CertKeen

Azure Solutions Architect Expert (AZ-305) · Free practice question 2 of 12

Key Vault key rotation policy

Burnside Logistics uses customer-managed keys in Azure Key Vault to encrypt several storage accounts. Compliance requires a new key version every 180 days and a notification 30 days before a key expires, with no manual steps. What should you recommend?

  1. A.Set a 180-day expiration date on each key and rely on Azure Advisor alerts
  2. B.Create an Azure Automation runbook that generates a new key every 180 days and updates each storage account
  3. C.Rotate the storage account access keys every 180 days
  4. D.Configure a key rotation policy on each key with automatic rotation and a near-expiry notification, and configure the storage accounts to use the latest key version automatically
Show answer and explanation

Correct answer: D. Configure a key rotation policy on each key with automatic rotation and a near-expiry notification, and configure the storage accounts to use the latest key version automatically

Why: A Key Vault rotation policy creates new key versions on a schedule and can raise a near-expiry event through Event Grid, and services such as Azure Storage can automatically pick up the latest version of a customer-managed key. A runbook is custom automation to maintain. Storage access keys are unrelated to encryption keys, and an expiration date alone does not create a new version.

More free Azure Solutions Architect Expert (AZ-305) questions