Rotating a Key Vault key on a schedule starts with creating a key rotation policy
You have an Azure subscription that contains an Azure Key Vault Standard key vault named Vault1. Vault1 hosts a 2048-bit RSA key named key1. You need to ensure that key1 is rotated every 90 days. What should you do first?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
A rotation policy is the control plane for scheduled key rotation; the vault tier and key type (RSA 2048) are already sufficient, so no upgrade or key recreation is needed to begin configuring rotation.
To rotate key1 automatically every 90 days, you create a key rotation policy on the key in Key Vault. The rotation policy defines the expiration action and rotation frequency (e.g., 90 days) and, once set, Key Vault generates a new key version on schedule.
Candidates think you must upgrade to Key Vault Premium or recreate the key as an EC key, but scheduled rotation is configured via a rotation policy on the existing RSA key in the Standard vault.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Azure Key Vault supports automatic key rotation through a rotation policy that you set per key, specifying the rotation interval. To rotate key1 every 90 days, the first action is to create that rotation policy. (Option A)Why the Other Options Are Wrong
- Option B (Modify access policies) controls who can use the key, not how often it rotates.
- Option C (Upgrade to Premium) is unnecessary; rotation is configured via a policy on the existing Standard vault key.
- Option D (Recreate as EC key) changes the key type but does not set a 90-day rotation schedule.