You have an Azure key vault named Vault1 and a VM named VM1 that has the Key Vault VM extension installed. After you rotate keys, secrets, and certificates in Vault1, which items on VM1 will be updated automatically?
Choose an answer
Tap an option to check your answer.
Correct answer: the certificates only.
Why this is the answer
The Key Vault VM extension for Windows and Linux is designed to automatically refresh certificates stored in an Azure Key Vault and bound to the VM. When certificates in Vault1 are rotated, the extension on VM1 will detect these changes and update the corresponding certificates on the VM. It does not automatically update keys or secrets. Keys are typically used for cryptographic operations and often require application-level integration for rotation, while secrets (like passwords or connection strings) are usually retrieved by applications at runtime and are not automatically synced to the VM's local storage by this extension.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed