You need to grant a user administrative access to an Azure Key Vault so they can configure advanced access policies, following the principle of least privilege. Which option should you use?
Choose an answer
Tap an option to check your answer.
Correct answer: RBAC.
Why this is the answer
Role-Based Access Control (RBAC) is the correct choice because it allows you to define granular permissions for Azure resources, including Key Vaults. You can assign specific built-in roles (like Key Vault Administrator) or custom roles to users, groups, or service principals, granting them the precise level of access required to configure advanced access policies without over-privileging them. This directly adheres to the principle of least privilege. Azure Information Protection focuses on data classification and protection, not administrative access to resources. Azure AD Privileged Identity Management (PIM) is used for just-in-time access and approval workflows for privileged roles, but RBAC is the underlying mechanism for defining those roles and permissions in the first place. Azure DevOps is a suite of development tools and is unrelated to managing access to Azure resources.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed