AZ-500 · Question #359
Case Study 3 - Fabrikam, Inc General Overview Fabrikam, Inc. is a consulting company that has a main office in Montreal and branch offices in Seattle and New York. Fabrikam has IT, human resources…
The correct answer is B. KeyVault1 only. Explanation Why B is Correct: Storage1 is located in the West US Azure region, and customer-managed key encryption requires that the Key Vault used must be in the same region as the storage account. Based on the case study table, only KeyVault1 resides in the West US region…
Question
Options
- AKeyVault2 and KeyVault3 only
- BKeyVault1 only
- CKeyVault1 and KeyVault3 only
- DKeyVault1, KeyVault2, and KeyVault3
How the community answered
(30 responses)- A10% (3)
- B73% (22)
- C3% (1)
- D13% (4)
Explanation
Explanation
Why B is Correct: Storage1 is located in the West US Azure region, and customer-managed key encryption requires that the Key Vault used must be in the same region as the storage account. Based on the case study table, only KeyVault1 resides in the West US region, making it the only eligible vault to encrypt Storage1.
Why the Distractors are Wrong:
- A (KeyVault2 and KeyVault3 only): Neither KeyVault2 nor KeyVault3 are in the West US region, so neither can be used alone or together to encrypt Storage1.
- C (KeyVault1 and KeyVault3 only): KeyVault3 is not in the West US region, so it cannot be paired or used for this purpose; only KeyVault1 qualifies.
- D (All three vaults): Including KeyVault2 and KeyVault3 is incorrect because region mismatch disqualifies them from being used for customer-managed key encryption of Storage1.
Memory Tip: Think "Same Region, Same Key Vault" - for customer-managed key encryption in Azure Storage, the Key Vault and the storage account must always reside in the same Azure region. If regions don't match, the option is automatically eliminated. This is a common exam trap!
Topics
Community Discussion
No community discussion yet for this question.