nerdexam
Microsoft

AZ-500 · Question #426

You have an Azure subscription that contains a managed identity named Identity1 and the Azure key vaults shown in the following table. KeyVault1 contains an access policy that grants Identity1 the…

The correct answer is A. Key Vault Crypto Service Encryption User. Key Vault Crypto User https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#key-vault-crypto- Key Vault Crypto Service Encryption User https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#key-vault-crypto…

Submitted by stefanr· Mar 6, 2026Secure identity and access

Question

You have an Azure subscription that contains a managed identity named Identity1 and the Azure key vaults shown in the following table. KeyVault1 contains an access policy that grants Identity1 the following key permissions: - Get - List - Wrap - Unwrap You need to provide Identity1 with the same permissions for KeyVault2. The solution must use the principle of least privilege. Which role should you assign to Identity1?

Options

  • AKey Vault Crypto Service Encryption User
  • BKey Vault Crypto User
  • CKey Vault Reader
  • DKey Vault Crypto Officer

How the community answered

(49 responses)
  • A
    73% (36)
  • B
    8% (4)
  • C
    4% (2)
  • D
    14% (7)

Explanation

Key Vault Crypto User https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#key-vault-crypto- Key Vault Crypto Service Encryption User https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#key-vault-crypto- service-encryption-user Comparing the permissions, Key Vault Crypto Service Encryption User has exactly the permissions required with least previlidge.

Topics

#managed identity#Key Vault RBAC#key permissions#least privilege

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice