AZ-500 exam dumps

AZ-500 practice question 193 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 193

Select 2

You are configuring network access for an Azure Key Vault that stores highly sensitive secrets. Your requirement is that only resources within a private subnet in your Azure Virtual Network (VNet) and a set of specific on-premises IP addresses can access the vault. Which two actions should you perform to meet these requirements?

  1. A

    A. Enable the Key Vault firewall and select 'Allow access from: Selected networks', then add the VNet subnet and on-premises IP addresses to the firewall configuration.

  2. B

    B. Set the Key Vault network rule to 'Disable all networks' and enable 'Allow trusted Microsoft services to bypass' to permit your VNet traffic.

  3. C

    C. Create a new private endpoint in the Key Vault settings, associate it with your VNet subnet, and configure firewall rules for on-premises IP addresses.

  4. D

    D. Turn off public network access in the Key Vault and rely on Role-Based Access Control (RBAC) alone to restrict unauthorized traffic.

Show answer and explanation

Correct answers: A, C

Explanation

To allow access from a specific Azure VNet subnet and on-premises IP addresses, you must configure the Key Vault firewall to accept traffic from those subnets and IP ranges (option A). In addition, creating a private endpoint (option C) securely maps the Key Vault to your VNet, eliminating public exposure. Refer to Microsoft documentation at https://learn.microsoft.com/azure/key-vault/general/network-security for more details on configuring firewall rules and private endpoints for Azure Key Vault.

  • A. Correct.

    A. Correct. Enabling the firewall with 'Allow access from: Selected networks' and explicitly listing your VNet subnet and on-premises IP addresses ensures that only approved sources can reach the Key Vault.

  • B. Incorrect.

    B. Incorrect. 'Disable all networks' blocks all traffic, including from your VNet, and 'Allow trusted Microsoft services to bypass' does not allow your VNet traffic by default. This setting won’t meet your scenario requirements.

  • C. Correct.

    C. Correct. A private endpoint creates a secure, dedicated connection to your VNet. Along with configuring the firewall rules for on-premises IP addresses, this ensures restricted access both from your Azure subnet and your on-prem environment.

  • D. Incorrect.

    D. Incorrect. Disabling public network access alone does not configure the vault to accept traffic from on-premises IP addresses, and RBAC controls permissions but does not control network-level connectivity.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam