Jump into concepts and practice - no test required
or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Recall & Review
beginner
What is Azure Key Vault used for?
Azure Key Vault is a cloud service that securely stores and controls access to secrets like passwords, keys, and certificates.
Click to reveal answer
beginner
Name one important step when creating a Key Vault in Azure.
You must specify a unique name and select a resource group and region where the Key Vault will be created.
Click to reveal answer
intermediate
What is the purpose of access policies in Azure Key Vault?
Access policies define who can read or manage secrets, keys, and certificates stored in the Key Vault.
Click to reveal answer
beginner
True or False: Azure Key Vault automatically encrypts all stored data.
True. Azure Key Vault encrypts all stored secrets and keys using Microsoft-managed or customer-managed keys.
Click to reveal answer
beginner
What is a best practice when naming your Azure Key Vault?
Use a unique, descriptive name that follows Azure naming rules and helps identify the vault's purpose or environment.
Click to reveal answer
Which of the following is required when creating an Azure Key Vault?
AA unique vault name
BA virtual machine
CA database connection string
DA storage account
✗ Incorrect
A unique vault name is required to create an Azure Key Vault. Other options are unrelated.
What does an access policy in Azure Key Vault control?
AThe network speed
BWho can access and manage secrets
CThe billing account
DThe virtual machine size
✗ Incorrect
Access policies control who can access and manage secrets, keys, and certificates in the vault.
Where is Azure Key Vault data stored?
AIn a virtual machine
BOn your local computer
CIn the selected Azure region
DIn a SQL database
✗ Incorrect
Azure Key Vault data is stored securely in the Azure region you select during creation.
Which of these is NOT a secret type stored in Azure Key Vault?
APasswords
BEncryption keys
CCertificates
DVirtual machine images
✗ Incorrect
Virtual machine images are not stored in Key Vault; it stores secrets, keys, and certificates.
What is a recommended practice for securing access to your Key Vault?
AUse access policies with least privilege
BShare the vault password with everyone
CDisable all logging
DUse the same password for all users
✗ Incorrect
Using access policies with least privilege ensures only necessary users have access.
Explain the main steps to create an Azure Key Vault and secure it.
Think about naming, location, permissions, and security.
You got /4 concepts.
Describe why Azure Key Vault is important for managing secrets in cloud applications.
Focus on security and control benefits.
You got /4 concepts.
Practice
(1/5)
1. What is the primary purpose of an Azure Key Vault?
easy
A. To host virtual machines
B. To manage Azure subscriptions
C. To securely store secrets, keys, and certificates
D. To monitor network traffic
Solution
Step 1: Understand Azure Key Vault's role
Azure Key Vault is designed to securely store sensitive information like secrets, keys, and certificates.
Step 2: Compare with other Azure services
Hosting VMs, managing subscriptions, and monitoring traffic are done by other Azure services, not Key Vault.
Final Answer:
To securely store secrets, keys, and certificates -> Option C
Quick Check:
Key Vault = Secure storage for secrets [OK]
Hint: Key Vault is for secrets and keys storage only [OK]
Common Mistakes:
Confusing Key Vault with VM hosting
Thinking Key Vault manages subscriptions
Assuming Key Vault monitors network
2. Which Azure CLI command correctly creates a Key Vault named myVault in the resource group myResourceGroup located in eastus?
easy
A. az keyvault create --name myVault --resource-group myResourceGroup --location eastus
B. az keyvault new --vault-name myVault --group myResourceGroup --region eastus
C. az vault create --name myVault --resource-group myResourceGroup --location eastus
D. az keyvault create --vault myVault --resource myResourceGroup --location eastus
Solution
Step 1: Identify correct Azure CLI syntax
The correct command uses az keyvault create with parameters --name, --resource-group, and --location.
Step 2: Check each option's parameters
az keyvault create --name myVault --resource-group myResourceGroup --location eastus matches the correct syntax exactly. Options B, C, and D use incorrect commands or parameter names.
Final Answer:
az keyvault create --name myVault --resource-group myResourceGroup --location eastus -> Option A
What will be the state of soft delete on the created Key Vault?
medium
A. Soft delete will be enabled by default
B. Soft delete will be disabled as specified
C. Soft delete will be enabled only if the region supports it
D. Command will fail due to invalid parameter
Solution
Step 1: Check parameter validity
The parameter --enable-soft-delete is deprecated and cannot be set to false; soft delete is always enabled now.
Step 2: Understand command behavior
Setting --enable-soft-delete false causes the command to fail because disabling soft delete is not allowed.
Final Answer:
Command will fail due to invalid parameter -> Option D
Quick Check:
Soft delete cannot be disabled now = Command will fail due to invalid parameter [OK]
Hint: Soft delete is always enabled; disabling causes error [OK]
Common Mistakes:
Assuming soft delete can be turned off
Ignoring deprecation of --enable-soft-delete
Thinking soft delete depends on region
4. You run this command to create a Key Vault:
az keyvault create --name vault123 --resource-group group123 --location eastus
But you get an error: ResourceGroupNotFound. What is the most likely fix?
medium
A. Change the location to westus
B. Create the resource group group123 before creating the Key Vault
C. Use a different Key Vault name
D. Add --enable-soft-delete true to the command
Solution
Step 1: Understand the error
ResourceGroupNotFound means the specified resource group does not exist.
Step 2: Fix by creating the resource group
You must create the resource group group123 first using az group create before creating resources inside it.
Final Answer:
Create the resource group group123 before creating the Key Vault -> Option B
Quick Check:
Resource group must exist before Key Vault creation [OK]
Hint: Create resource group first to avoid ResourceGroupNotFound [OK]
Common Mistakes:
Trying to change location instead of creating group
Changing vault name without checking group
Adding unrelated parameters to fix error
5. You want to create an Azure Key Vault with these requirements: - Name: secureVault - Resource group: prodGroup - Location: centralus - Enable soft delete - Set access policy to allow user with object ID 1234abcd to get and list secrets
Which Azure CLI command sequence correctly achieves this?
hard
A. az keyvault create --name secureVault --resource-group prodGroup --location centralus && az keyvault set-policy --name secureVault --object-id 1234abcd --secret-permissions get list
B. az keyvault create --name secureVault --resource-group prodGroup --location centralus --enable-soft-delete true --access-policy object-id=1234abcd permissions=secrets:get,list
C. az keyvault create --name secureVault --resource-group prodGroup --location centralus --enable-soft-delete false && az keyvault set-policy --name secureVault --object-id 1234abcd --secret-permissions get list
D. az keyvault create --name secureVault --resource-group prodGroup --location centralus && az keyvault set-policy --name secureVault --object-id 1234abcd --secret-permissions get,list
Solution
Step 1: Create Key Vault with default soft delete enabled
Soft delete is enabled by default and cannot be disabled, so no need to specify it.
Step 2: Set access policy with correct syntax
Use az keyvault set-policy with --object-id and --secret-permissions get list to allow the user to get and list secrets.
Step 3: Verify command correctness
az keyvault create --name secureVault --resource-group prodGroup --location centralus && az keyvault set-policy --name secureVault --object-id 1234abcd --secret-permissions get list uses correct commands and parameters. az keyvault create --name secureVault --resource-group prodGroup --location centralus && az keyvault set-policy --name secureVault --object-id 1234abcd --secret-permissions get,list incorrectly uses comma between permissions. az keyvault create --name secureVault --resource-group prodGroup --location centralus --enable-soft-delete true --access-policy object-id=1234abcd permissions=secrets:get,list uses invalid parameters. az keyvault create --name secureVault --resource-group prodGroup --location centralus --enable-soft-delete false && az keyvault set-policy --name secureVault --object-id 1234abcd --secret-permissions get list tries to disable soft delete, which is invalid.
Final Answer:
az keyvault create --name secureVault --resource-group prodGroup --location centralus && az keyvault set-policy --name secureVault --object-id 1234abcd --secret-permissions get list -> Option A
Quick Check:
Create then set-policy with correct permissions = az keyvault create --name secureVault --resource-group prodGroup --location centralus && az keyvault set-policy --name secureVault --object-id 1234abcd --secret-permissions get list [OK]
Hint: Create vault first, then set access policy with correct permissions [OK]