Courseiva
Implement Azure security →hardMultiple Select

AZ-204 Implement Azure security Practice Question

An API receives JWT access tokens from Microsoft Entra ID. Which two token properties should the API validate before accepting a request? The team wants the control to be enforceable during normal operations.

⚠ Common exam trap

Test-takers frequently think validating the user's display name (Option B) is necessary for authorization, but token validation is about verifying the token's authenticity and intended audience, not user attributes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Issuer and signature are valid for the trusted tenant

Option A is correct because the API must verify that the JWT was issued by the trusted Microsoft Entra ID tenant (checking the iss claim against the tenant's issuer URL) and that its signature validates against Entra ID's published signing keys, which prevents forged or tampered tokens. Option C is correct because the API must confirm the aud claim matches its own expected audience — the Application ID URI or client ID — so that a token issued for a different resource cannot be replayed against this API. Option B is not a security control: a display name claim is optional, user-controlled in some flows, and does not prove the token's validity or intended recipient. Option D is incorrect because tokens should be sent in the Authorization header as a Bearer token, not in a query string, which would expose them in logs and URLs and is not a validation property.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Issuer and signature are valid for the trusted tenant

    Why this is correct

    Validating the issuer confirms the token was minted by the trusted Microsoft Entra ID tenant, while signature verification proves the token is authentic and untampered. Together these prevent forged or foreign-tenant tokens from being accepted, satisfying the requirement for an enforceable control during normal API operations.

  • ✗

    The user's display name is present

    Why it's wrong here

    Display name is a cosmetic claim, not a security control; a forged token can carry any name. Validation must instead check the signature, issuer, audience and expiry. Names appear in profile lookups or UI display, where identity presentation rather than authorisation is the goal.

  • ✓

    Token audience matches the API application ID URI or client ID

    Why this is correct

    Checking that the audience claim matches the API's application ID URI or client ID ensures the token was issued specifically for this API, not another resource. This blocks token replay against unintended services, directly satisfying the requirement for an enforceable validation control during normal operations.

  • ✗

    The token was sent in a query string

    Why it's wrong here

    Query-string placement is a transport detail, not a token claim the API validates; tokens in URLs leak via logs and referrer headers. The API must verify signature, issuer, audience, expiry, and scopes. Query-string transmission would only be relevant when diagnosing why a token was rejected or exposed.

About these practice questions

Courseiva writes every AZ-204 question from scratch — 883 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.