hardmultiple choiceObjective-mapped

A company stores sensitive data in Azure Blob Storage. They want to enforce encryption at rest using a customer-managed key (CMK) stored in Azure Key Vault. Additionally, they require that the key vault be in a different region than the storage account to protect against regional disasters. Can this be achieved, and if so, what is the implication?

Question 1hardmultiple choice
Full question →

A company stores sensitive data in Azure Blob Storage. They want to enforce encryption at rest using a customer-managed key (CMK) stored in Azure Key Vault. Additionally, they require that the key vault be in a different region than the storage account to protect against regional disasters. Can this be achieved, and if so, what is the implication?

Answer choices

Why each option matters

Good practice is not just finding the correct option. The wrong answers often show the exact trap the exam wants you to fall into.

A

Distractor review

Yes, but the storage account must use a different key vault per region; no other implications.

This is incorrect because the key vault must be in the same region as the storage account, not just different vaults per region.

B

Distractor review

Yes, but you must enable cross-region replication for the key vault and pay additional costs.

Azure Key Vault offers geo-replication for the vault itself, but this does not enable using a vault from a different region for storage encryption. The storage encryption CMK feature requires the vault to be in the same region.

C

Best answer

No, Azure does not support CMK from a different region than the storage account.

This is correct. The key vault and the storage account must reside in the same region for CMK encryption of Azure Storage.

D

Distractor review

Yes, but you must use a managed identity from the storage account's region to access the key vault.

Managed identity region does not override the requirement; the key vault must be in the same region as the storage account regardless of identity.

Common exam trap

Common exam trap: answer the scenario, not the keyword

Many certification questions include familiar terms but test a specific constraint. Read the exact wording before choosing an answer that is generally true but wrong for this case.

Technical deep dive

How to think about this question

This question should be treated as a scenario, not a definition check. Identify the problem, the constraint and the best action. Then compare each option against those facts.

KKey Concepts to Remember

  • Read the scenario before looking for a memorised answer.
  • Find the constraint that changes the correct option.
  • Eliminate answers that are true in general but not in this case.
  • Use explanations to understand the rule behind the answer.

TExam Day Tips

  • Underline the problem statement mentally.
  • Watch for words such as best, first, most likely and least administrative effort.
  • Review why wrong options are wrong, not only why the correct option is correct.

Related practice questions

Related AZ-500 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

More questions from this exam

Keep practising from the same exam bank, or move into a focused topic page if this question exposed a weak area.

FAQ

Questions learners often ask

What does this AZ-500 question test?

Read the scenario before looking for a memorised answer.

What is the correct answer to this question?

The correct answer is: No, Azure does not support CMK from a different region than the storage account. — Azure Storage encryption with customer-managed keys requires the key vault to be in the same Azure region as the storage account. Cross-region key vaults are not supported for storage encryption. This is a fundamental limitation to be aware of. The storage account cannot use a CMK from a different region, so the requirement cannot be met as stated.

What should I do if I get this AZ-500 question wrong?

Then try more questions from the same exam bank and focus on understanding why the wrong options are tempting.

Discussion

Loading comments…

Sign in to join the discussion.