AZ-500 · Question #408
You have an Azure subscription that contains an Azure key vault. You need to configure the maximum number of days for which new keys are valid. The solution must minimize administrative effort. What…
The correct answer is B. Azure Policy. You want to improve the security posture of your company by implementing requirements around minimum key sizes and maximum validity periods of certificates in your company's key vaults but you don't know which teams will be compliant and which are not. Manage certificates that…
Question
Options
- AKey Vault properties
- BAzure Policy
- CAzure Purview
- DAzure Blueprints
How the community answered
(47 responses)- A6% (3)
- B83% (39)
- C2% (1)
- D9% (4)
Explanation
You want to improve the security posture of your company by implementing requirements around minimum key sizes and maximum validity periods of certificates in your company's key vaults but you don't know which teams will be compliant and which are not. Manage certificates that are within a specified number of days of expiration. Your service can experience an outage if a certificate that is not being adequately monitored is not rotated prior to its expiration. This policy is critical to making sure that your certificates stored in key vault are being monitored. It is recommended that you apply this policy multiple times with different expiration thresholds, for example, at 180, 90, 60, and 30-day thresholds. This policy can be used to monitor and triage certificate expiration in your organization. https://learn.microsoft.com/en-us/azure/key-vault/general/azure-policy?tabs=certificates
Community Discussion
No community discussion yet for this question.