AZ-204 Practice Question: Connect to and consume Azure services and third-party services
Which THREE considerations are important when designing a solution using Azure API Management (APIM) to secure backend APIs?
⚠ Common exam trap
The trap here is that candidates might think storing credentials in APIM policies is acceptable for simplicity, but Azure explicitly warns against this, and the exam expects knowledge of secure secret management via Key Vault integration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement rate limiting to prevent abuse
Option A is correct because implementing rate limiting (via the rate-limit or rate-limit-by-key policy) in APIM protects backend APIs from abuse, throttling excessive requests and mitigating denial-of-service or brute-force scenarios. Option C is correct because using OAuth2 authentication with Microsoft Entra ID (Microsoft Entra ID) lets APIM validate caller identity through token issuance and scopes, ensuring only authorized clients can reach the backend. Option D is correct because JWT validation policies (validate-jwt) verify token signatures, issuers, audiences, and claims at the gateway, enforcing authentication and authorization before requests reach the backend. Option B is wrong because storing backend database credentials in APIM policies exposes secrets in policy definitions; credentials should be kept in Azure Key Vault and referenced via named values. Option E is wrong because disabling TLS removes transport encryption, exposing API traffic to interception and violating security best practices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement rate limiting to prevent abuse
Why this is correct
Implementing rate limiting in API Management (APIM) is crucial for protecting backend services from denial-of-service attacks, excessive consumption, and unintentional abuse. By configuring policies that restrict the number of API calls a client can make within a specified time frame, such as per minute or per hour, it ensures fair usage and maintains the stability and availability of the underlying resources. This prevents a single client from monopolizing resources and impacting other legitimate users.
- ✗
Store backend database credentials in APIM policies
Why it's wrong here
Storing sensitive backend database credentials directly within APIM policies is a severe security vulnerability. Policy definitions are often part of source control or configuration files, making credentials susceptible to exposure if these artifacts are compromised. Best practice dictates using Azure Key Vault to securely store such secrets, and then referencing these secrets from APIM policies using managed identities or named values, ensuring credentials are never hardcoded or directly exposed.
- ✓
Use OAuth2 authentication with Microsoft Entra ID
Why this is correct
Utilizing OAuth2 authentication with Microsoft Entra ID (Azure AD) is a robust and industry-standard approach for securing APIs by providing secure delegated access. Microsoft Entra ID acts as the identity provider, issuing access tokens after successful user or application authentication and authorization. These tokens, typically JSON Web Tokens (JWTs), are then presented to the API Management gateway, which validates them to ensure the caller has the necessary permissions to access the backend services, thereby enforcing strong identity-based security.
- ✓
Use JWT validation policies to verify tokens
Why this is correct
Implementing JWT validation policies within Azure API Management is essential for verifying the authenticity and integrity of incoming access tokens. These policies validate the token's signature, expiration, issuer, and audience claims against a trusted identity provider, such as Microsoft Entra ID. By performing this rigorous validation at the gateway, APIM ensures that only legitimate, unexpired, and correctly issued tokens are allowed to pass through to the backend services, preventing unauthorized access and token tampering.
- ✗
Disable TLS to improve performance
Why it's wrong here
Disabling Transport Layer Security (TLS) to supposedly improve performance is a critical security misstep and should never be considered in a production environment. TLS encrypts all communication between clients and the API gateway, protecting data in transit from eavesdropping, tampering, and man-in-the-middle attacks. While there's a minor overhead, the security benefits of TLS far outweigh any negligible performance gains from disabling it, making it an indispensable component of secure API design.
Go deeper
Related to this question
Learn chapter
Azure SDK Best Practices and Patterns
Key term
API Management
API Management is a service that acts as a front door for application programming interfaces, controlling access, monitoring usage, and enforcing security policies.
Key term
Key Vault Secrets
Key Vault Secrets are secure containers in Microsoft Azure that store sensitive information like passwords, connection strings, and API keys, keeping them encrypted and accessible only to authorized applications and users.
About these practice questions
One of 883 original AZ-204 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.