AZ-500 Secure compute, storage, and databases Practice Question
Exhibit
{
"properties": {
"encryption": {
"keySource": "Microsoft.Keyvault",
"keyvaultproperties": {
"keyvaulturi": "https://mykeyvault.vault.azure.net/",
"keyname": "myencryptionkey",
"keyversion": "1234567890abcdef"
}
}
}
}Refer to the exhibit. You are deploying an Azure Storage account with the ARM template snippet shown. The deployment fails with an error about the encryption configuration. What is the most likely cause?
⚠ Common exam trap
Candidates often assume the key vault URI or key identifier is the only configuration needed, overlooking the critical requirement that the storage account's identity must have explicit permissions on the key vault.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The storage account does not have the required permissions on the key vault
The storage account must be granted explicit permissions on the Azure Key Vault to access the encryption key. Even if the key vault URI, key name, and version are correct, the deployment will fail if the storage account's managed identity (or the user-assigned identity) does not have 'Get', 'Wrap Key', and 'Unwrap Key' permissions on the key vault. This is a common oversight when configuring customer-managed keys for Azure Storage encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The key vault URI is incorrect
Why it's wrong here
The key vault URI is not the problem because the format shown is syntactically valid: Azure Key Vault URIs always use the pattern https://{vault-name}.vault.azure.net/{object-type}/{name}/{version}. A malformed URI would produce a validation error such as "Invalid URI" or "KeyVaultUrlFailed", not an authorization failure. The error you are seeing points to the storage account being denied access to the key, not to an issue with the URI's structure.
- ✓
The storage account does not have the required permissions on the key vault
Why this is correct
The most likely root cause is that the storage account's system-assigned managed identity has not been granted the required permissions on the key vault. When you use customer-managed keys (CMK) with Azure Storage, the storage service must wrap and unwrap the data encryption key using the key vault key. To do this, the managed identity needs at least Get, WrapKey, and UnwrapKey permissions on the key vault's access policy (or the equivalent RBAC role such as "Key Vault Crypto Service Encryption User"). Without these permissions, the storage account cannot perform the envelope encryption operation and the deployment fails.
- ✗
The key name or version is missing
Why it's wrong here
The key name and version are indeed both present in the provided snippet, so this is not the cause. A missing key name or version would cause a clear validation error, often with a message like "The specified keyvault key name is invalid" or "Key version is required"—not an authorization or permission failure. Since the configuration already includes a specific version, the storage account can resolve the key's material; the remaining issue is access, not completeness of the key identifier.
- ✗
The key vault is in a different region than the storage account
Why it's wrong here
The key vault being in a different region than the storage account is not a valid reason for this error. Azure Storage supports customer-managed keys from key vaults in any Azure region; the storage service accesses the key vault over the network using the key's URI. Cross-region failures would typically manifest as network connectivity problems or DNS resolution errors, not as an authorization failure. The error you are seeing is an access-permissions issue, which is independent of the key vault's geographic location.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.