AZ-500 Secure compute, storage, and databases Practice Question
You are a security engineer for a healthcare company that stores patient records in an Azure Storage account. A compliance requirement mandates that all data in the storage account be encrypted at rest using a key that the company controls and can revoke at any time. The storage account is currently configured with Microsoft-managed keys for encryption. You need to change the encryption key management to meet the compliance requirement. What should you do first?
⚠ Common exam trap
Many candidates confuse encryption in transit (Secure transfer required) or infrastructure encryption with customer-managed encryption at rest.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an Azure Key Vault and generate a customer-managed key, then configure the storage account to use that key for encryption.
To meet the requirement of encrypting data at rest with a customer-managed key, you must create an Azure Key Vault, generate a key, and configure the storage account to use that key for encryption. This ensures the organization controls the key lifecycle, including revocation. Other options either address different encryption aspects (in-transit) or use Microsoft-managed keys, which do not provide the required control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an Azure Key Vault and generate a customer-managed key, then configure the storage account to use that key for encryption.
Why this is correct
Azure Storage supports server-side encryption with customer-managed keys stored in Azure Key Vault. To meet the requirement of using a company-controlled key that can be revoked, you must create a Key Vault, generate a key, and then update the storage account's encryption settings to use that key. This gives the organization full control over the encryption key lifecycle, including rotation and revocation, satisfying the compliance mandate.
- ✗
Enable Azure Disk Encryption on the storage account to use customer-managed keys.
Why it's wrong here
Azure Disk Encryption is used to encrypt OS and data disks attached to virtual machines, not Azure Storage accounts for blobs or files. It does not apply to storage account encryption at rest. Enabling Azure Disk Encryption on a storage account is not a valid operation and would not meet the requirement for customer-managed keys for blob storage encryption.
- ✗
Enable Secure transfer required on the storage account to enforce encryption in transit.
Why it's wrong here
Secure transfer required enforces HTTPS for data in transit, but the requirement is about encryption at rest with a customer-managed key. Enabling secure transfer does not change how data is encrypted at rest and does not provide customer control over the encryption key. Therefore, it does not meet the compliance requirement.
- ✗
Configure the storage account to use infrastructure encryption with Microsoft-managed keys.
Why it's wrong here
Infrastructure encryption adds a second layer of encryption but still uses Microsoft-managed keys by default. It does not provide customer control over the encryption key. The requirement explicitly states that the company must control the key and be able to revoke it, so infrastructure encryption with Microsoft-managed keys does not satisfy the compliance requirement.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.