AZ-204 Develop Azure compute solutions Practice Question
You are developing a containerized web application that will be deployed to Azure App Service. The application must read a connection string from an environment variable at runtime. You want to avoid storing the connection string in the source code or in the App Service application settings in plaintext. What should you do?
⚠ Common exam trap
The trap here is thinking that hiding application settings in the portal or using build arguments keeps secrets secure, when those methods still store or expose the value in plaintext or metadata.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Store the connection string in Azure Key Vault and reference it from App Service application settings by using a Key Vault reference.
Key Vault references let App Service fetch secrets from Azure Key Vault and surface them as environment variables. The connection string is not stored in application settings or source code, and access to Key Vault can be controlled with managed identities and access policies. This provides secure storage, centralized management, and easy rotation, directly meeting the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the connection string in the App Service application settings and enable the 'hidden' setting so it is not displayed in the portal.
Why it's wrong here
App Service application settings are stored in plaintext in the App Service configuration, even if the portal hides the value. Anyone with read access to the app's configuration or the underlying platform can retrieve the value. This does not provide encryption at rest or access control, so it does not satisfy the requirement to avoid plaintext storage.
- ✓
Store the connection string in Azure Key Vault and reference it from App Service application settings by using a Key Vault reference.
Why this is correct
Key Vault references allow App Service to retrieve secrets from Azure Key Vault and expose them as environment variables to your container. The connection string is never stored in plaintext in application settings or source code. The app reads it as an environment variable, and App Service handles authentication to Key Vault, often via a managed identity, meeting the security requirement.
- ✗
Store the connection string in a configuration file that is baked into the container image and read it from the file at runtime.
Why it's wrong here
Baking the connection string into the container image means it is stored in the image layers, which can be inspected by anyone with access to the registry or the running container. This violates the requirement to avoid plaintext storage and does not use a secure secret store. It also makes secret rotation difficult because a new image must be built.
- ✗
Pass the connection string as a build argument when building the container image and set it as a container environment variable.
Why it's wrong here
Build arguments are recorded in the image history and can be retrieved with tools like docker history. Setting the connection string as a build argument exposes it in the image metadata and potentially in logs. This approach does not provide secure storage and fails to meet the requirement to avoid plaintext secrets in the deployment pipeline.
Go deeper
Related to this question
About these practice questions
One of 883 original AZ-204 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.