Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Exhibit

{
  "properties": {
    "infrastructureEncryption": "Enabled",
    "encryption": {
      "keySource": "Microsoft.Keyvault",
      "keyvaultProperties": {
        "keyUri": "https://myvault.vault.azure.net/keys/mykey/abc123",
        "currentVersionedKeyIdentifier": "https://myvault.vault.azure.net/keys/mykey/abc123",
        "lastKeyRotationTimestamp": "2025-12-01T00:00:00Z"
      }
    }
  }
}

Refer to the exhibit. You are reviewing the encryption configuration of an Azure Log Analytics workspace used by Microsoft Sentinel. The configuration shows infrastructure encryption enabled and customer-managed key (CMK) from Azure Key Vault. What additional step must be taken to ensure that the CMK is used for all data?

⚠ Common exam trap

Watch out — candidates often confuse enabling CMK with simply selecting a key from Key Vault, forgetting that the workspace must be explicitly granted cryptographic permissions on that key to actually use it for encryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Grant the Log Analytics workspace access to the Key Vault key

When you configure a customer-managed key (CMK) for a Log Analytics workspace, you must explicitly grant the workspace (via its managed identity) the 'Get', 'Unwrap Key', and 'Wrap Key' permissions on the Key Vault key. Without this access, the workspace cannot use the CMK to encrypt data at rest. Option C correctly identifies this required step.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable double encryption on Sentinel

    Why it's wrong here

    Double encryption is not a configurable option on Microsoft Sentinel. Sentinel inherits encryption at rest from the underlying Log Analytics workspace, and enabling a customer-managed key (CMK) provides one additional encryption layer, not a separate 'double encryption' feature. Thus, this setting cannot grant the workspace any permissions to a Key Vault key, so it does not solve the problem.

  • ✗

    Enable purge protection on the Key Vault

    Why it's wrong here

    Purge protection is a Key Vault deletion-recovery setting that prevents the permanent deletion of vaults and keys, but it has no bearing on which principals can use a key. The identified failure is that the Log Analytics workspace lacks the necessary Key Vault access policy (Get, WrapKey, UnwrapKey) needed to perform encryption operations. Therefore, enabling purge protection alone, while perhaps recommended for CMK scenarios, does not authorize the workspace to access the customer-managed key.

  • ✓

    Grant the Log Analytics workspace access to the Key Vault key

    Why this is correct

    For Sentinel to use a customer-managed key, the Log Analytics workspace that stores Sentinel data must present a managed identity and be granted explicit cryptographic permissions on the Key Vault key. Specifically, the workspace needs Key Vault operations such as Get, WrapKey, and UnwrapKey to encrypt and decrypt the workspace's data encryption key. This access is granted through a Key Vault access policy, so provisioning that policy is the correct remediation.

  • ✗

    Ensure the Key Vault is in a different region than the workspace

    Why it's wrong here

    Azure Key Vault and the Log Analytics workspace that is encrypted with a customer-managed key must reside in the same Azure region. Placing the Key Vault in a different region than the workspace would violate a foundational requirement for CMK and cause the workspace to fail to initialize or encrypt. Therefore, ensuring a different region is exactly the opposite of what is required.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.