AZ-500 Secure compute, storage, and databases Practice Question
A company stores sensitive data in Azure Blob Storage. They use customer-managed keys (CMK) stored in Azure Key Vault for encryption at rest. The security policy requires that the encryption keys be automatically rotated every 90 days. Which configuration should they implement to meet this requirement without manual intervention?
⚠ Common exam trap
Many exam-takers think custom automation (Option B) is required for key rotation, but Azure Key Vault's built-in auto-rotation feature directly meets the requirement without additional overhead.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable key auto-rotation in Key Vault by setting a rotation policy on the key.
Azure Key Vault supports automatic key rotation by configuring a rotation policy on the key. When you enable auto-rotation, Key Vault automatically creates a new key version at the specified interval (e.g., every 90 days) without any manual intervention. This directly satisfies the requirement for automatic rotation of customer-managed keys used for Azure Storage encryption at rest.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable key auto-rotation in Key Vault by setting a rotation policy on the key.
Why this is correct
Key Vault's rotation policy is the native mechanism that automatically generates new key versions at a defined interval (e.g., 90 days) or before an expiry date, without any custom code or manual action. For storage encryption, a versionless key URI in the storage account automatically references the latest rotated version, minimizing disruption. This directly satisfies the requirement for automatic rotation.
- ✗
Use a custom Azure Automation runbook to rotate the key.
Why it's wrong here
A custom Azure Automation runbook can technically rotate the key by calling PowerShell or REST APIs, but it requires writing and maintaining the script, assigning a managed identity, handling failures, and managing runbook schedules. This adds operational complexity and a separate automation dependency when Key Vault already exposes a built-in rotation policy. The requirement specifically calls for a native, no-manual-intervention solution, making a custom runbook an unnecessary and less supportable alternative.
- ✗
Set a key expiration date of 90 days and manually renew.
Why it's wrong here
Setting a key expiration date of 90 days and manually renewing before each expiry leaves the rotation process dependent on an administrator's schedule and memory. If the renewal is missed or delayed, the key can expire and cause encryption operations for blob storage to fail, making this approach unreliable. A 90-day expiration with manual renewal does not satisfy the 'without manual intervention' condition.
- ✗
Enable versioning on the storage account and manually create a new key version.
Why it's wrong here
Enabling versioning on the storage account applies to blob object versions for data protection and does not affect the lifecycle of the customer-managed encryption key in Key Vault. Manually creating a new key version in Key Vault is an administrative action, not an automated process, and if the storage account references a versioned key URI, it will keep using the old version until the account is updated. Therefore this option neither automates rotation nor aligns with the native Key Vault rotation behavior.
Quick reference
Azure Blob Storage Tier Comparison
| Tier | Storage Cost | Retrieval Cost | Latency | Use Case |
|---|---|---|---|---|
| Hot | Highest | Lowest | Immediate | Active data, frequent reads |
| Cool | Lower | Higher | Immediate | Data accessed < once / month |
| Cold | Lower still | Higher | Immediate | Data accessed < once / quarter |
| Archive | Lowest | Highest + rehydration delay | Hours | Long-term compliance retention |
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.