Courseiva

AZ-500 Secure compute, storage, and databases Practice Question

Your organization uses Azure Storage for sensitive customer data. You need to ensure that data at rest is encrypted using a customer-managed key (CMK) stored in Azure Key Vault. Additionally, you want to automatically rotate the key every 90 days. What should you configure?

⚠ Common exam trap

A common mix-up: candidates confuse Azure Disk Encryption (for VMs) with Azure Storage encryption (for data services), leading candidates to select Option A even though it does not apply to storage accounts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Azure Storage encryption with a customer-managed key and configure a key rotation policy in Azure Key Vault.

Azure Storage encryption with a customer-managed key (CMK) allows you to use your own key stored in Azure Key Vault to encrypt data at rest. By configuring a key rotation policy in Azure Key Vault, you can automatically rotate the key every 90 days, meeting both the CMK and rotation requirements without custom code.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Azure Disk Encryption on the storage account and store the key in Key Vault with rotation policy.

    Why it's wrong here

    Azure Disk Encryption (ADE) is designed for virtual machine disks, using BitLocker on Windows or DM-Crypt on Linux to protect VM OS and data disks at the host level. It cannot be enabled on an Azure Storage account because storage services such as blobs, files, and queues are not block devices and have no disk-level encryption layer. Additionally, storing the disk encryption key in Key Vault with a rotation policy does not address the requirement, as ADE keys are for VM disks, not for encrypting data at rest within Azure Storage.

  • ✗

    Enable server-side encryption with a platform-managed key and use Azure Policy to enforce rotation.

    Why it's wrong here

    Enabling server-side encryption with a platform-managed key (PMK) means Microsoft owns and rotates the encryption keys entirely, so you have no visibility or control over the key rotation schedule. Azure Policy can only enforce compliance rules like requiring encryption at the storage account level, but it cannot perform key rotation in Key Vault or in the Azure Storage service. Furthermore, PMKs do not support user-configured rotation policies, so this option fails the stated requirement to configure a rotation policy for the customer-managed key.

  • ✗

    Use client-side encryption with .NET client library and implement custom rotation logic.

    Why it's wrong here

    Client-side encryption with the .NET client library encrypts data before it is transmitted, but it requires you to manage the encryption keys and rotation logic within your application code. This approach does not integrate with Azure Key Vault's built-in key rotation policy, meaning you must implement custom logic to track key versions, re-encrypt existing data, and securely exchange keys. Even with custom rotation, the solution would not fulfill the requirement of using an Azure-managed rotation policy, making it more complex and error-prone than the correct answer.

  • ✓

    Enable Azure Storage encryption with a customer-managed key and configure a key rotation policy in Azure Key Vault.

    Why this is correct

    Azure Storage encryption with a customer-managed key (CMK) allows you to specify a key stored in Azure Key Vault, which is used for server-side encryption of all data in the storage account. By configuring a key rotation policy in Key Vault, you can automatically rotate the key version at the desired interval, and the storage service will seamlessly use the new version without any manual intervention. This meets the requirement of both using a customer-managed key and enabling automated rotation through an Azure-native policy.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.