AZ-500 Secure compute, storage, and databases Practice Question
You are a security administrator for a company that stores sensitive data in Azure Blob Storage. The data must be encrypted at rest with a customer-managed key (CMK) stored in Azure Key Vault, and the key must be automatically rotated every 90 days. You need to configure the storage account to meet these requirements. What should you do?
⚠ Common exam trap
Candidates often confuse infrastructure encryption or customer-provided keys with customer-managed keys stored in Key Vault, which are distinct features with different configuration steps.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the storage account to use a customer-managed key from Key Vault and set the key rotation policy in Key Vault to 90 days.
To use a customer-managed key for Azure Storage encryption, you must configure the storage account to reference a key in Key Vault. Key Vault's rotation policy can automatically rotate the key on a schedule, and the storage account will use the latest version if configured to do so. This provides automatic key rotation without manual intervention, satisfying the 90-day requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a customer-provided key (CPK) on each blob upload and configure an Azure Automation runbook to rotate the key every 90 days.
Why it's wrong here
Customer-provided keys are specified per request and are not stored by Azure; they do not provide at-rest encryption with a customer-managed key in Key Vault. An Automation runbook could rotate keys but would not integrate with the storage account's encryption configuration. This option does not meet the requirement for CMK-based encryption at rest.
- ✗
Enable infrastructure encryption on the storage account and set the key rotation policy in Key Vault to 90 days.
Why it's wrong here
Infrastructure encryption adds a second layer of encryption but does not configure the use of a customer-managed key for the primary encryption. The rotation policy in Key Vault alone would rotate the key, but the storage account must be explicitly configured to use that key. This option does not ensure the storage account uses the CMK, so it fails the requirement.
- ✓
Configure the storage account to use a customer-managed key from Key Vault and set the key rotation policy in Key Vault to 90 days.
Why this is correct
Configuring the storage account to use a customer-managed key from Key Vault ensures that the data encryption key is wrapped by the CMK. Setting a rotation policy in Key Vault automatically rotates the key every 90 days. Because the storage account references the Key Vault key, it will use the new key version after rotation, meeting both encryption and rotation requirements.
- ✗
Create a new customer-managed key in Key Vault every 90 days and manually update the storage account to use the new key.
Why it's wrong here
Manual key rotation is error-prone and does not provide automatic rotation. The scenario requires automatic rotation every 90 days, which this approach does not guarantee. Additionally, manually updating the storage account introduces operational overhead and potential downtime, making it an inefficient and unreliable solution.
Quick reference
Azure Blob Storage Tier Comparison
| Tier | Storage Cost | Retrieval Cost | Latency | Use Case |
|---|---|---|---|---|
| Hot | Highest | Lowest | Immediate | Active data, frequent reads |
| Cool | Lower | Higher | Immediate | Data accessed < once / month |
| Cold | Lower still | Higher | Immediate | Data accessed < once / quarter |
| Archive | Lowest | Highest + rehydration delay | Hours | Long-term compliance retention |
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.