Skip to Content

AZ-500: Securing Storage1: Encrypting with Customer-Managed Keys in Azure

Learn how to meet technical requirements by encrypting Storage1 with customer-managed keys in Azure. Explore the key vault solution for a secure storage environment.


This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.

To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.

At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.

To start the case study
To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.

General Overview
Fabrikam, Inc. is a consulting company that has a main office in Montreal and branch offices in Seattle and New York. Fabrikam has IT, human resources (HR), and finance departments.

Existing Environment

Network Environment

  • Fabrikam has a Microsoft 365 subscription and an Azure subscription named subscription1.
  • The network contains an on-premises Active Directory domain named The domain contains two organizational units (OUs) named OU1 and OU2.
  • Azure AD Connect cloud sync syncs only OU1.

The Azure resources hierarchy is shown in the following exhibit.

The Azure resources hierarchy is shown in the following exhibit.

The Azure Active Directory (Azure AD) tenant contains the users shown in the following table.

Name Type Directory-synced Role Delegated to
User1 User Yes User None
Admin1 User No User Access Administrator Tenant Root Group
Admin2 User No Security administrator MG1
Admin3 User No Contributor Subscription1
Admin4 User No Owner RG1
Group1 Group No Not applicable None

Azure AD contains the resources shown in the following table.

Name Type Setting
CAPolicy1 Conditional access policy Users in the finance department must use multi-factor authentication (MFA) when accessing Microsoft SharePoint Online.
Sentinel1 Azure Sentinel workspace Not applicable.
SecPol1 Azure Policy definition Security configuration for virtual machines.

Subscription1 Resources

Subscription1 contains the virtual networks shown in the following table.

Name Subnet Location Peer
VNET1 Subnet1, Subnet2 West US VNET2, VNET3
VNET2 Subnet1 Central US VNET1, VNET3
VNET3 Subnet1 West US VNET1, VNET2

Subscription1 contains the network security groups (NSGs) shown in the following table.

Name Location
NSG2 West US
NSG3 Central US
NSG4 West US

Subscription1 contains the virtual machines shown in the following table.

Name Operating system Location Connected to Associated NSG
VM1 Windows Server 2019 West US VNET1/Subnet1 None
VM2 CentOS-based 8.2 West US VNET1/Subnet2 NSG2
VM3 Windows Server 2016 Central US VNET2/Subnet1 NSG3
VM4 Ubuntu Server 18.04 LTS West US VNET3/Subnet1 NSG4

Subscription1 contains the Azure key vaults shown in the following table.

Name Location Pricing tier Private endpoint
KeyVault1 West US Standard VNET1/Subnet1
KeyVault2 Central US Premium None
KeyVault3 East US Premium VNET1/Subnet1,

Subscription1 contains a storage account named storage1 in the West US Azure region.

Planned Changes and Requirements

Planned Changes
Fabrikam plans to implement the following changes:

Create two application security groups as shown in the following table.

Name Location
ASG1 West US
ASG2 Central US
  • Associate the network interface of VM1 to ASG1.
  • Deploy SecPol1 by using Azure Security Center.
  • Deploy a third-party app named App1. A version of App1 exists for all available operating systems.
  • Create a resource group named RG2.
  • Sync OU2 to Azure AD.
  • Add User1 to Group1.

Technical Requirements
Fabrikam identifies the following technical requirements:

  • The finance department users must reauthenticate after three hours when they access SharePoint Online.
  • Storage1 must be encrypted by using customer-managed keys and automatic key rotation.

From Sentinel1, you must ensure that the following notebooks can be launched:

  • Entity Explorer – Account
  • Entity Explorer – Windows Host
  • Guided Investigation Process Alerts

VM1, VM2, and VM3 must be encrypted by using Azure Disk Encryption.

Just in time (JIT) VM access for VM1, VM2, and VM3 must be enabled.

App1 must use a secure connection string stored in KeyVault1.

KeyVault1 traffic must NOT travel over the internet.

You need to encrypt storage1 to meet the technical requirements.
Which key vaults can you use?

A. KeyVault2 and KeyVault3 only
B. KeyVault1 only
C. KeyVault1 and KeyVault3 only
D. KeyVault1, KeyVault2, and KeyVault3


B. KeyVault1 only


The storage account and the key vault must be in the same region and in the same Azure Active Directory (Azure AD) tenant, but they can be in different subscriptions.
Storage1 is in the West US region. KeyVault1 is the only key vault in the same region.


The latest Microsoft AZ-500 Azure Security Technologies certification actual real practice exam question and answer (Q&A) dumps are available free, which are helpful for you to pass the Microsoft AZ-500 Azure Security Technologies exam and earn Microsoft AZ-500 Azure Security Technologies certification.

AZ-500 Microsoft Azure Security Technologies Exam Questions and Answers

Alex Lim is a certified IT Technical Support Architect with over 15 years of experience in designing, implementing, and troubleshooting complex IT systems and networks. He has worked for leading IT companies, such as Microsoft, IBM, and Cisco, providing technical support and solutions to clients across various industries and sectors. Alex has a bachelor’s degree in computer science from the National University of Singapore and a master’s degree in information security from the Massachusetts Institute of Technology. He is also the author of several best-selling books on IT technical support, such as The IT Technical Support Handbook and Troubleshooting IT Systems and Networks. Alex lives in Bandar, Johore, Malaysia with his wife and two chilrdren. You can reach him at [email protected] or follow him on Website | Twitter | Facebook

    Ads Blocker Image Powered by Code Help Pro

    Your Support Matters...

    We run an independent site that is committed to delivering valuable content, but it comes with its challenges. Many of our readers use ad blockers, causing our advertising revenue to decline. Unlike some websites, we have not implemented paywalls to restrict access. Your support can make a significant difference. If you find this website useful and choose to support us, it would greatly secure our future. We appreciate your help. If you are currently using an ad blocker, please consider disabling it for our site. Thank you for your understanding and support.