Estate policy requires every RSA key in Key Vault to be scheduled to rotate within 730 days. Which governance approach should the security engineer use?
Select an answer to reveal the explanation.
Short Explanation
Want every RSA key on a 730-day rotation diet? Assign the built-in Policy that audits keys missing a timely rotation policy—it flags gaps; it doesn’t quietly rotate them for you.
Full Explanation
Azure Policy includes built-in definitions that audit Key Vault keys lacking an appropriate rotation policy within a required interval. Audit-effect assignments surface compliance gaps for remediation; they do not themselves rotate existing key material. Manual tribal knowledge and unrelated Sentinel UEBA features do not implement that governance control. Deleting keys without a rotation plan risks application outages.