Your application uses keys stored in Azure Key Vault and you must enforce a particular cryptographic algorithm and key size for keys placed in the vault. Which mechanism enforces these constraints?
Choose an answer
Tap an option to check your answer.
Correct answer: Azure Policy.
Why this is the answer
Azure Policy is the correct mechanism because it allows you to define and enforce rules over your Azure resources, including Key Vault. You can create custom policies to specify required cryptographic algorithms (e.g., RSA, EC) and key sizes (e.g., 2048, 4096) for keys created or updated in Key Vault. If a key is created that violates these policies, the operation can be denied or audited. Secret versioning tracks changes to secrets but does not enforce constraints on their properties. A Key Vault firewall restricts network access to the vault but doesn't govern the cryptographic properties of keys within it. Access policies control who can perform operations on keys, secrets, and certificates, but they do not enforce cryptographic standards.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed