Courseiva

AZ-500 Secure compute, storage, and databases Practice Question

You need to ensure that an Azure Key Vault is accessible only from a specific virtual network and that all operations are logged. What should you configure?

⚠ Common exam trap

Many candidates confuse Azure RBAC (which controls permissions) with network-level access controls, or they think Azure Policy alone can enforce VNet restrictions, but Policy only audits or enforces configuration settings—it does not configure the actual firewall rules or diagnostic logging.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Key Vault firewall and virtual network service endpoints, and diagnostic settings

To restrict Key Vault access to a specific virtual network, you must configure the Key Vault firewall and virtual network service endpoints, which allow you to deny all traffic except that originating from the specified VNet/subnet. To log all operations, you must configure diagnostic settings to send audit events (e.g., AuditEvent logs) to a Log Analytics workspace, Storage account, or Event Hub. Option A is correct because it combines both network access control and logging requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Key Vault firewall and virtual network service endpoints, and diagnostic settings

    Why this is correct

    Enabling the Key Vault firewall with an "Allow selected networks" rule and configuring virtual network service endpoints for Microsoft.KeyVault restricts data-plane access to approved virtual networks and specified IP CIDRs. This is the enforcement mechanism that determines whether a request originates from an allowed network before the vault processes it. Adding diagnostic settings then captures audit and authentication logs, giving you the observability needed to verify that only permitted clients reached the vault.

  • ✗

    Azure RBAC roles and diagnostic settings

    Why it's wrong here

    RBAC roles such as Key Vault Secrets User govern identity permissions, deciding who can read or write secrets, but they do not inspect the client's source IP address or virtual network. A user holding the role can call the vault from any publicly routable endpoint unless a separate network rule blocks the request. Pairing RBAC with diagnostic settings only tells you who was allowed after the fact; it cannot make the vault accessible only from specific network locations.

  • ✗

    Soft-delete and purge protection, and diagnostic settings

    Why it's wrong here

    Soft-delete and purge protection control the lifecycle of a Key Vault by retaining deleted vaults and enabling recovery within a configurable retention window. They have no bearing on network-layer authorization, so a vault protected this way remains reachable from any network unless its firewall is explicitly configured. Diagnostic settings merely record the traffic that arrives; they impose no network restriction on that traffic.

  • ✗

    Azure Policy and diagnostic settings

    Why it's wrong here

    Azure Policy can audit compliance and even enforce that a Key Vault has a firewall enabled, but the policy engine does not intercept API requests or evaluate source IP addresses during secret operations. To actually ensure the vault is only reachable from approved networks, you must deploy the underlying firewall rules and virtual network service endpoints. Diagnostic settings provide observability, not enforcement, so this combination is a governance tool rather than a network access control solution.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.