exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 1 question 22 discussion

Actual exam question from Microsoft's AZ-500
Question #: 22
Topic #: 1
[All AZ-500 Questions]

You have been tasked with delegate administrative access to your company's Azure key vault.
You have to make sure that a specific user can set advanced access policies for the key vault. You also have to make sure that access is assigned based on the principle of least privilege.
Which of the following options should you use to achieve your goal?

  • A. Azure Information Protection B. RBAC
  • C. Azure AD Privileged Identity Management (PIM)
  • D. Azure DevOps
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️
Reference:
https://docs.microsoft.com/en-us/azure/key-vault/key-vault-secure-your-key-vault

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
wallythebos
Highly Voted 3 years, 7 months ago
For those that won't see it B is right in front of the option A.
upvoted 55 times
cfsxtuv33
3 years, 4 months ago
Ahh, thats funny, I kept seeing contributors saying B sits in front of A. i was like what the heck are they talking about!? Then I saw it....sitting in the same row as "A." So yeah, option "B" RBAC is correct.
upvoted 4 times
...
...
somenick
Highly Voted 2 years, 7 months ago
Admins please fix formatting so the option B is on the new line
upvoted 16 times
...
stonwall12
Most Recent 2 months, 2 weeks ago
Selected Answer: C
Answer: It's cooked, the answer is B, RBAC Reason: Role-Based Access Control (RBAC) in Azure allows you to assign specific permissions to users based on their roles, adhering to the principle of least privilege. For managing advanced access policies in Azure Key Vault, the 'Key Vault Contributor' role provides the necessary permissions without granting excessive access. Reference: https://learn.microsoft.com/en-us/azure/key-vault/general/rbac-guide
upvoted 1 times
...
AdityaGupta
3 months, 1 week ago
Selected Answer: A
It can be either RBAC or Access Policies. We have option B as RBAC.
upvoted 2 times
...
xRiot007
9 months, 2 weeks ago
You can't use PIM (C) for this scenario so go for RBAC (B). In a real life scenario, the user would have a ticket on a backlog that he is required to complete after setting up. Then you de-assign the role from his identity, to respect the least privilege principle, unless the user is explicitly required permanent access from then onwards.
upvoted 1 times
...
Mazhar1993
1 year ago
The correct answer is RBAC. RBAC allows you to assign specific roles like Key Vault Contributor, which grants the user the ability to set advanced access policies, ensuring access based on the principle of least privilege. Azure Information Protection focuses on data classification, labeling, and protection, not managing access to Azure Key Vault. While Azure AD Privileged Identity Management offers time-based and approval-based role activation, it doesn't directly manage access to Azure Key Vault or allow setting advanced access policies for it. Azure DevOps is primarily a set of services for software development, not for managing access to Azure Key Vault. https://learn.microsoft.com/en-us/azure/key-vault/general/security-features
upvoted 3 times
...
Andre369
1 year, 11 months ago
B. RBAC (Role-Based Access Control) RBAC allows you to grant specific permissions to users, groups, or service principals based on their roles. By assigning the appropriate RBAC role to the specific user, you can grant them the necessary permissions to set advanced access policies for the Key Vault, while ensuring that they only have the minimum privileges required for their tasks. RBAC provides a granular level of control over access to Azure resources, allowing you to assign roles such as "Key Vault Contributor" or "Key Vault Administrator" to the user, depending on the level of access needed. This ensures that the user has the necessary permissions to manage the Key Vault without granting excessive privileges.
upvoted 4 times
...
FedericoBellotti
1 year, 11 months ago
the b is not visible
upvoted 1 times
...
zellck
1 year, 11 months ago
B is the answer. https://learn.microsoft.com/en-us/azure/key-vault/general/rbac-migration Azure role-based access control (Azure RBAC) is an authorization system built on Azure Resource Manager that provides fine-grained access management of Azure resources. With Azure RBAC you control access to resources by creating role assignments, which consist of three elements: a security principal, a role definition (predefined set of permissions), and a scope (group of resources or individual resource).
upvoted 2 times
...
Dinya_jui
2 years, 1 month ago
correct answer B
upvoted 1 times
...
majstor86
2 years, 1 month ago
B. RBAC
upvoted 2 times
...
brutananadilewski0000
2 years, 2 months ago
Just to notify you that the answer B is RBAC
upvoted 1 times
...
AZ5cert
2 years, 4 months ago
B: RBAC
upvoted 1 times
...
Irishtk
3 years ago
Ans is B (RBAC) "Authorization in Key Vault uses a combination of Azure role-based access control (Azure RBAC) and Azure Key Vault access policies" https://docs.microsoft.com/en-us/azure/key-vault/general/security-features
upvoted 6 times
...
TheLegendPasha
3 years ago
The answer is B but for some reason is BUGGED.
upvoted 2 times
...
in_da_cloud
3 years ago
The answer is B: The management plane uses RBAC - this is where you manage Key Vault itself which implies creating and deleting key vaults, retrieving Key Vault properties, and updating access policies. https://docs.microsoft.com/en-us/azure/key-vault/general/security-features#access-model-overview
upvoted 2 times
...
Eltooth
3 years, 1 month ago
B is correct answer.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago