Courseiva

AZ-500 Secure compute, storage, and databases Practice Question

An Azure Storage account is configured with server-side encryption (SSE) using a customer-managed key stored in Azure Key Vault. The security team requires that the storage account's identity be used to authenticate to the key vault for key access. Additionally, they want the identity to be automatically deleted when the storage account is deleted. Which type of identity should they assign to the storage account?

⚠ Common exam trap

A common mix-up: candidates confuse user-assigned managed identities with system-assigned ones, overlooking the critical lifecycle coupling requirement that system-assigned identities are automatically deleted with the parent resource, while user-assigned identities persist independently.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

System-assigned managed identity

A system-assigned managed identity is tied to the lifecycle of the Azure resource (the storage account) and is automatically deleted when the resource is deleted. This identity can be used to authenticate to Azure Key Vault for accessing the customer-managed key used in server-side encryption (SSE), satisfying the security team's requirement for automatic deletion upon storage account deletion.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    System-assigned managed identity

    Why this is correct

    A system-assigned managed identity is created directly on the storage account and shares its lifecycle: when enabled, Microsoft Entra ID automatically provisions a corresponding service principal for the account, and when the storage account is deleted, the identity is removed automatically. It requires no application ID, client secret, or certificate rotation, so it meets both requirements of credential-free authentication and automatic cleanup. The storage account can use this identity to authenticate to Azure Key Vault for customer-managed key operations.

  • ✗

    User-assigned managed identity

    Why it's wrong here

    A user-assigned managed identity is created as a standalone Azure resource, not as a property of the storage account. Even after you assign it to the storage account, it remains an independent object with its own lifecycle, so deleting the storage account does not delete the identity; you must explicitly delete it later to prevent an orphaned identity and stale Microsoft Entra ID permissions. This manual cleanup requirement violates the prerequisite that the identity be automatically removed when the storage account is removed.

  • ✗

    Service principal

    Why it's wrong here

    A service principal is not an identity you assign directly to a resource; it is created through an Microsoft Entra ID app registration and requires managing credentials such as a client secret or certificate. Those credentials expire and must be rotated and securely stored, which contradicts a no-credential-management design. Additionally, the service principal is not linked to the storage account's lifecycle, so deleting the storage account leaves the service principal and its Key Vault permissions in place, requiring separate cleanup.

  • ✗

    Microsoft Entra ID user account

    Why it's wrong here

    An Microsoft Entra ID user account is a human principal intended for interactive sign-in, not for non-interactive resource authentication. Using one for the storage account would require storing and rotating a user password, and security features like multi-factor authentication or conditional access would disrupt automated key-fetching operations. A user account has no lifecycle relationship with the storage account, making it both insecure and operationally invalid as an Azure resource identity.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.