Your production Key Vault stores secrets and keys used by multiple services. You must ensure that accidental deletion of secrets/keys can be recovered for a defined period and that no one can permanently delete them during that period, even subscription owners. What should you configure?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable soft-delete on the vault and set an appropriate retention period., Enable purge protection on the vault so deleted objects cannot be permanently removed before retention expires..
Why this is the answer
The correct options are enabling soft-delete and purge protection. Soft-delete ensures that deleted secrets and keys are retained for a specified period, allowing for recovery. Purge protection, when enabled alongside soft-delete, prevents anyone, even subscription owners, from permanently deleting (purging) the soft-deleted items before the retention period expires. This combination directly addresses the requirement of recoverable accidental deletions and preventing permanent removal. Applying a ReadOnly resource lock (incorrect) prevents all modifications and deletions, which is too restrictive as it would also prevent legitimate updates to secrets and keys. Using Azure RBAC to deny Delete permissions (incorrect) is not sufficient because subscription owners can bypass or modify RBAC assignments. Furthermore, RBAC alone doesn't provide a recovery mechanism for accidental deletions; it only prevents them.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed