AZ-500 Secure compute, storage, and databases Practice Question
A company enables Azure Disk Encryption (ADE) on Windows virtual machines using a key encryption key (KEK) stored in Azure Key Vault. They want the KEK to be automatically rotated every 30 days to meet compliance requirements. Which Azure Key Vault feature should they enable?
⚠ Common exam trap
Test-takers frequently confuse key expiration (which only invalidates a key) with key rotation (which creates a new version and keeps the old one valid for a time), leading them to select 'Key expiration date' instead of 'Key rotation policy'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Key rotation policy
A key rotation policy in Azure Key Vault allows you to define automatic rotation rules for keys, including a rotation interval (e.g., every 30 days) and a rotation time window. This feature ensures that the KEK is automatically replaced with a new key version at the specified interval without manual intervention, meeting compliance requirements for periodic key rotation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Key rotation policy
Why this is correct
Azure Key Vault's key rotation policy enables automatic generation of a new key version at a specified interval, such as every 30 days, without administrator intervention. For Azure Disk Encryption, this rotation re-wraps the BitLocker key encryption key (KEK) used to encrypt the disk encryption key (DEK), ensuring that the underlying data remains encrypted while the key material is refreshed. This is the correct option because it satisfies the requirement for automatic, recurring key rotation as opposed to a one-time action.
- ✗
Key expiration date
Why it's wrong here
Setting an expiration date on a Key Vault key causes the key to become disabled or unusable after the specified date, but it does not trigger creation of a new key version. For Azure Disk Encryption, an expired key would prevent the VM from successfully decrypting its disks, potentially causing boot failures rather than rotating to fresh key material. Because the requirement is for ongoing rotation, expiration alone fails to meet it.
- ✗
Soft-delete
Why it's wrong here
Soft-delete is a Key Vault data protection feature that retains a deleted key for a configurable retention period, allowing recovery of accidentally removed key material. It does not generate new key versions or alter the active key's cryptographic material, so it cannot serve as a key rotation mechanism. While soft-delete is a recommended security control for ADE environments to avoid data loss, it is unrelated to rotating the KEK or DEK.
- ✗
Purge protection
Why it's wrong here
Purge protection is a Key Vault security setting that prevents a soft-deleted vault or key from being permanently purged until the retention period has elapsed, thereby guarding against permanent loss. It does not create any new key versions or change the key's rotation schedule, so it has no effect on automating a 30-day key refresh for Azure Disk Encryption. Purge protection complements deletion recovery but cannot fulfill the requirement for automatic key rotation.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.