hardmultiple choiceObjective-mapped

A company uses Azure SQL Database with Transparent Data Encryption (TDE) protected by a customer-managed key stored in Azure Key Vault. The Key Vault has a firewall enabled that blocks all public network access. The SQL server has a system-assigned managed identity with the 'Key Vault Crypto Service Encryption User' role assigned at the key scope. Despite this, TDE operations fail because the SQL server cannot access the Key Vault. What additional configuration is required?

Question 1hardmultiple choice
Full question →

A company uses Azure SQL Database with Transparent Data Encryption (TDE) protected by a customer-managed key stored in Azure Key Vault. The Key Vault has a firewall enabled that blocks all public network access. The SQL server has a system-assigned managed identity with the 'Key Vault Crypto Service Encryption User' role assigned at the key scope. Despite this, TDE operations fail because the SQL server cannot access the Key Vault. What additional configuration is required?

Answer choices

Why each option matters

Good practice is not just finding the correct option. The wrong answers often show the exact trap the exam wants you to fall into.

A

Distractor review

Enable the Azure SQL Database server's firewall to allow Azure services to access the server.

The SQL server firewall controls access to the SQL server, not access to the Key Vault.

B

Best answer

Configure the Key Vault firewall to allow trusted Microsoft services to bypass the firewall.

This setting allows trusted Azure services, including Azure SQL Database, to access the Key Vault when using a managed identity.

C

Distractor review

Assign a user-assigned managed identity to the SQL server instead of a system-assigned identity.

Both system and user-assigned identities work; the issue is not the identity type but the firewall.

D

Distractor review

Change the Key Vault firewall to allow all networks.

This would open the Key Vault to public access, which defeats the security requirement.

Common exam trap

Common exam trap: ACLs stop at the first match

ACLs are processed top to bottom. The first matching entry wins, and an implicit deny usually exists at the end.

Technical deep dive

How to think about this question

ACL questions test precision: source, destination, protocol, port and direction. A generally correct ACL can still fail if it is applied on the wrong interface or in the wrong direction.

KKey Concepts to Remember

  • Standard ACLs match source addresses.
  • Extended ACLs can match source, destination, protocol and ports.
  • The first matching ACL entry is used.
  • There is usually an implicit deny at the end.

TExam Day Tips

  • Check inbound versus outbound direction.
  • Read the ACL from top to bottom.
  • Look for a broader permit or deny above the intended line.

Related practice questions

Related AZ-500 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

More questions from this exam

Keep practising from the same exam bank, or move into a focused topic page if this question exposed a weak area.

FAQ

Questions learners often ask

What does this AZ-500 question test?

Standard ACLs match source addresses.

What is the correct answer to this question?

The correct answer is: Configure the Key Vault firewall to allow trusted Microsoft services to bypass the firewall. — Azure Key Vault firewall allows you to deny public access but provides an option to allow trusted Microsoft services to bypass the firewall. Azure SQL Database, when configured with a managed identity and the appropriate permissions, is considered a trusted Microsoft service for Key Vault. Enabling this setting allows the SQL server to access the Key Vault for TDE operations without opening public access.

What should I do if I get this AZ-500 question wrong?

Then try more questions from the same exam bank and focus on understanding why the wrong options are tempting.

Discussion

Loading comments…

Sign in to join the discussion.