Jump into concepts and practice - no test required
or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Key Vault creation
📖 Scenario: You are setting up a secure place in Azure to store secrets like passwords and keys. This secure place is called a Key Vault. It helps keep your important information safe and easy to manage.
🎯 Goal: Create an Azure Key Vault resource with basic settings using an ARM template. You will define the resource, set its name, location, and access policies step-by-step.
📋 What You'll Learn
Create a resource group variable
Define the Key Vault resource with name and location
Add an access policy with a specific object ID
Complete the ARM template with all required properties
💡 Why This Matters
🌍 Real World
Azure Key Vault is used to securely store and manage sensitive information like keys, secrets, and certificates in cloud applications.
💼 Career
Knowing how to create and configure Key Vaults is essential for cloud engineers and security specialists working with Azure infrastructure.
Progress0 / 4 steps
1
Create a variable for the resource group name
Create a variable called resourceGroupName and set it to "MyResourceGroup".
Azure
Hint
Use var to declare the variable and assign the exact string.
2
Define the Key Vault resource with name and location
Create a variable called keyVault and assign an object with type set to "Microsoft.KeyVault/vaults", name set to "MyKeyVault", and location set to "eastus".
Azure
Hint
Define an object with the exact keys and values as shown.
3
Add an access policy with a specific object ID
Add a property properties to keyVault with an accessPolicies array containing one object with objectId set to "12345678-1234-1234-1234-123456789abc".
Azure
Hint
Remember to nest the accessPolicies array inside properties.
4
Complete the ARM template with all required properties
Add apiVersion set to "2019-09-01" and sku with family set to "A" and name set to "standard" inside keyVault.
Azure
Hint
Include apiVersion and sku properties at the top level of the keyVault object.
Practice
(1/5)
1. What is the primary purpose of an Azure Key Vault?
easy
A. To host virtual machines
B. To manage Azure subscriptions
C. To securely store secrets, keys, and certificates
D. To monitor network traffic
Solution
Step 1: Understand Azure Key Vault's role
Azure Key Vault is designed to securely store sensitive information like secrets, keys, and certificates.
Step 2: Compare with other Azure services
Hosting VMs, managing subscriptions, and monitoring traffic are done by other Azure services, not Key Vault.
Final Answer:
To securely store secrets, keys, and certificates -> Option C
Quick Check:
Key Vault = Secure storage for secrets [OK]
Hint: Key Vault is for secrets and keys storage only [OK]
Common Mistakes:
Confusing Key Vault with VM hosting
Thinking Key Vault manages subscriptions
Assuming Key Vault monitors network
2. Which Azure CLI command correctly creates a Key Vault named myVault in the resource group myResourceGroup located in eastus?
easy
A. az keyvault create --name myVault --resource-group myResourceGroup --location eastus
B. az keyvault new --vault-name myVault --group myResourceGroup --region eastus
C. az vault create --name myVault --resource-group myResourceGroup --location eastus
D. az keyvault create --vault myVault --resource myResourceGroup --location eastus
Solution
Step 1: Identify correct Azure CLI syntax
The correct command uses az keyvault create with parameters --name, --resource-group, and --location.
Step 2: Check each option's parameters
az keyvault create --name myVault --resource-group myResourceGroup --location eastus matches the correct syntax exactly. Options B, C, and D use incorrect commands or parameter names.
Final Answer:
az keyvault create --name myVault --resource-group myResourceGroup --location eastus -> Option A
What will be the state of soft delete on the created Key Vault?
medium
A. Soft delete will be enabled by default
B. Soft delete will be disabled as specified
C. Soft delete will be enabled only if the region supports it
D. Command will fail due to invalid parameter
Solution
Step 1: Check parameter validity
The parameter --enable-soft-delete is deprecated and cannot be set to false; soft delete is always enabled now.
Step 2: Understand command behavior
Setting --enable-soft-delete false causes the command to fail because disabling soft delete is not allowed.
Final Answer:
Command will fail due to invalid parameter -> Option D
Quick Check:
Soft delete cannot be disabled now = Command will fail due to invalid parameter [OK]
Hint: Soft delete is always enabled; disabling causes error [OK]
Common Mistakes:
Assuming soft delete can be turned off
Ignoring deprecation of --enable-soft-delete
Thinking soft delete depends on region
4. You run this command to create a Key Vault:
az keyvault create --name vault123 --resource-group group123 --location eastus
But you get an error: ResourceGroupNotFound. What is the most likely fix?
medium
A. Change the location to westus
B. Create the resource group group123 before creating the Key Vault
C. Use a different Key Vault name
D. Add --enable-soft-delete true to the command
Solution
Step 1: Understand the error
ResourceGroupNotFound means the specified resource group does not exist.
Step 2: Fix by creating the resource group
You must create the resource group group123 first using az group create before creating resources inside it.
Final Answer:
Create the resource group group123 before creating the Key Vault -> Option B
Quick Check:
Resource group must exist before Key Vault creation [OK]
Hint: Create resource group first to avoid ResourceGroupNotFound [OK]
Common Mistakes:
Trying to change location instead of creating group
Changing vault name without checking group
Adding unrelated parameters to fix error
5. You want to create an Azure Key Vault with these requirements: - Name: secureVault - Resource group: prodGroup - Location: centralus - Enable soft delete - Set access policy to allow user with object ID 1234abcd to get and list secrets
Which Azure CLI command sequence correctly achieves this?
hard
A. az keyvault create --name secureVault --resource-group prodGroup --location centralus && az keyvault set-policy --name secureVault --object-id 1234abcd --secret-permissions get list
B. az keyvault create --name secureVault --resource-group prodGroup --location centralus --enable-soft-delete true --access-policy object-id=1234abcd permissions=secrets:get,list
C. az keyvault create --name secureVault --resource-group prodGroup --location centralus --enable-soft-delete false && az keyvault set-policy --name secureVault --object-id 1234abcd --secret-permissions get list
D. az keyvault create --name secureVault --resource-group prodGroup --location centralus && az keyvault set-policy --name secureVault --object-id 1234abcd --secret-permissions get,list
Solution
Step 1: Create Key Vault with default soft delete enabled
Soft delete is enabled by default and cannot be disabled, so no need to specify it.
Step 2: Set access policy with correct syntax
Use az keyvault set-policy with --object-id and --secret-permissions get list to allow the user to get and list secrets.
Step 3: Verify command correctness
az keyvault create --name secureVault --resource-group prodGroup --location centralus && az keyvault set-policy --name secureVault --object-id 1234abcd --secret-permissions get list uses correct commands and parameters. az keyvault create --name secureVault --resource-group prodGroup --location centralus && az keyvault set-policy --name secureVault --object-id 1234abcd --secret-permissions get,list incorrectly uses comma between permissions. az keyvault create --name secureVault --resource-group prodGroup --location centralus --enable-soft-delete true --access-policy object-id=1234abcd permissions=secrets:get,list uses invalid parameters. az keyvault create --name secureVault --resource-group prodGroup --location centralus --enable-soft-delete false && az keyvault set-policy --name secureVault --object-id 1234abcd --secret-permissions get list tries to disable soft delete, which is invalid.
Final Answer:
az keyvault create --name secureVault --resource-group prodGroup --location centralus && az keyvault set-policy --name secureVault --object-id 1234abcd --secret-permissions get list -> Option A
Quick Check:
Create then set-policy with correct permissions = az keyvault create --name secureVault --resource-group prodGroup --location centralus && az keyvault set-policy --name secureVault --object-id 1234abcd --secret-permissions get list [OK]
Hint: Create vault first, then set access policy with correct permissions [OK]