Drag or tap steps into the slots.
SC-100 Practice Question: Order the steps to configure Azure Key Vault…
Order the steps to configure Azure Key Vault firewall and virtual network service endpoints.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Enable service endpoint on subnet, then add virtual network rule in Key Vault firewall, then (optionally) allow trusted Microsoft services, then save the firewall configuration.
The correct sequence for configuring Azure Key Vault firewall and virtual network service endpoints begins by enabling the service endpoint for Microsoft.KeyVault on the target subnet. Next, you add a virtual network rule in the Key Vault firewall settings that references that subnet. Optionally, you can configure the firewall to allow trusted Microsoft services. Finally, you save the configuration to apply all changes. This order ensures that network rules are valid and the firewall behaves as expected.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable service endpoint on subnet, then add virtual network rule in Key Vault firewall, then (optionally) allow trusted Microsoft services, then save the firewall configuration.
Why this is correct
This is the correct order because the service endpoint must be enabled on the subnet before you can add a virtual network rule referencing that subnet. After adding rules, you may choose to allow trusted Microsoft services, and finally save all changes.
- ✗
Add virtual network rule in Key Vault firewall, then enable service endpoint on subnet, then save, then allow trusted Microsoft services.
Why it's wrong here
Attempting to add a virtual network rule to the Key Vault firewall before enabling the Microsoft.KeyVault service endpoint on the subnet fails because the rule cannot resolve or validate the subnet as an allowed source. Azure Key Vault's firewall only accepts virtual network rules for subnets that have the service endpoint explicitly activated, as that endpoint ensures all traffic to the vault is routed through the Microsoft backbone. Without the service endpoint, the rule is either rejected by the API or silently ignored, meaning traffic from that subnet would still be blocked. Additionally, while saving and enabling trusted Microsoft services at the end are correct, the critical dependency is that the service endpoint must precede the rule creation.
- ✗
Enable service endpoint on subnet, then save the firewall configuration, then add virtual network rule, then allow trusted Microsoft services.
Why it's wrong here
Saving the firewall configuration immediately after enabling the service endpoint but before adding the virtual network rule commits a state where no network rules exist, so the Key Vault will continue to deny traffic from the subnet if the default action is 'Deny'. The save operation persists the current rules, and since the rule is absent at that moment, the firewall is locked down and you would need a second, separate update to add the rule—introducing an unnecessary and possibly lengthy window of misconfiguration. This ordering mistake is especially dangerous because if the firewall explicitly denies all other sources, the vault becomes temporarily inaccessible before the rule is added. The correct sequence is to add the virtual network rule as part of the same editing session, then save once all intended rules are in place.
- ✗
Allow trusted Microsoft services, then enable service endpoint, then add virtual network rule, then save.
Why it's wrong here
Turning on the 'Allow trusted Microsoft services' exception before defining network rules is misleading because that bypass applies to all trusted services, effectively weakening the firewall before you have even established the baseline access controls. The intended order is to first configure and save the network rules—such as the virtual network rule—and only then, if needed, add the trusted services exception so that you are explicitly aware of what is being allowed beyond your network boundaries. Additionally, the service endpoint must be enabled on the subnet before adding the virtual network rule, and this sequence incorrectly places the trusted services toggle first, which has no dependency on the service endpoint. The final save should occur only after all rules and exceptions are set, but here saving is correctly last while the earlier steps are in an invalid order.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.