AZ-500 exam dumps

AZ-500 practice question 197 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 197

Select 2

You manage an Azure Key Vault that stores secrets for a critical application. A developer on your team needs read-only access to view these secrets to troubleshoot an issue, but must not be able to update secrets or manage access policies (e.g., configuring who can access keys and secrets). Which two approaches would satisfy this requirement?

  1. A

    Assign the developer the Key Vault Contributor role at the Key Vault scope

  2. B

    Configure a Key Vault Access Policy that grants only 'Get' and 'List' permissions for secrets

  3. C

    Assign the developer the built-in Key Vault Secrets User role via Azure RBAC at the Key Vault scope

  4. D

    Grant the developer the Key Vault Administrator role at the subscription scope

Show answer and explanation

Correct answers: B, C

Explanation

In Azure Key Vault, there are two main ways to manage permissions: vault access policies and Azure RBAC. A vault access policy can be configured to restrict a user's rights to only read secrets (e.g., 'Get' and 'List'). Alternatively, using Azure RBAC roles, the 'Key Vault Secrets User' built-in role limits a user’s capabilities strictly to reading secrets, without broader management permissions. Both approaches ensure the developer can read secrets but not modify them or update who has access. For more details, see Microsoft Docs: https://learn.microsoft.com/azure/key-vault/general/overview-security and https://learn.microsoft.com/azure/key-vault/general/rbac-guide.

  • A. Incorrect.

    Option 1 is incorrect. The Key Vault Contributor role allows managing vault properties and secrets, including updating access policies. This exceeds the read-only requirement.

  • B. Correct.

    Option 2 is correct. Using a dedicated Key Vault access policy that grants the developer 'Get' and 'List' permissions for secrets provides read-only access without letting them manage vault settings or policies.

  • C. Correct.

    Option 3 is correct. The built-in Key Vault Secrets User role in Azure RBAC also grants read access to secrets without allowing the user to manage vault settings or permissions. This role meets the requirement of read-only access for secrets.

  • D. Incorrect.

    Option 4 is incorrect. The Key Vault Administrator role at the subscription scope provides full access to manage Key Vaults and secrets, far beyond the read-only requirement.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam