Courseiva

AZ-500 Secure compute, storage, and databases Practice Question

You are the security administrator for a company that uses Azure Blob Storage to store sensitive documents. You need to ensure that all blob data is encrypted at rest using customer-managed keys (CMK) stored in Azure Key Vault. You have enabled encryption with CMK on the storage account. However, after a key rotation in Key Vault, you notice that newly uploaded blobs are encrypted with the new key, but existing blobs are still encrypted with the old key. You need to ensure that all blobs are re-encrypted with the new key. What should you do?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Re-upload the existing blobs using the new key version by calling the Put Blob operation with the new encryption key.

To ensure all blobs are re-encrypted with the new key, you must trigger a rewrite of the blob data. Re-uploading the existing blobs using the Put Blob operation with the new encryption key forces the storage account to re-encrypt the data using the latest key version from Key Vault. Option A is incorrect because the 'Rewrite' operation does not exist in Azure Blob Storage; you must overwrite the blob to trigger re-encryption. Option B is incorrect because changing the encryption key setting does not retroactively re-encrypt existing blobs; it only applies to new blobs. Option C is incorrect because Azure Storage does not automatically re-encrypt existing blobs when the key is rotated; only new blobs use the new key version.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Update the storage account's encryption scope to use the new key version and then call the 'Rewrite' operation on each blob.

    Why it's wrong here

    The Azure Blob Storage API does not expose a 'Rewrite' operation; blobs cannot be re-encrypted in place via a dedicated API call. Even if you update the encryption scope to reference the new key version, existing blobs remain encrypted with the key version that was active at the time of their last write. To apply the new key version, you must read the data and write it back as a new blob version or overwrite the existing blob, for example via Put Blob. Therefore this option is invalid because it references a non-existent operation and would not change the encryption of existing blobs.

  • ✗

    Set the storage account encryption to use a different key, then revert to the original key to force re-encryption.

    Why it's wrong here

    Rotating or changing the customer-managed encryption key at the storage account level updates the key used for future encryption operations, but it does not initiate a background re-encryption of existing blob data. The act of switching to a different key and back merely updates key metadata; blobs remain associated with the key version that was in effect when they were last written. There is no 'force re-encryption' mechanism through key switching—you must explicitly rewrite the data to have it encrypted with the new key.

  • ✗

    No action is needed; Azure Storage automatically re-encrypts existing blobs with the new key after rotation.

    Why it's wrong here

    Azure Storage does not perform automatic re-encryption of existing blobs after a customer-managed key rotation. Each blob's encryption metadata records the key version used at the time it was written, and that metadata remains unchanged until the blob is rewritten. Simply rotating the key in Key Vault or updating the storage account's encryption settings has no effect on existing blob data. To satisfy the requirement, you must actively rewrite the blobs with the new key version.

  • ✓

    Re-upload the existing blobs using the new key version by calling the Put Blob operation with the new encryption key.

    Why this is correct

    To encrypt existing blobs with the new key version, you need to rewrite them. The recommended approach is to call the Put Blob operation (e.g., using the same blob name) with the new encryption key version, which overwrites the existing blob and encrypts it under the current key. This ensures the blob's encryption metadata is updated to reflect the new key version. You could also use Copy Blob or an Azure Storage SDK to read and re-upload the data, but Put Blob is the direct mechanism.

Quick reference

Azure Blob Storage Tier Comparison

TierStorage CostRetrieval CostLatencyUse Case
HotHighestLowestImmediateActive data, frequent reads
CoolLowerHigherImmediateData accessed < once / month
ColdLower stillHigherImmediateData accessed < once / quarter
ArchiveLowestHighest + rehydration delayHoursLong-term compliance retention

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.