AZ-500 Secure compute, storage, and databases Practice Question
A company uses Azure Key Vault to store secrets for their applications. They want to ensure that an application hosted on an Azure virtual machine can access secrets from only a specific Key Vault, and that all traffic between the VM and Key Vault remains within the Azure network and does not traverse the public internet. Which configuration should they implement?
⚠ Common exam trap
A common mix-up: candidates confuse service endpoints with private endpoints, not realizing that service endpoints still use the public endpoint of the resource and do not provide true private IP-based isolation, while private endpoints assign a private IP and can fully disable public access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a private endpoint for Key Vault in the same VNet as the VM and disable public network access on the Key Vault.
It combines a private endpoint for Azure Key Vault with disabling public network access. A private endpoint assigns a private IP address from the VM's VNet to the Key Vault, ensuring all traffic stays within the Microsoft Azure backbone network and never traverses the public internet. Disabling public network access on the Key Vault firewall then blocks any attempts to access the vault via its public endpoint, enforcing that only traffic through the private endpoint is allowed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a private endpoint for Key Vault in the same VNet as the VM and disable public network access on the Key Vault.
Why this is correct
A private endpoint attaches a network interface with a private IP from your VNet directly to Key Vault, so all requests from the VM resolve to that IP and traverse the Azure backbone rather than the public internet. Disabling public network access on the vault, which means setting the firewall's default action to deny and allowing only private endpoint connections, ensures that no traffic can reach the vault through its public DNS name or IP. This combination gives the required private connectivity and eliminates any accidental public exposure, which is why it is the correct choice.
- ✗
Enable the Key Vault firewall and add the VM's public IP address to the allowed list.
Why it's wrong here
Adding the VM's public IP address to the Key Vault firewall only filters which source IPs are permitted to hit the vault's public endpoint; it does not change the network path the traffic takes. The VM's requests still resolve to Key Vault's public IP address and are routed over the internet/public infrastructure, directly violating the requirement to avoid the public internet. Moreover, a VM without a stable public IP (e.g., behind Azure NAT or in a subnet without a public IP) may not even have a source IP to add, making this approach both insecure and operationally brittle.
- ✗
Use a service endpoint for Key Vault on the VM's subnet, and assign a managed identity to the VM.
Why it's wrong here
A service endpoint routes traffic from the VM's subnet to the Key Vault service over the Azure backbone, but it still terminates at the service's public endpoint—the vault's public IP address—so it does not provide the isolation of a private IP. Only a private endpoint places a private IP from your VNet in front of the vault, which is what meets the 'no public internet' requirement. Assigning a managed identity to the VM only addresses authentication, not the network path, so this combination fails to deliver the required private connectivity.
- ✗
Assign a system-assigned managed identity to the VM and grant it access to the Key Vault.
Why it's wrong here
A system-assigned managed identity gives the VM an Microsoft Entra-backed identity that can be granted access to Key Vault secrets, but it solely handles authentication and authorization. It does not affect how the VM reaches the vault; without a private endpoint or service endpoint, the request still goes to the vault's public endpoint over the internet. Network privacy is a separate control-plane concern, so this option cannot satisfy the requirement to keep traffic off the public internet.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.