You manage certificates for workloads in Azure. You need to use Azure Key Vault to store an existing PFX for immediate use and also enable automatic renewal and rotation for future certificates issued by a public CA. What should you configure? Choose two actions.
Choose an answer
Tap an option to check your answer.
Correct answer: Import the existing PFX into Azure Key Vault as a Certificate (with private key) and grant consuming services Secret GET access to the certificate's associated secret., Configure a Certificate Issuer (e.g., DigiCert/GlobalSign) in Key Vault and create the certificate in Key Vault with a policy that defines lifetime actions (auto-renew 60 days before expiry)..
Why this is the answer
To use an existing PFX immediately, you must import it into Key Vault as a Certificate, which includes the private key. Consuming services then need Secret GET access to retrieve the certificate data. For future certificates and automatic renewal, you need to configure a Certificate Issuer within Key Vault. This links Key Vault to a public CA. Then, when you create a new certificate in Key Vault, you define a policy that includes lifetime actions, such as auto-renewal a specified number of days before expiry. Enabling automatic rotation on an imported PFX is incorrect because Key Vault cannot directly renew certificates with the original CA without an integrated issuer. Azure Policy cannot auto-rotate certificates without issuer configuration, as it lacks the mechanism to interact with CAs. App Service Managed Certificates are specific to Azure App Service and do not manage certificates for general workloads in Key Vault.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed