AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Exhibit
{
"properties": {
"infrastructureEncryption": "Enabled",
"encryption": {
"keySource": "Microsoft.Keyvault",
"keyvaultProperties": {
"keyUri": "https://myvault.vault.azure.net/keys/mykey/abc123",
"currentVersionedKeyIdentifier": "https://myvault.vault.azure.net/keys/mykey/abc123",
"lastKeyRotationTimestamp": "2025-12-01T00:00:00Z"
}
}
}
}Refer to the exhibit. You are reviewing the encryption configuration of an Azure Log Analytics workspace used by Microsoft Sentinel. The configuration shows infrastructure encryption enabled and customer-managed key (CMK) from Azure Key Vault. What additional step must be taken to ensure that the CMK is used for all data?
⚠ Common exam trap
Watch out — candidates often confuse enabling CMK with simply selecting a key from Key Vault, forgetting that the workspace must be explicitly granted cryptographic permissions on that key to actually use it for encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant the Log Analytics workspace access to the Key Vault key
When you configure a customer-managed key (CMK) for a Log Analytics workspace, you must explicitly grant the workspace (via its managed identity) the 'Get', 'Unwrap Key', and 'Wrap Key' permissions on the Key Vault key. Without this access, the workspace cannot use the CMK to encrypt data at rest. Option C correctly identifies this required step.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable double encryption on Sentinel
Why it's wrong here
Double encryption is not a configurable option on Microsoft Sentinel. Sentinel inherits encryption at rest from the underlying Log Analytics workspace, and enabling a customer-managed key (CMK) provides one additional encryption layer, not a separate 'double encryption' feature. Thus, this setting cannot grant the workspace any permissions to a Key Vault key, so it does not solve the problem.
- ✗
Enable purge protection on the Key Vault
Why it's wrong here
Purge protection is a Key Vault deletion-recovery setting that prevents the permanent deletion of vaults and keys, but it has no bearing on which principals can use a key. The identified failure is that the Log Analytics workspace lacks the necessary Key Vault access policy (Get, WrapKey, UnwrapKey) needed to perform encryption operations. Therefore, enabling purge protection alone, while perhaps recommended for CMK scenarios, does not authorize the workspace to access the customer-managed key.
- ✓
Grant the Log Analytics workspace access to the Key Vault key
Why this is correct
For Sentinel to use a customer-managed key, the Log Analytics workspace that stores Sentinel data must present a managed identity and be granted explicit cryptographic permissions on the Key Vault key. Specifically, the workspace needs Key Vault operations such as Get, WrapKey, and UnwrapKey to encrypt and decrypt the workspace's data encryption key. This access is granted through a Key Vault access policy, so provisioning that policy is the correct remediation.
- ✗
Ensure the Key Vault is in a different region than the workspace
Why it's wrong here
Azure Key Vault and the Log Analytics workspace that is encrypted with a customer-managed key must reside in the same Azure region. Placing the Key Vault in a different region than the workspace would violate a foundational requirement for CMK and cause the workspace to fail to initialize or encrypt. Therefore, ensuring a different region is exactly the opposite of what is required.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.