AZ-500 Secure compute, storage, and databases Practice Question
Which THREE capabilities are provided by Azure Storage Service Encryption (SSE) when using customer-managed keys?
⚠ Common exam trap
It's easy for candidates to confuse SSE's server-side encryption with client-side encryption (Option B) or mix up access control mechanisms (RBAC) with encryption capabilities, leading them to select options that are valid Azure features but not provided by SSE.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Auditing of key usage via Azure Key Vault logs.
Azure Storage Service Encryption (SSE) with customer-managed keys integrates with Azure Key Vault, which can be configured to log key operations such as encrypt, decrypt, wrap, and unwrap. These logs are sent to Azure Monitor or a storage account, enabling auditing of key usage for compliance and security monitoring.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Auditing of key usage via Azure Key Vault logs.
Why this is correct
Auditing of key usage via Azure Key Vault logs: When Azure Storage accesses a customer-managed key stored in Key Vault to encrypt or decrypt data at rest, the Key Vault records the operation, such as key wrap or unwrap, in its diagnostic logs. By enabling Key Vault auditing, you can monitor key usage, detect unauthorized access, and meet compliance requirements. This capability is present specifically when SSE is configured with customer-managed keys, not with Microsoft-managed keys.
- ✗
Client-side encryption of data before upload.
Why it's wrong here
Client-side encryption of data before upload: This is a separate feature provided by the Azure Storage client SDK, where data is encrypted on the client (for example, using Azure Key Vault or a locally managed key) before transmission and decrypted after download. In contrast, SSE operates entirely on the server side, transparently encrypting data only after it reaches Azure Storage. Therefore, client-side encryption is not a built-in capability of SSE and requires additional application code to implement.
- ✓
Automatic encryption of data at rest.
Why this is correct
Automatic encryption of data at rest: SSE automatically encrypts all data written to Azure Blob, File, Queue, and Table storage, as well as Azure Data Lake Storage Gen2, before persisting it, and transparently decrypts it on read. This behavior requires no code changes and is enabled by default for all storage accounts, using AES-256 encryption. This is the core, foundational capability of Azure Storage Service Encryption.
- ✓
Ability to rotate keys periodically.
Why this is correct
Ability to rotate keys periodically: When SSE is configured with customer-managed keys, you can manually rotate the key in Azure Key Vault or set an automatic rotation policy based on key age or expiry, causing new writes to be encrypted with a new key version. Azure Storage retains previous key versions so that old data remains decryptable without interruption. This rotation capability is not available with Microsoft-managed keys, where the platform fully manages the key lifecycle.
- ✗
Control access to the storage account using RBAC.
Why it's wrong here
Control access to the storage account using RBAC: Azure RBAC is an authorization mechanism that governs which identities can perform management and data operations, such as listing or reading blobs. While RBAC is essential for securing access to a storage account, it does not perform encryption or participate in the SSE encryption pipeline. Encryption and access control are independent security layers, so RBAC control should not be conflated with data-at-rest encryption.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.