTTP 403 Forbidden), which means the URI resolved successfully and the service reached the vault, so the vault name is valid and the issue lies in identity permission evaluation.

  • ✗

    The key vault has a firewall enabled and does not allow access from the storage account

    Why it's wrong here

    Azure Key Vault firewall restrictions are evaluated at the network layer before any authorization or key retrieval occurs. If the storage account's IP address or virtual network is blocked, the API returns a distinct error such as 'Forbidden' with details like 'Not allowed by firewall' or a network rule rejection, rather than a key-access permission error. The error in the scenario is specifically about inability to access the key due to lack of permissions, not a network connectivity or firewall policy issue.

  • ✗

    The key vault is in a different Azure region than the storage account

    Why it's wrong here

    Azure Key Vault and Azure Storage account regions are independent; a storage account can use a customer-managed key from a key vault in any Azure region. Cross-region key vault references are fully supported and do not generate access errors, though they might introduce additional latency. The authorization failure occurs against the key vault microservice itself, not as a result of regional mismatch, so this option cannot explain the reported error.

  • ✓

    The user-assigned managed identity does not have permissions to access the key

    Why this is correct

    For a storage account using a customer-managed key with a user-assigned managed identity, that identity must be explicitly granted at least get, wrapKey, and unwrapKey permissions on the key vault through an access policy or Azure RBAC (for example, the 'Key Vault Crypto Service Encryption User' role). Without these key-level permissions, Azure Storage cannot retrieve the encryption key or perform wrap/unwrap operations, resulting in a 403 Forbidden error when the storage account attempts to access the keyUri. This matches the symptom and is the correct root cause when other configuration settings like network rules and key version are verified correct.

About these practice questions

One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.