Courseiva

AZ-204 · topic practice

Implement Azure security practice questions

This domain covers securing Azure workloads: Microsoft Entra ID authentication and authorization, managed identities, Azure Key Vault access via RBAC and access policies, and protecting app configuration and secrets. Questions present scenario constraints—least privilege, no stored credentials, secret rotation—and ask you to select the correct identity, permission model, or Key Vault integration approach.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Implement Azure security

What the exam tests

What to know about Implement Azure security

Be able to choose the right identity (managed identity vs service principal), grant least-privilege Key Vault permissions via RBAC or access policies, and wire secrets into App Service or Functions using Key Vault references—without storing credentials in configuration.

Assigning Key Vault RBAC roles versus access policies for least-privilege team access

Using managed identities with DefaultAzureCredential to read Key Vault secrets without stored credentials

Referencing Key Vault secrets from App Service and Azure Functions via Key Vault references

Scoping Key Vault access with Microsoft Entra ID app registrations, service principals, and access policies

Watch out for

Common Implement Azure security exam traps

  • ▸Mixing Key Vault access policies with Azure RBAC on the same vault, which causes conflicting or unexpected permission evaluation.
  • ▸Granting broad roles like Key Vault Administrator when read-only or list-only access was explicitly required by the scenario.
  • ▸Storing secrets in application settings or source instead of using managed identities and Key Vault references, violating no-credential policies.

Practice set

Implement Azure security questions

20 questions · select your answer, then reveal the explanation

Your company stores sensitive documents in an Azure Storage account. You need to ensure that only authorized Microsoft Entra ID users can read the documents, and that shared keys (account access keys) cannot be used. Which two steps must you take? (Choose the most appropriate single answer that describes the combined action.)

Question 2mediummultiple choice
Review the full subnetting walkthrough →

You need to restrict access to an Azure Storage account so that only a specific subnet of a virtual network can access the data. Additionally, you need to allow management access from the Azure portal (e.g., to view containers). Which configuration should you apply?

You deploy an Azure App Service web app that uses a system-assigned managed identity. The app needs to read a secret stored in Azure Key Vault to connect to a third-party service. You want to grant the minimum required permissions to the managed identity. Which Azure RBAC role should you assign to the managed identity at the Key Vault scope?

An API receives JWT access tokens from Microsoft Entra ID. Which two token properties should the API validate before accepting a request? The design must avoid adding custom operational scripts.

A background service must call Microsoft Graph without a signed-in user. Which Microsoft identity platform permission model is required?

Match each Azure authentication mechanism to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Automated identity for Azure resources without secrets

Identity for applications to access Azure resources

Delegated access token with limited permissions

Identity service for customer-facing applications

You are implementing a microservices solution on Azure Kubernetes Service (AKS). You need to securely store and retrieve connection strings to a database without hardcoding them in the application code. The solution should automatically rotate secrets every 90 days. What should you use?

Your company uses Azure DevOps for CI/CD. The security team requires that all pull request (PR) merges to the main branch be signed with a valid code signing certificate to ensure code integrity. Which Azure DevOps feature should you enforce?

Your organization uses Azure Policy to enforce compliance. You need to ensure that all Azure SQL databases have Advanced Data Security (ADS) enabled. What type of Azure Policy effect should you use to automatically enable ADS if it is not already enabled?

Refer to the exhibit. You are creating a custom Azure RBAC role. You assign this role to a user for the Production resource group. The user needs to read the contents of a blob in a container. Which permission is necessary for the user to list the container's blobs?

Exhibit

{
  "roleName": "Custom Storage Blob Data Reader",
  "assignableScopes": ["/subscriptions/12345-.../resourceGroups/ProdRG"],
  "permissions": [
    {
      "actions": ["Microsoft.Storage/storageAccounts/blobServices/containers/read"],
      "notActions": [],
      "dataActions": ["Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read"],
      "notDataActions": []
    }
  ]
}

You need to restrict access to an Azure Storage blob container so that only users from your Microsoft Entra tenant can read blobs, and deny all other access including anonymous traffic. What should you configure?

Which TWO services can be used to manage secrets and certificates for applications running on Azure? (Choose two.)

Which TWO permissions should be granted to an application's managed identity to allow it to read secrets from Azure Key Vault and use them to access Azure Storage?

Which TWO of the following are benefits of using Azure Key Vault to store application secrets?

Question 15mediummultiple choice
Read the full Implement security explanation →

A company uses Azure Logic Apps to orchestrate workflows that process sensitive data. They need to ensure that workflow runs are logged and auditable, and that the logs are tamper-proof. Which Azure service should they use?

Which THREE measures can you use to protect data at rest in Azure Cosmos DB? (Choose three.)

Your application uses Azure App Service and needs to authenticate users via Microsoft Entra ID. Which THREE components must be configured in the App Service authentication settings?

Refer to the exhibit. You create a custom RBAC role with the shown permissions. You assign this role to a user at the resource group scope. What can the user do?

Exhibit

Refer to the exhibit.
{
  "roleName": "CustomRole",
  "actions": [
    "Microsoft.KeyVault/vaults/read",
    "Microsoft.KeyVault/vaults/secrets/read"
  ],
  "notActions": [],
  "assignableScopes": ["/subscriptions/sub1/resourceGroups/rg1"]
}

You are developing a .NET Core API that uses Azure AD for authentication. You want to restrict access to specific claims. Which middleware component should you use to check claims?

A company is designing a secure microservices architecture on Azure Kubernetes Service (AKS). The security requirements include: encrypting secrets at rest and in transit, rotating secrets automatically, and avoiding hard-coded credentials in application code. Which THREE solutions should the company use? (Choose three.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Implement Azure security sessions

Start a Implement Azure security only practice session

Every question in these sessions is drawn from the Implement Azure security domain — nothing else.

Related practice questions

Related AZ-204 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the AZ-204 exam test about Implement Azure security?
Be able to choose the right identity (managed identity vs service principal), grant least-privilege Key Vault permissions via RBAC or access policies, and wire secrets into App Service or Functions using Key Vault references—without storing credentials in configuration.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Implement Azure security questions in a focused session?
Yes — the session launcher on this page draws every question from the Implement Azure security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other AZ-204 topics?
Use the topic links above to move to related areas, or go back to the AZ-204 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the AZ-204 exam covers. They are not copied from any real exam or dump site.