AZ-500 Secure compute, storage, and databases Practice Question
An Azure Storage account is configured with server-side encryption (SSE) using a customer-managed key stored in Azure Key Vault. The security team requires that the storage account's identity be used to authenticate to the key vault for key access. Additionally, they want the identity to be automatically deleted when the storage account is deleted. Which type of identity should they assign to the storage account?
⚠ Common exam trap
A common mix-up: candidates confuse user-assigned managed identities with system-assigned ones, overlooking the critical lifecycle coupling requirement that system-assigned identities are automatically deleted with the parent resource, while user-assigned identities persist independently.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
System-assigned managed identity
A system-assigned managed identity is tied to the lifecycle of the Azure resource (the storage account) and is automatically deleted when the resource is deleted. This identity can be used to authenticate to Azure Key Vault for accessing the customer-managed key used in server-side encryption (SSE), satisfying the security team's requirement for automatic deletion upon storage account deletion.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
System-assigned managed identity
Why this is correct
A system-assigned managed identity is created directly on the storage account and shares its lifecycle: when enabled, Microsoft Entra ID automatically provisions a corresponding service principal for the account, and when the storage account is deleted, the identity is removed automatically. It requires no application ID, client secret, or certificate rotation, so it meets both requirements of credential-free authentication and automatic cleanup. The storage account can use this identity to authenticate to Azure Key Vault for customer-managed key operations.
- ✗
User-assigned managed identity
Why it's wrong here
A user-assigned managed identity is created as a standalone Azure resource, not as a property of the storage account. Even after you assign it to the storage account, it remains an independent object with its own lifecycle, so deleting the storage account does not delete the identity; you must explicitly delete it later to prevent an orphaned identity and stale Microsoft Entra ID permissions. This manual cleanup requirement violates the prerequisite that the identity be automatically removed when the storage account is removed.
- ✗
Service principal
Why it's wrong here
A service principal is not an identity you assign directly to a resource; it is created through an Microsoft Entra ID app registration and requires managing credentials such as a client secret or certificate. Those credentials expire and must be rotated and securely stored, which contradicts a no-credential-management design. Additionally, the service principal is not linked to the storage account's lifecycle, so deleting the storage account leaves the service principal and its Key Vault permissions in place, requiring separate cleanup.
- ✗
Microsoft Entra ID user account
Why it's wrong here
An Microsoft Entra ID user account is a human principal intended for interactive sign-in, not for non-interactive resource authentication. Using one for the storage account would require storing and rotating a user password, and security features like multi-factor authentication or conditional access would disrupt automated key-fetching operations. A user account has no lifecycle relationship with the storage account, making it both insecure and operationally invalid as an Azure resource identity.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.