AZ-500 Manage identity and access Practice Question
A managed identity is used by an Azure Function to access Key Vault. Which two configurations are required?
⚠ Common exam trap
A common mix-up: candidates assume a client secret (Option A) is required for any Microsoft Entra ID authentication, failing to recognize that managed identities provide a passwordless, credential-free authentication mechanism via Microsoft Entra ID tokens.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A system-assigned or user-assigned managed identity enabled on the function app
A managed identity (either system-assigned or user-assigned) provides an Microsoft Entra ID-authenticated identity for the function app, eliminating the need for credentials like client secrets. This identity is used to obtain an Microsoft Entra ID access token for authenticating to Key Vault. Option D is also required because the managed identity must be granted explicit Key Vault permissions (e.g., via an access policy or RBAC role) to read secrets; without these permissions, token-based authentication will fail with a 403 Forbidden error.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A client secret stored in the function app settings
Why it's wrong here
A client secret stored in the function app settings does not use a managed identity; it is a manually managed credential that must be rotated and protected in configuration. This approach still requires handling a secret, whereas the stated requirement is to authenticate via an Microsoft Entra ID managed identity, so it fails the core requirement and introduces a security risk.
- ✓
A system-assigned or user-assigned managed identity enabled on the function app
Why this is correct
Enabling a system-assigned or user-assigned managed identity on the function app creates an Microsoft Entra ID identity automatically managed by Azure and tied to the app's lifecycle. The function can then request an access token from the Azure Instance Metadata Service (IMDS) endpoint without any stored secrets, which is exactly the mechanism required to securely authenticate to an Azure key vault.
- ✗
A public IP address on the function app
Why it's wrong here
A public IP address on the function app is a network-level attribution, not an identity; it cannot authenticate to Azure Key Vault or prove that the request comes from that specific function's managed identity. Even if you restrict the Key Vault firewall by IP address, the function still lacks a credential or token for authentication, so this fails the requirement entirely.
- ✓
Key Vault permissions granted to that managed identity
Why this is correct
Granting Key Vault permissions to that managed identity is an essential companion step: without an access policy or an RBAC role such as 'Key Vault Secrets User,' the enabled managed identity will receive a 403 Forbidden when attempting to read the key. This authorization step binds the principal (the managed identity) to a specific data plane action, making it correct as part of the overall solution, though it is not the enabling step itself.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.