Rotating a Key Vault key on a schedule starts with creating a key rotation policy

Implement and manage enforcement of cloud governance policies
Answer Correct answer: A — Create a key rotation policy on key1 and set the rotation interval to 90 days; no vault upgrade is required.

You have an Azure subscription that contains an Azure Key Vault Standard key vault named Vault1. Vault1 hosts a 2048-bit RSA key named key1. You need to ensure that key1 is rotated every 90 days. What should you do first?

  1. Create a key rotation policy. Correct Answer
  2. Modify the Access policies settings of Vault1.
  3. Upgrade Vault1 to Key Vault Premium.
  4. Recreate key1 as an EC key.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

A rotation policy is the control plane for scheduled key rotation; the vault tier and key type (RSA 2048) are already sufficient, so no upgrade or key recreation is needed to begin configuring rotation.

To rotate key1 automatically every 90 days, you create a key rotation policy on the key in Key Vault. The rotation policy defines the expiration action and rotation frequency (e.g., 90 days) and, once set, Key Vault generates a new key version on schedule.

Candidates think you must upgrade to Key Vault Premium or recreate the key as an EC key, but scheduled rotation is configured via a rotation policy on the existing RSA key in the Standard vault.

Community Discussion (3 comments)

husam421 👍 9 Selected: A
Given answer is correct https://learn.microsoft.com/en-us/azure/key-vault/managed-hsm/key-rotation
Jimmy500 👍 1
A is correct!
ITFranz 👍 1
Answer is A. Automated key rotation in Managed HSM allows users to configure Managed HSM to automatically generate a new key version at a specified frequency. You can set a rotation policy to configure rotation for each individual key and optionally rotate keys on demand

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Azure Key Vault supports automatic key rotation through a rotation policy that you set per key, specifying the rotation interval. To rotate key1 every 90 days, the first action is to create that rotation policy. (Option A)

Why the Other Options Are Wrong

  • Option B (Modify access policies) controls who can use the key, not how often it rotates.
  • Option C (Upgrade to Premium) is unnecessary; rotation is configured via a policy on the existing Standard vault key.
  • Option D (Recreate as EC key) changes the key type but does not set a 90-day rotation schedule.

Community Comment Notes

The top comment linked the Key Vault key-rotation docs and stated: 'You can set a rotation policy to configure rotation for each individual key,' confirming A with 100 community votes.

Official Reference

Related Analysis

← Back to AZ-500 Study Guide