You are onboarding api.contoso.com as a custom domain on an Azure CDN Standard (Microsoft) endpoint. Corporate security requires using a certificate issued by your approved CA and managing the private key lifecycle in Azure Key Vault, including manual rotation on your schedule. What should you configure for HTTPS on the custom domain?
Choose an answer
Tap an option to check your answer.
Correct answer: Use Bring Your Own Certificate (BYOC) with a certificate stored in Azure Key Vault and enable HTTPS for the custom domain..
Why this is the answer
The correct answer is to use Bring Your Own Certificate (BYOC) with a certificate stored in Azure Key Vault and enable HTTPS for the custom domain. This option directly addresses all requirements: using a certificate from an approved CA, managing the private key lifecycle in Key Vault, and supporting manual rotation. Azure CDN Standard (Microsoft) integrates with Key Vault for BYOC, allowing you to specify your certificate and control its lifecycle. Using an Azure-managed certificate is incorrect because it doesn't allow you to use a certificate from your approved CA or manage the private key lifecycle manually. Uploading a PFX file directly to the CDN endpoint is incorrect because it bypasses Key Vault, failing to meet the requirement for managing the private key lifecycle there. Terminating TLS only at the origin is incorrect as it would send unencrypted traffic between the client and CDN, violating security best practices and likely corporate security policies.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed