AZ-500 Exam QuestionsBrowse all questions from this exam

AZ-500 Exam - Question 402


You have an Azure subscription that contains as Azure key vault and an Azure Storage account. The key vault contains customer-managed keys. The storage account is configured to use the customer-managed keys stored in the key vault.

You plan to store data in Azure by using the following services:

✑ Azure Files

✑ Azure Blob storage

✑ Azure Table storage

✑ Azure Queue storage

Which two services support data encryption by using the keys stored in the key vault? Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point.

Show Answer
Correct Answer: BC

Azure Files and Blob storage support data encryption using customer-managed keys stored in the key vault. When you configure customer-managed keys for the storage account, data in Blob storage and Azure Files is always protected by these keys. While Queue storage and Table storage do offer encryption, they are not automatically protected by customer-managed keys and require additional configuration during storage account creation. Therefore, the correct options are Azure Files and Blob storage.

Discussion

20 comments
Sign in to comment
majstor86Options: BC
Mar 4, 2023

B. Azure Files C. Blob storage

zellckOptions: BC
May 3, 2023

BC is the answer. https://learn.microsoft.com/en-us/azure/storage/common/customer-managed-keys-overview#customer-managed-keys-for-queues-and-tables Data stored in Queue and Table storage isn't automatically protected by a customer-managed key when customer-managed keys are enabled for the storage account. You can optionally configure these services to be included in this protection at the time that you create the storage account. Data in Blob storage and Azure Files is always protected by customer-managed keys when customer-managed keys are configured for the storage account.

ESAJRROptions: BC
Sep 5, 2023

B. Azure Files C. Blob storage

wingcheukOptions: BC
Jan 19, 2024

B and C support customer-managed keys. Azure Table storage and Azure Queue storage do not support encryption with customer-managed keys. They are encrypted with service-managed keys by default.

thienvupt
Oct 4, 2021

Azure Storage services supported All Blob storage, Azure Files1,2 Blob storage

itbrpl
Oct 20, 2021

Today's exam 20/10/21..

zioggs
Nov 4, 2021

Exam - 4/11/21

sudarchary
Nov 10, 2021

Correct

somenick
Oct 19, 2022

Correct, but outdated. Customer-managed key (CMK) support can be limited to blob service and file service only, or to ALL service types. After the storage account is created, this support cannot be changed.

Ajdlfasudfo0
Jan 1, 2023

outdated question

heatfan900
Sep 12, 2023

ANSWERS R CORRECT FOR CMK: https://learn.microsoft.com/en-us/azure/storage/common/storage-service-encryption

[Removed]
Dec 21, 2023

Customer-managed key (CMK) support can be limited to blob service and file service only, or to all service types. After the storage account is created, this support cannot be changed.Learn more

JackGelder
Nov 12, 2024

Seems outdated for a bit, 'cause now you can choose what services you want to protect with CMK during creation of storage account: it can be blobs and files only or all services.

Anil512
Mar 23, 2025

Now all 4 services can be encrypted using CMK.

cfsxtuv33
Dec 18, 2021

Answers are correct..C and D, the provided link gives informative info regarding question.

cfsxtuv33
Dec 18, 2021

I apologize...B and C

wsrudmenOptions: BC
Oct 10, 2022

Correct. Data in Blob storage and Azure Files is always protected by customer-managed keys when customer-managed keys are configured for the storage account. Data stored in Queue and Table storage isn't automatically protected by a customer-managed key when customer-managed keys are enabled for the storage account. You can optionally configure these services to be included in this protection at the time that you create the storage account.

tutonata
Mar 6, 2023

AD, you need to read the question. When using customer managed keys on a storage account, the CMK are automatically enabled for BLOB and FILE. You can then optionaly configure Queues and Tables. "Data stored in Queue and Table storage isn't automatically protected by a customer-managed key when customer-managed keys are enabled for the storage account. You can optionally configure these services to be included in this protection at the time that you create the storage account." https://learn.microsoft.com/en-us/azure/storage/common/customer-managed-keys-overview#customer-managed-keys-for-queues-and-tables

tutonataOptions: AD
Mar 6, 2023

AD, you need to read the question. Question says: "storage account is configured to use the CMK stored in the keyvault" so the question is about the additional services that can use the CMK, not the ones who are using it by default when configured. When using customer managed keys on a storage account, the CMK are automatically enabled for BLOB and FILE. You can then optionaly configure Queues and Tables. "Data stored in Queue and Table storage isn't automatically protected by a customer-managed key when customer-managed keys are enabled for the storage account. You can optionally configure these services to be included in this protection at the time that you create the storage account." https://learn.microsoft.com/en-us/azure/storage/common/customer-managed-keys-overview#customer-managed-keys-for-queues-and-tables

LonDonMagic
Apr 19, 2023

It's impressive how confident you are in being wrong. It's BC.

NotAChatBot
Jun 29, 2023

The question is misleading. All services support data encryption with customer managed keys stored in a key vault.

[Removed]
Dec 21, 2023

Customer-managed key (CMK) support can be limited to blob service and file service only, or to all service types. After the storage account is created, this support cannot be changed. If the storage account is already created then you cannot selected all services

heatfan900
Aug 9, 2023

the question should reference MMK not CMK. MMK, by default, only has BLOBS and FILES selected but CMK will automatically select all files types

4f13ccaOptions: BC
Apr 16, 2025

"Data stored in Queue and Table storage isn't automatically protected by a customer-managed key when customer-managed keys are enabled for the storage account. You can optionally configure these services to be included in this protection at the time that you create the storage account." https://learn.microsoft.com/en-us/azure/storage/common/customer-managed-keys-overview Isn't automatically, logical solution BC