AZ-500 exam dumps

AZ-500 practice question 196 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 196

Select 2

You manage an Azure Key Vault used by multiple development teams. The vault is configured to use Azure role-based access control (RBAC) instead of the classic vault access policies. A new application named 'ContosoWebApp' has a system-assigned managed identity in Azure AD, and security requirements specify that only this application can retrieve secrets from the Key Vault. Additionally, a security group of administrators needs to manage secrets without granting read access to the application’s secrets. Which two steps should you take to fulfill these requirements?

  1. A
    1. Under ‘Access policies’ in the Key Vault, grant the ContosoWebApp identity secret get and list permissions directly.
  2. B
    1. At the Key Vault resource level, assign the 'Key Vault Secrets User' role to the ContosoWebApp’s managed identity.
  3. C
    1. Assign the 'Key Vault Contributor' role at the Key Vault resource scope to the administrator security group.
  4. D
    1. Enable 'Allow trusted Microsoft services to bypass firewall' under the Key Vault Networking settings.
Show answer and explanation

Correct answers: B, C

Explanation

When Key Vault is configured for Azure RBAC, you manage access through Azure role assignments instead of classic Key Vault access policies. In this scenario, you must create separate role assignments to meet distinct access requirements: the ContosoWebApp identity needs to retrieve secrets (Key Vault Secrets User), and administrators need to manage secrets (Key Vault Contributor). For more details, see Microsoft's documentation: https://learn.microsoft.com/azure/key-vault/general/rbac-guide.

  • A. Incorrect.

    Option 1: Incorrect. While you can configure Access Policies, the scenario explicitly states that Azure RBAC is used instead of the classic vault access policies. Granting permissions under ‘Access policies’ is a separate model and does not align with the chosen RBAC approach.

  • B. Correct.

    Option 2: Correct. When using Azure RBAC, you should assign an appropriate role at the scope of the Key Vault resource for the ContosoWebApp’s managed identity. 'Key Vault Secrets User' grants read access to secrets without allowing modifications, matching the requirement that only this application can retrieve secrets.

  • C. Correct.

    Option 3: Correct. Administrators need the ability to manage (create, delete, update) secrets. Assigning them the 'Key Vault Contributor' role at the Key Vault resource level enables this capability without automatically granting read access to the application’s secrets.

  • D. Incorrect.

    Option 4: Incorrect. Enabling 'Allow trusted Microsoft services to bypass firewall' is useful for certain services or functionalities, but it does not control identity-based access to secrets. It also does not fulfill the requirement for restricting access via RBAC.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam