AZ-304 – Question #89


Question #89

You have an Azure web app named App1 and an Azure key vault named KV1.
App1 stores database connection strings in KV1.
App1 performs the following types of requests to KV1:
✑ Get
✑ List
✑ Wrap
✑ Delete
✑ Unwrap
✑ Backup
✑ Decrypt
✑ Encrypt
You are evaluating the continuity of service for App1.
You need to identify the following if the Azure region that hosts KV1 becomes unavailable:
✑ To where will KV1 fail over?
✑ During the failover, which request type will be unavailable?
What should you identify? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Correct Answer:

Box 1: A server in the same paired region
The contents of your key vault are replicated within the region and to a secondary region at least 150 miles away, but within the same geography to maintain high durability of your keys and secrets.

Box 2: Delete –
During failover, your key vault is in read-only mode. Requests that are supported in this mode are:
✑ List certificates
✑ Get certificates
✑ List secrets
✑ Get secrets
✑ List keys
✑ Get (properties of) keys
✑ Encrypt
✑ Decrypt
✑ Wrap
✑ Unwrap
✑ Verify
✑ Sign
✑ Backup