AZ-500 exam dumps

AZ-500 practice question 194 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 194

Select 2

You are an Azure Security Engineer for a company that stores secrets in an Azure Key Vault. The company wants to restrict vault access to only an Azure App Service (deployed in the same subscription) and to DevOps engineers connecting from a known on-premises IP range. You have already set the Key Vault firewall to 'Allow access from selected networks' only. Which two actions must you take next to meet these requirements?

  1. A

    Create a private endpoint for the Key Vault in the same virtual network as the Azure App Service.

  2. B

    Enable the 'Allow trusted Microsoft services to bypass this firewall' setting to give the Azure App Service direct access to the Key Vault.

  3. C

    Add the on-premises IP address range to the Key Vault firewall settings.

  4. D

    Change the Key Vault firewall to 'Allow access from all networks' to support communications from on-premises and Azure App Service.

Show answer and explanation

Correct answers: A, C

Explanation

When a Key Vault is configured to allow access from selected networks only, you must specify exactly which networks or IP address ranges can connect. Azure App Service is not included in the trusted service exceptions, so relying on 'Allow trusted Microsoft services to bypass this firewall' will not work for Azure App Service. Instead, establishing a private endpoint in the same virtual network and adding the on-premises IP range ensures that both the hosted application and DevOps engineers can securely connect. Refer to Microsoft's documentation on 'Azure Key Vault firewalls and virtual networks' for detailed guidance on network restrictions and private endpoints.

  • A. Correct.

    Correct. Creating a private endpoint in the same virtual network as the Azure App Service ensures traffic flows securely within Azure and does not require public internet access. This meets the 'selected networks' firewall requirement.

  • B. Incorrect.

    Incorrect. ‘Allow trusted Microsoft services to bypass this firewall’ does not grant access to Azure App Service, because Azure App Service is not part of the trusted services list for Key Vault. This is a common misconception.

  • C. Correct.

    Correct. You need to add the on-premises IP address range so that requests originating from that range are allowed to connect. This is essential for DevOps engineers to access Key Vault from on-premises.

  • D. Incorrect.

    Incorrect. Changing the firewall to 'Allow access from all networks' would override your restricted access requirement and grant everyone access, which violates the security policy.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam