You need to allow a specific user to add and delete certificates in an Azure Key Vault while following the principle of least privilege. Which option should you use?
Choose an answer
Tap an option to check your answer.
Correct answer: A key vault access policy.
Why this is the answer
A key vault access policy is the correct choice because it provides granular control over permissions within a specific Azure Key Vault. You can define which users, groups, or applications have permissions to perform operations like 'Get', 'List', 'Set', and 'Delete' on keys, secrets, or certificates. This directly adheres to the principle of least privilege by allowing you to grant only the necessary permissions for certificate management to the specific user. Azure Policy is used for enforcing organizational standards and assessing compliance across resources, not for granting specific data plane access to individual users within a Key Vault. Azure AD Privileged Identity Management (PIM) manages, controls, and monitors access to important resources in Azure AD, Azure, and other Microsoft online services, primarily for just-in-time access or approval workflows for elevated roles, not for direct certificate management permissions within a Key Vault. Azure DevOps is a suite of development tools and services, completely unrelated to managing Key Vault access.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed