This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Answer the following questions to check your understanding of configuring and securing Azure Key Vault.
Your organization's compliance policy requires that Key Vault objects can't be permanently deleted during a 90-day retention window—even by subscription owners. Which Key Vault setting enforces retention?
Soft delete
Purge protection
Azure Policy enforcement
Resource lock
Contoso's application needs to retrieve secrets from Azure Key Vault without storing credentials in code or configuration files. What is the recommended approach?
Assign the Key Vault Secrets User role to a managed identity
Configure a vault access policy for a service principal with a client secret
Add the application's IP address to the Key Vault firewall allow list
Assign the Key Vault Administrator role to the application's managed identity
A security engineer needs application servers in an Azure virtual network to access Key Vault with no public internet exposure. Which solution meets the requirement?
Configure a private endpoint for Key Vault
Configure a virtual network service endpoint for Key Vault
Enable the trusted Azure services bypass in the Key Vault firewall
Configure a resource lock on the Key Vault
You must answer all questions before checking your work.
Was this page helpful?
Need help with this topic?
Want to try using Ask Learn to clarify or guide you through this topic?