You manage TLS certificates for an Azure App Service. Certificates must be issued by DigiCert, auto-renew 30 days before expiration, and alert your operations team when renewal occurs. You will store and manage the certificates in Azure Key Vault. Which actions should you take? Select all that apply.
Choose an answer
Tap an option to check your answer.
Correct answer: In Key Vault, add a certificate issuer for DigiCert and configure the certificate to use that issuer., Define a Key Vault certificate policy with a lifetime action to auto-renew 30 days before expiry., Add certificate contacts in Key Vault so renewal and expiration notifications are emailed to the team..
Why this is the answer
To meet the requirement of DigiCert issuance, you must configure a certificate issuer in Key Vault specifically for DigiCert and then associate your certificate with this issuer. For auto-renewal 30 days before expiration, a Key Vault certificate policy is essential; within this policy, you define a lifetime action to trigger renewal at the specified interval. To alert the operations team upon renewal, adding certificate contacts in Key Vault ensures that email notifications are sent for renewal events and expirations. The App Service Managed Certificate option is incorrect because it issues certificates from App Service's own CA and does not allow specifying DigiCert as the issuer or integrating with existing Key Vault certificates for auto-rotation.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed