Enforce Cryptographic Algorithm in Key Vault
You are developing an application that uses keys stored in Azure Key Vault. You need to enforce a specific cryptographic algorithm and key size for keys stored in the vault. What should you use?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the ability to enforce compliance on Key Vault keys, where the common trap is confusing access control (Access policies) with resource configuration compliance (Azure Policy).
Azure Key Vault key creation can be restricted using Azure Policy to enforce specific cryptographic algorithms and key sizes. This page explains why Azure Policy is the correct choice for enforcing these compliance standards over other Key Vault features.
Selecting Access policies (D) because it controls key permissions, but it does not restrict the cryptographic algorithm or key size during key creation.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Azure Policy is the Azure service designed to enforce organizational standards and assess compliance at-scale. By applying Azure Policy to Azure Key Vault, you can specifically deny or audit the creation of keys that do not match required cryptographic algorithms and key sizes. This ensures that all keys created in the vault meet your security baseline and compliance requirements.Why the Other Options Are Wrong
Secret versioning (A) only manages the history and iterations of secrets, lacking any capability to enforce key specifications. Key Vault Firewall (C) restricts network access to the vault but does not govern the properties of the keys created inside. Access policies (D) define permissions for principals to perform operations on vault objects, but they do not restrict the cryptographic algorithms or sizes of the keys themselves.Community Comment Notes
The community correctly identifies Azure Policy as the mechanism for enforcing compliance rules on Key Vault resources. As FeriAZ noted, Azure Policy can "apply policies on various resources, including Azure Key Vault, to ensure they comply with specific rules". Tralalaaz204 provided the official Microsoft documentation reference for Key Vault policy definitions, further supporting this verdict.Official Reference
Exam Strategy
When a question asks to "enforce" a specific configuration or standard across Azure resources, default to Azure Policy. Distinguish between access control (who can do what) and compliance enforcement (what is allowed to exist).