Enforce Cryptographic Algorithm in Key Vault

Implement secure Azure solutions
Answer Correct answer: B — Use Azure Policy to enforce a specific cryptographic algorithm and key size for keys stored in Azure Key Vault.

You are developing an application that uses keys stored in Azure Key Vault. You need to enforce a specific cryptographic algorithm and key size for keys stored in the vault. What should you use?

  1. Secret versioning
  2. Azure Policy Correct Answer
  3. Key Vault Firewall
  4. Access policies

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the ability to enforce compliance on Key Vault keys, where the common trap is confusing access control (Access policies) with resource configuration compliance (Azure Policy).

Azure Key Vault key creation can be restricted using Azure Policy to enforce specific cryptographic algorithms and key sizes. This page explains why Azure Policy is the correct choice for enforcing these compliance standards over other Key Vault features.

Selecting Access policies (D) because it controls key permissions, but it does not restrict the cryptographic algorithm or key size during key creation.

Community Discussion (4 comments)

FeriAZ 👍 4 Selected: B
Azure Policy is a service in Azure that helps you enforce organizational standards and assess compliance at scale. With Azure Policy, you can apply policies on various resources, including Azure Key Vault, to ensure they comply with specific rules and requirements, like enforcing specific cryptographic algorithms and key sizes.
Tralalaaz204 👍 4 Selected: B
I agree. See https://learn.microsoft.com/en-us/azure/key-vault/policy-reference
AzDeveloper 👍 2 Selected: B
B is correct Reference: https://learn.microsoft.com/en-us/azure/key-vault/general/azure-policy
Ciupaz 👍 1 Selected: B
Azure Policy is the correct answer.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Azure Policy is the Azure service designed to enforce organizational standards and assess compliance at-scale. By applying Azure Policy to Azure Key Vault, you can specifically deny or audit the creation of keys that do not match required cryptographic algorithms and key sizes. This ensures that all keys created in the vault meet your security baseline and compliance requirements.

Why the Other Options Are Wrong

Secret versioning (A) only manages the history and iterations of secrets, lacking any capability to enforce key specifications. Key Vault Firewall (C) restricts network access to the vault but does not govern the properties of the keys created inside. Access policies (D) define permissions for principals to perform operations on vault objects, but they do not restrict the cryptographic algorithms or sizes of the keys themselves.

Community Comment Notes

The community correctly identifies Azure Policy as the mechanism for enforcing compliance rules on Key Vault resources. As FeriAZ noted, Azure Policy can "apply policies on various resources, including Azure Key Vault, to ensure they comply with specific rules". Tralalaaz204 provided the official Microsoft documentation reference for Key Vault policy definitions, further supporting this verdict.

Official Reference

Exam Strategy

When a question asks to "enforce" a specific configuration or standard across Azure resources, default to Azure Policy. Distinguish between access control (who can do what) and compliance enforcement (what is allowed to exist).

Related Analysis

← Back to AZ-204 Study Guide