A meadowlark-count teammate begins designing private-endpoint hub-and-spoke plus Managed HSM pools for a simple app secret read. What scope matches AZ-204 Domain 3 for Key Vault?
Select an answer to reveal the explanation.
Short Explanation
AZ-204 asks whether the app can read secrets/keys/certs—not whether you designed an HSM fleet with hub-and-spoke private endpoints. That deeper security-engineer territory is AZ-500.
Full Explanation
AZ-204 Domain 3 expects developers to use Key Vault for secrets, keys, and certificates from application code with proper identity. Managed HSM fleets, hub-and-spoke private-endpoint architectures, and security-operations tooling are AZ-500-oriented and should not dominate an AZ-204 Key Vault developer item. Network isolation may be supporting context only.