You have an Azure subscription with an Azure Key Vault named Vault1 that contains a secret named Secret1. An application is registered in Azure Active Directory. Which action grants the application permission to use Secret1?
Choose an answer
Tap an option to check your answer.
Correct answer: In Azure Key Vault, create an access policy..
Why this is the answer
To grant an application permission to use a secret within an Azure Key Vault, you must create an access policy directly on the Key Vault. Access policies define who (users, groups, or applications) can perform what operations (get, list, set, delete, etc.) on keys, secrets, or certificates stored in the vault. Creating a role in Azure AD is for managing permissions to Azure resources at a broader level, not for granular Key Vault secret access. Creating a key in Azure Key Vault is for cryptographic keys, not for granting access to secrets. Enabling Azure AD Application Proxy is for publishing on-premises web applications to external users, unrelated to Key Vault access control.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed