Courseiva

AZ-500 Secure compute, storage, and databases Practice Question

A company stores sensitive data in Azure Blob Storage. They use customer-managed keys (CMK) stored in Azure Key Vault for encryption at rest. The security policy requires that the encryption keys be automatically rotated every 90 days. Which configuration should they implement to meet this requirement without manual intervention?

⚠ Common exam trap

Many exam-takers think custom automation (Option B) is required for key rotation, but Azure Key Vault's built-in auto-rotation feature directly meets the requirement without additional overhead.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable key auto-rotation in Key Vault by setting a rotation policy on the key.

Azure Key Vault supports automatic key rotation by configuring a rotation policy on the key. When you enable auto-rotation, Key Vault automatically creates a new key version at the specified interval (e.g., every 90 days) without any manual intervention. This directly satisfies the requirement for automatic rotation of customer-managed keys used for Azure Storage encryption at rest.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable key auto-rotation in Key Vault by setting a rotation policy on the key.

    Why this is correct

    Key Vault's rotation policy is the native mechanism that automatically generates new key versions at a defined interval (e.g., 90 days) or before an expiry date, without any custom code or manual action. For storage encryption, a versionless key URI in the storage account automatically references the latest rotated version, minimizing disruption. This directly satisfies the requirement for automatic rotation.

  • ✗

    Use a custom Azure Automation runbook to rotate the key.

    Why it's wrong here

    A custom Azure Automation runbook can technically rotate the key by calling PowerShell or REST APIs, but it requires writing and maintaining the script, assigning a managed identity, handling failures, and managing runbook schedules. This adds operational complexity and a separate automation dependency when Key Vault already exposes a built-in rotation policy. The requirement specifically calls for a native, no-manual-intervention solution, making a custom runbook an unnecessary and less supportable alternative.

  • ✗

    Set a key expiration date of 90 days and manually renew.

    Why it's wrong here

    Setting a key expiration date of 90 days and manually renewing before each expiry leaves the rotation process dependent on an administrator's schedule and memory. If the renewal is missed or delayed, the key can expire and cause encryption operations for blob storage to fail, making this approach unreliable. A 90-day expiration with manual renewal does not satisfy the 'without manual intervention' condition.

  • ✗

    Enable versioning on the storage account and manually create a new key version.

    Why it's wrong here

    Enabling versioning on the storage account applies to blob object versions for data protection and does not affect the lifecycle of the customer-managed encryption key in Key Vault. Manually creating a new key version in Key Vault is an administrative action, not an automated process, and if the storage account references a versioned key URI, it will keep using the old version until the account is updated. Therefore this option neither automates rotation nor aligns with the native Key Vault rotation behavior.

Quick reference

Azure Blob Storage Tier Comparison

TierStorage CostRetrieval CostLatencyUse Case
HotHighestLowestImmediateActive data, frequent reads
CoolLowerHigherImmediateData accessed < once / month
ColdLower stillHigherImmediateData accessed < once / quarter
ArchiveLowestHighest + rehydration delayHoursLong-term compliance retention

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.