Courseiva

AZ-500 Secure compute, storage, and databases Practice Question

You are designing a solution to store sensitive documents in Azure Blob Storage. The documents must be encrypted at rest using a customer-managed key that is automatically rotated every 90 days. Microsoft Entra ID must be used to control access to the key. What should you use?

⚠ Common exam trap

Many candidates confuse client-side encryption (CSE) with server-side encryption (SSE), mistakenly thinking CSE is required for customer-managed keys, when in fact SSE with CMK in Key Vault provides the same key control with automatic rotation and simpler management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Storage Service Encryption (SSE) with a customer-managed key stored in Azure Key Vault and configure key rotation.

Azure Storage Service Encryption (SSE) with a customer-managed key (CMK) stored in Azure Key Vault allows you to control the encryption key used for data at rest in Blob Storage. By storing the key in Key Vault, you can configure automatic key rotation every 90 days, and you can use Microsoft Entra ID (formerly Azure AD) to control access to the key via RBAC roles such as Key Vault Crypto Officer. This meets all requirements: encryption at rest, customer-managed key, automatic rotation, and Entra ID-based access control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Storage Service Encryption (SSE) with platform-managed keys.

    Why it's wrong here

    Azure Storage Service Encryption (SSE) with platform-managed keys encrypts data at rest automatically, but the encryption keys are managed entirely by Microsoft. This provides no opportunity for your organization to control, rotate, or audit key usage, which is often required for regulatory compliance. Because the keys are not customer-owned, this option fails to meet the requirement of customer-managed key control.

  • ✗

    Azure Storage encryption with infrastructure encryption enabled.

    Why it's wrong here

    Azure Storage encryption with infrastructure encryption enabled provides a second layer of encryption using a separate set of Microsoft-managed keys, resulting in double encryption at the infrastructure level. While this enhances security by protecting against a compromise of a single encryption layer, it still does not offer any customer control over the encryption keys. Therefore, this does not satisfy the need for customer-managed keys and rotation.

  • ✓

    Azure Storage Service Encryption (SSE) with a customer-managed key stored in Azure Key Vault and configure key rotation.

    Why this is correct

    Azure Storage Service Encryption (SSE) with a customer-managed key stored in Azure Key Vault allows you to bring your own key (BYOK) and retain full control over key lifecycle, including enabling automatic rotation on schedule. By configuring key rotation, you can replace keys periodically to meet security and compliance policies, and you can audit key usage through Key Vault and Azure Monitor. This provides the necessary customer control and rotation that are missing from Microsoft-managed key options.

  • ✗

    Client-side encryption (CSE) using Azure Key Vault.

    Why it's wrong here

    Client-side encryption (CSE) using Azure Key Vault encrypts data on the client side before it is uploaded to Azure, using a key retrieved from Key Vault. Although this approach protects data in transit and at rest, it requires you to implement and manage encryption logic within your client applications, including key wrapping and unwrapping. This adds significant application complexity and performance overhead, and it does not leverage the native, transparent server-side encryption offered by Azure Storage, making it a less practical choice for this scenario.

Quick reference

Azure Blob Storage Tier Comparison

TierStorage CostRetrieval CostLatencyUse Case
HotHighestLowestImmediateActive data, frequent reads
CoolLowerHigherImmediateData accessed < once / month
ColdLower stillHigherImmediateData accessed < once / quarter
ArchiveLowestHighest + rehydration delayHoursLong-term compliance retention

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.