AZ-500 Secure compute, storage, and databases Practice Question
You have an Azure Cosmos DB account with multiple containers. You need to ensure that data is encrypted at rest using a customer-managed key stored in Azure Key Vault. Which steps should you take?
⚠ Common exam trap
Test-takers frequently confuse Azure SQL Database encryption features (TDE, Always Encrypted) with Cosmos DB's encryption-at-rest mechanism, or incorrectly assume that VM-level encryption (Azure Disk Encryption) applies to PaaS database services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the Cosmos DB account to use a customer-managed key from Key Vault and assign the appropriate RBAC role.
Azure Cosmos DB supports encryption at rest using customer-managed keys (CMK) stored in Azure Key Vault. To enable this, you must configure the Cosmos DB account to use a CMK from Key Vault and assign the appropriate RBAC role (e.g., 'Key Vault Crypto Service Encryption User') to the Cosmos DB system-assigned managed identity, allowing it to access the key for encryption and decryption operations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Azure Disk Encryption on the VMs hosting Cosmos DB.
Why it's wrong here
Azure Disk Encryption (ADE) applies only to IaaS virtual machine disks and is not relevant to Cosmos DB, which is a fully managed Platform-as-a-Service (PaaS) offering. You never manage or have access to the underlying VMs that host Cosmos DB data, so there are no VM disks to encrypt with ADE. Additionally, Cosmos DB already provides encryption at rest using Microsoft-managed keys; the appropriate way to take control of keys for Cosmos DB is to configure a customer-managed key (CMK) in Azure Key Vault, not ADE.
- ✓
Configure the Cosmos DB account to use a customer-managed key from Key Vault and assign the appropriate RBAC role.
Why this is correct
Configuring the Cosmos DB account to use a customer-managed key (CMK) from Azure Key Vault is the correct approach because Cosmos DB natively supports CMK for encrypting your data at rest. To enable this, you must assign an appropriate RBAC role, such as Key Vault Crypto Service Encryption User, to the Cosmos DB account's system-assigned managed identity or the principal you designate. This ensures that your application uses the key in Key Vault, allowing you to control key rotation, auditing, and revocation while relying on Key Vault's FIPS 140-2-validated HSM protection.
- ✗
Enable Transparent Data Encryption (TDE) and bring your own key (BYOK) from Key Vault.
Why it's wrong here
Transparent Data Encryption (TDE) and bring-your-own-key (BYOK) are SQL database features, specifically designed for Azure SQL Database, Azure SQL Managed Instance, and SQL Server; they do not apply to Cosmos DB. Cosmos DB does not use TDE because its storage engine encrypts data at rest by default with Microsoft-managed keys, and it offers its own CMK integration with Azure Key Vault rather than TDE's SQL-specific mechanism. Therefore, selecting TDE with BYOK is incorrect because it targets a different database service architecture and would not satisfy an encryption-at-rest requirement for Azure Cosmos DB.
- ✗
Enable Always Encrypted on the Cosmos DB account and reference the key from Key Vault.
Why it's wrong here
Always Encrypted is a client-side encryption technology available in Azure SQL Database, Azure SQL Managed Instance, and SQL Server, where sensitive data is encrypted on the client and the keys are stored in Azure Key Vault or Windows Certificate Store. This feature is not available in Azure Cosmos DB, which does not expose Always Encrypted as an encryption option. While Cosmos DB supports client-side encryption using its own library, the correct way to use customer-managed keys for server-side data encryption is to configure a CMK in Key Vault and assign the appropriate RBAC role to the Cosmos DB account, not to enable Always Encrypted.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.