You are designing a solution to store application secrets. You need to ensure that secrets are encrypted at rest and access is audited. Which TWO Azure services should you use?
Azure Monitor is a comprehensive solution for collecting, analyzing, and acting on telemetry from Azure and on-premises environments. While it does not store application secrets itself, it is crucial for monitoring the security and access patterns of a dedicated secret store like Azure Key Vault. By integrating with Key Vault diagnostic logs, Azure Monitor enables auditing of secret access, detection of anomalous behavior, and alerting on security incidents, thereby enhancing the overall security posture of the secret management solution.
Why this answer
Azure Monitor is correct because it provides the auditing and logging capabilities required to track access to secrets. By enabling diagnostic settings on Key Vault, you can send audit events (e.g., secret get, set, delete) to a Log Analytics workspace, storage account, or Event Hub, which are then queryable via Azure Monitor Logs. This satisfies the requirement for access auditing.
Exam trap
The trap here is that candidates often confuse Azure App Configuration with Key Vault, but App Configuration is for non-sensitive settings (e.g., feature flags) and lacks the encryption-at-rest and auditing guarantees required for secrets, while Key Vault is the dedicated service for secure secret storage and access logging.