You have microservices on an AKS cluster that use Cosmos DB and Blob storage protected with customer-managed keys in Azure Key Vault. Keys must rotate automatically every three months, allow manual rotation, and send notifications before keys expire. Which two actions should you take to enable rotation and expiry notifications?
Choose an answer
Tap an option to check your answer.
Correct answer: Create and configure an Azure Event Grid instance., Create and configure a key rotation policy when creating the key..
Why this is the answer
To enable automatic key rotation and expiry notifications, you must create and configure a key rotation policy when creating the key. This policy defines the rotation frequency (e.g., every three months) and the notification period before expiry. Azure Key Vault integrates with Azure Event Grid to send notifications for key lifecycle events, including rotation and impending expiry. Therefore, you also need to create and configure an Azure Event Grid instance to subscribe to these Key Vault events and route them to your desired notification endpoint (e.g., Azure Function, Logic App, Webhook). Configuring Azure Key Vault alerts is not the primary mechanism for key rotation or expiry notifications; it's more for operational metrics. Creating an access policy is necessary for applications to use the keys but doesn't manage rotation or notifications.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed