Exam AZ-500 All QuestionsBrowse all questions from this exam
Question 466

You need to encrypt storage1 to meet the technical requirements.

Which key vaults can you use?

    Correct Answer: D

    The storage account and the key vault must be in the same Azure Active Directory (Azure AD) tenant, but they can be in different regions and subscriptions. Therefore, all three key vaults, KeyVault1, KeyVault2, and KeyVault3, can be used to encrypt storage1, since they do not need to be in the same region. Guidelines confirm that the storage account and key vault can be in different regions within the same tenant.

Discussion
somenickOption: D

Things have changed. Now KeyVault can be in a different region or sub, but in the same tenant: https://learn.microsoft.com/en-us/azure/storage/common/customer-managed-keys-configure-existing-account?WT.mc_id=Portal-Microsoft_Azure_Storage&tabs=azure-portal

azure_2563

Correct

Pamban

Correct! supported below You can either create your own keys and store them in the key vault or managed HSM, or you can use the Azure Key Vault APIs to generate keys. The storage account and the key vault or managed HSM can be in different Microsoft Entra tenants, regions, and subscriptions. Link: https://learn.microsoft.com/en-us/azure/storage/common/customer-managed-keys-overview

Dom1nation

Still though keep in mind it's different for Azure Disk Encryption: https://learn.microsoft.com/en-us/azure/virtual-machines/windows/disk-encryption-key-vault?tabs=azure-portal#create-a-key-vault

JaridBOption: A

No one has pointed out that a Standard tier keyvault does not support automatic key rotation, its only an feature offered with priemium tier pricing. Correct answer would be A. KeyVault2 and KeyVault3 only

datz

You are right sir, questions clearly asks meet technical requirements...meaning automatic key rotations...

zellckOption: D

D is the answer. https://learn.microsoft.com/en-us/azure/storage/common/customer-managed-keys-configure-existing-account?tabs=azure-portal You can use a new or existing key vault to store customer-managed keys. The storage account and key vault may be in different regions or subscriptions in the same tenant.

majstor86Option: D

D. KeyVault1, KeyVault2, and KeyVault3

TheProfessorOption: D

The storage account and the key vault or managed HSM can be in different Azure Active Directory (Azure AD) tenants, regions, and subscriptions.

TheProfessor

Ref link: https://learn.microsoft.com/en-us/azure/storage/common/customer-managed-keys-overview

Pipas_PeladasOption: D

On reference link: The storage account and the key vault or managed HSM can be different Azure Active Directory (Azure AD) tenants, regions, and subscriptions.

WilianCAriasOption: D

D for sure

wardy1983Option: D

Answer: D Explanation: Things have changed. Now KeyVault can be in a different region or sub, but in the same tenant: https://learn.microsoft.com/en-us/azure/storage/common/customer-managed-keys-configure-existingaccount? WT.mc_id=Portal-Microsoft_Azure_Storage&tabs=azure-portal On reference link: The storage account and the key vault or managed HSM can be different Azure Active Directory (Azure AD) tenants, regions, and subscriptions.

tutonataOption: D

You can either create your own keys and store them in the key vault or managed HSM, or you can use the Azure Key Vault APIs to generate keys. The storage account and the key vault or managed HSM can be different Azure Active Directory (Azure AD) tenants, regions, and subscriptions. https://learn.microsoft.com/en-us/azure/storage/common/customer-managed-keys-overview

another2Option: D

You can use all the key Vaultes in the same Tenant, answer is D

OumaOption: D

Confirmed - ttps://learn.microsoft.com/en-us/azure/storage/common/customer-managed-keys-configure-existing-account?WT.mc_id=Portal-Microsoft_Azure_Storage&tabs=azure-portal

joegie00698Option: D

Answer is correct. The disk encryption part is the key: To ensure that encryption secrets don't cross regional boundaries, you must create and use a key vault that's in the same region and tenant as the VMs to be encrypted.

Pamban

it is not regarding vm, it is storage right?

wardy1983Option: D

D Things have changed. Now KeyVault can be in a different region or sub, but in the same tenant: https://learn.microsoft.com/en-us/azure/storage/common/customer-managed-keys-configure-existingaccount? WT.mc_id=Portal-Microsoft_Azure_Storage&tabs=azure-portal On reference link: The storage account and the key vault or managed HSM can be different Azure Active Directory (Azure AD) tenants, regions, and subscriptions.

_punky_Option: D

Explanation: No, the Key Vault and the Azure Storage Account do not need to be in the same region when using customer-managed keys for Azure Storage encryption1. The storage account and the Key Vault or Managed Hardware Security Module (HSM) can be in different Microsoft Entra tenants, regions, and subscriptions

ESAJRROption: B

B. KeyVault1 only

massnonnOption: D

it's D: keyvault it's same geographical area and subscription