Azure Solutions Architect Expert (AZ-305) · Free practice question 2 of 12
Key Vault key rotation policy
Burnside Logistics uses customer-managed keys in Azure Key Vault to encrypt several storage accounts. Compliance requires a new key version every 180 days and a notification 30 days before a key expires, with no manual steps. What should you recommend?
- A.Set a 180-day expiration date on each key and rely on Azure Advisor alerts
- B.Create an Azure Automation runbook that generates a new key every 180 days and updates each storage account
- C.Rotate the storage account access keys every 180 days
- D.Configure a key rotation policy on each key with automatic rotation and a near-expiry notification, and configure the storage accounts to use the latest key version automatically
Show answer and explanation
Correct answer: D. Configure a key rotation policy on each key with automatic rotation and a near-expiry notification, and configure the storage accounts to use the latest key version automatically
Why: A Key Vault rotation policy creates new key versions on a schedule and can raise a near-expiry event through Event Grid, and services such as Azure Storage can automatically pick up the latest version of a customer-managed key. A runbook is custom automation to maintain. Storage access keys are unrelated to encryption keys, and an expiration date alone does not create a new version.
More free Azure Solutions Architect Expert (AZ-305) questions
- Pass-through authentication for on-premises policy
- Queue Storage for large simple backlogs
- API Management multi-region deployment
- Dedicated Host for physical isolation
- Private Link service for SaaS providers
- Event Hubs Kafka endpoint
- Template specs for versioned templates
- Cosmos DB for Apache Cassandra
- Resource Graph for cross-subscription inventory
- Azure Data Explorer for telemetry analytics
- Performance-based sizing in Azure Migrate