AZ-500 exam dumps

AZ-500 practice question 164 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 164

Select 2

Your organization wants to migrate a cryptographic key generated in its on-premises HSM into an Azure Key Vault for use with BYOK (Bring Your Own Key). You have already provisioned an HSM-protected Key Vault and downloaded the Azure Key Vault BYOK tool. Which two actions must you take to correctly import and manage your on-premises key using BYOK?

  1. A

    Wrap the on-premises key with the RSA public key provided by Azure Key Vault using the BYOK tool before importing.

  2. B

    Enable purge protection on the Key Vault to prevent accidental irreversible deletions.

  3. C

    Import the raw, unprotected key directly from the Azure portal without wrapping it.

  4. D

    Grant appropriate Key Vault access policies (e.g., Import, Get, List) to allow BYOK operations.

Show answer and explanation

Correct answers: A, D

Explanation

When bringing your own key to Azure Key Vault, you must generate or hold the key in an on-premises HSM. Then you use the Azure Key Vault BYOK tool (or equivalent Azure CLI/PowerShell utilities) to wrap the key with Key Vault’s KEK before importing it. Appropriate Key Vault permissions must be assigned so that the import can be performed. While enabling purge protection is best practice to prevent irreversible deletions, it is not mandatory for the BYOK import. More details can be found in Microsoft’s official BYOK documentation: https://docs.microsoft.com/azure/key-vault/keys/byok.

  • A. Correct.

    This option is correct. Azure Key Vault requires that the on-premises key be wrapped (i.e., encrypted) with the Key Exchange Key (KEK) from the Key Vault before import. The BYOK tool handles the wrap/unwrap process so that the private key never leaves the HSM environment unprotected.

  • B. Incorrect.

    Although highly recommended, enabling purge protection is not a strict requirement for the BYOK import process. Purge protection ensures that keys cannot be permanently deleted from the Key Vault during the retention period. This is a best practice for secure key management but not an essential step to import a BYOK key.

  • C. Incorrect.

    This option is incorrect. You cannot directly import the raw, unprotected key through the Azure portal. The on-premises key must be wrapped using the Key Vault’s public key (via the BYOK tool) before being imported, ensuring the key material remains protected end-to-end.

  • D. Correct.

    This option is correct. You must configure relevant access policies to allow actions like 'Get', 'Import', and 'List' in the Key Vault for the principal performing the BYOK import. Without appropriate permissions, the BYOK process cannot be completed.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam