Courseiva

AZ-500 Secure compute, storage, and databases Practice Question

You have an Azure Cosmos DB account with multiple containers. You need to ensure that data is encrypted at rest using a customer-managed key stored in Azure Key Vault. Which steps should you take?

⚠ Common exam trap

Test-takers frequently confuse Azure SQL Database encryption features (TDE, Always Encrypted) with Cosmos DB's encryption-at-rest mechanism, or incorrectly assume that VM-level encryption (Azure Disk Encryption) applies to PaaS database services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the Cosmos DB account to use a customer-managed key from Key Vault and assign the appropriate RBAC role.

Azure Cosmos DB supports encryption at rest using customer-managed keys (CMK) stored in Azure Key Vault. To enable this, you must configure the Cosmos DB account to use a CMK from Key Vault and assign the appropriate RBAC role (e.g., 'Key Vault Crypto Service Encryption User') to the Cosmos DB system-assigned managed identity, allowing it to access the key for encryption and decryption operations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Azure Disk Encryption on the VMs hosting Cosmos DB.

    Why it's wrong here

    Azure Disk Encryption (ADE) applies only to IaaS virtual machine disks and is not relevant to Cosmos DB, which is a fully managed Platform-as-a-Service (PaaS) offering. You never manage or have access to the underlying VMs that host Cosmos DB data, so there are no VM disks to encrypt with ADE. Additionally, Cosmos DB already provides encryption at rest using Microsoft-managed keys; the appropriate way to take control of keys for Cosmos DB is to configure a customer-managed key (CMK) in Azure Key Vault, not ADE.

  • ✓

    Configure the Cosmos DB account to use a customer-managed key from Key Vault and assign the appropriate RBAC role.

    Why this is correct

    Configuring the Cosmos DB account to use a customer-managed key (CMK) from Azure Key Vault is the correct approach because Cosmos DB natively supports CMK for encrypting your data at rest. To enable this, you must assign an appropriate RBAC role, such as Key Vault Crypto Service Encryption User, to the Cosmos DB account's system-assigned managed identity or the principal you designate. This ensures that your application uses the key in Key Vault, allowing you to control key rotation, auditing, and revocation while relying on Key Vault's FIPS 140-2-validated HSM protection.

  • ✗

    Enable Transparent Data Encryption (TDE) and bring your own key (BYOK) from Key Vault.

    Why it's wrong here

    Transparent Data Encryption (TDE) and bring-your-own-key (BYOK) are SQL database features, specifically designed for Azure SQL Database, Azure SQL Managed Instance, and SQL Server; they do not apply to Cosmos DB. Cosmos DB does not use TDE because its storage engine encrypts data at rest by default with Microsoft-managed keys, and it offers its own CMK integration with Azure Key Vault rather than TDE's SQL-specific mechanism. Therefore, selecting TDE with BYOK is incorrect because it targets a different database service architecture and would not satisfy an encryption-at-rest requirement for Azure Cosmos DB.

  • ✗

    Enable Always Encrypted on the Cosmos DB account and reference the key from Key Vault.

    Why it's wrong here

    Always Encrypted is a client-side encryption technology available in Azure SQL Database, Azure SQL Managed Instance, and SQL Server, where sensitive data is encrypted on the client and the keys are stored in Azure Key Vault or Windows Certificate Store. This feature is not available in Azure Cosmos DB, which does not expose Always Encrypted as an encryption option. While Cosmos DB supports client-side encryption using its own library, the correct way to use customer-managed keys for server-side data encryption is to configure a CMK in Key Vault and assign the appropriate RBAC role to the Cosmos DB account, not to enable Always Encrypted.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.