AZ-204 Practice Question: Connect to and consume Azure services and third-party services
Which TWO Azure services can be used to store application configuration settings?
⚠ Common exam trap
Many candidates confuse Azure Key Vault as a configuration store for all settings, but it is specifically for secrets (e.g., connection strings, passwords) and not for general application configuration like feature flags or non-sensitive settings, which is why both A and E are correct but for different purposes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure App Configuration
Azure App Configuration (A) is purpose-built for centrally managing application settings and feature flags, providing key-value storage with labels, revisions, and point-in-time snapshots that applications can consume via SDKs or the REST API. Azure Key Vault (E) is also correct because it stores configuration secrets such as connection strings, API keys, and certificates that applications retrieve at runtime, and it is commonly paired with App Configuration for a complete configuration solution. Azure Queue Storage (B) is a messaging service for asynchronous message passing between components, not a configuration store. Azure Blob Storage (C) is object storage for unstructured data like documents and images, not a dedicated configuration service. Azure Cosmos DB (D) is a globally distributed NoSQL database for application data, and while it could technically hold settings, it is not intended as an application configuration service.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure App Configuration
Why this is correct
Azure App Configuration is a dedicated, managed service specifically engineered for centralizing and managing application configuration settings. It supports dynamic configuration updates without redeploying applications, integrates with feature flags, and provides robust version control and snapshot capabilities. This service simplifies configuration management across microservices and distributed applications, making it ideal for modern cloud-native solutions.
- ✗
Azure Queue Storage
Why it's wrong here
Azure Queue Storage is primarily designed for asynchronous message queuing, enabling decoupled application components to communicate reliably. It stores messages temporarily for FIFO processing, not persistent, easily queryable configuration settings. While a configuration update message could be sent, the service itself does not store the configuration values for direct application retrieval, making it unsuitable for managing application settings.
- ✗
Azure Blob Storage
Why it's wrong here
Azure Blob Storage is an object storage solution optimized for storing large amounts of unstructured data, such as documents, images, and video files. While it can technically host configuration files, it lacks the specialized features of a configuration management service, such as dynamic updates, versioning specific to configuration changes, or built-in integration for feature flags. Retrieving and managing configuration from Blob Storage would require significant custom application logic and would not offer the benefits of a dedicated service.
- ✗
Azure Cosmos DB
Why it's wrong here
Azure Cosmos DB is a globally distributed, multi-model database service designed for high-performance, low-latency access to transactional data. While any database could store configuration, Cosmos DB is an expensive and complex solution optimized for operational data workloads, not for the simple key-value or hierarchical storage and retrieval patterns typical of application configuration. Using it for configuration would be significant overkill and would not provide the specialized features offered by dedicated configuration services.
- ✓
Azure Key Vault
Why this is correct
Azure Key Vault is a cloud service for securely storing and managing cryptographic keys, secrets, and certificates. It is an essential component for storing sensitive application configuration data, such as database connection strings, API keys, and other credentials, which should never be hardcoded or stored in plain text. While it doesn't manage all application settings, it is crucial for securing the critical secrets that form part of an application's overall configuration.
Quick reference
Azure Blob Storage Tier Comparison
| Tier | Storage Cost | Retrieval Cost | Latency | Use Case |
|---|---|---|---|---|
| Hot | Highest | Lowest | Immediate | Active data, frequent reads |
| Cool | Lower | Higher | Immediate | Data accessed < once / month |
| Cold | Lower still | Higher | Immediate | Data accessed < once / quarter |
| Archive | Lowest | Highest + rehydration delay | Hours | Long-term compliance retention |
Go deeper
Related to this question
Learn chapter
Cosmos DB Emulator and Local Development
Key term
Azure App Configuration
Azure App Configuration is a managed Azure service that stores and manages application settings and feature flags separately from your code, allowing you to update them without redeploying or restarting your application.
Key term
Azure Queue Storage
Azure Queue Storage is a cloud service for storing and retrieving large numbers of messages that can be accessed from anywhere, enabling asynchronous communication between application components.
About these practice questions
One of 883 original AZ-204 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.