AZ-500 exam dumps

AZ-500 practice question 200 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 200

Single answer

Your organization hosts a public e-commerce website in Azure. The website’s SSL certificate, issued by a supported Certificate Authority (CA), is stored in Azure Key Vault. The security team wants to ensure the certificate will be automatically renewed before it expires. Which step must you take to achieve this?

  1. A

    Enable auto-rotation for the certificate within the Key Vault access policy settings

  2. B

    Configure a Key Vault certificate policy with the correct issuer and auto-renew parameters

  3. C

    Create a custom script that checks the Key Vault certificate and manually re-imports it once it is close to expiration

  4. D

    Assign the website’s managed identity the 'Key Vault Contributor' role to regenerate certificates automatically

Show answer and explanation

Correct answer: B

Explanation

To automatically renew a certificate in Azure Key Vault, you must configure a certificate policy with a supported issuer (such as a public CA configured in the Key Vault) and define the renewal settings. This enables Key Vault to request, receive, and store an updated certificate before the current one expires. For detailed guidance, refer to the official Azure documentation on managing certificates in Key Vault: https://learn.microsoft.com/azure/key-vault/certificates/about-certificates.

  • A. Incorrect.

    Option 1 is incorrect because there is no dedicated 'auto-rotation' setting in the Key Vault access policy. Access policies grant permissions but do not configure automatic certificate renewal.

  • B. Correct.

    Option 2 is correct because Key Vault supports auto-renewal when you configure a certificate policy with a supported issuer and the appropriate renewal parameters. The policy instructs Key Vault to request a new certificate before the current one expires.

  • C. Incorrect.

    Option 3 is incorrect because relying on a custom script is a manual approach, not a built-in automated process. While it might work, it does not leverage Key Vault’s native auto-renewal capabilities.

  • D. Incorrect.

    Option 4 is incorrect because assigning 'Key Vault Contributor' to a managed identity alone does not trigger auto-renewal. You still need to configure a certificate policy with the correct issuer and renewal settings.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam