Identity1 has key permissions (Get, List, Wrap, Unwrap) on KeyVault1. To grant Identity1 the same key permissions on KeyVault2 using least privilege, which role should you assign?
Choose an answer
Tap an option to check your answer.
Correct answer: Key Vault Crypto Service Encryption User.
Why this is the answer
The Key Vault Crypto Service Encryption User role grants permissions to perform cryptographic operations like Get, List, Wrap, and Unwrap on keys. This aligns precisely with the required permissions for Identity1 on KeyVault2, adhering to the principle of least privilege. Key Vault Crypto User provides basic cryptographic operations but might not include all specified permissions. Key Vault Reader only allows reading metadata about keys, secrets, and certificates, not performing operations on them. Key Vault Crypto Officer has elevated permissions, including creating and deleting keys, which exceeds the stated requirement.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed