Courseiva
Implement Azure security →easyMultiple Choice

AZ-204 Implement Azure security Practice Question

You are developing a .NET console application that runs on a developer workstation and also in an Azure Container Instance. The application must read secrets from Azure Key Vault. During local development, the developer signs in with the Azure CLI. In Azure, the container uses a managed identity. You want a single code path that works in both environments without storing credentials. Which approach should you use?

⚠ Common exam trap

The trap here is choosing a credential type that only works in one environment, such as managed identity locally or interactive sign-in in a headless container.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Instantiate SecretClient with a DefaultAzureCredential and pass the Key Vault URI.

DefaultAzureCredential is designed for code that must run in multiple environments. It tries developer tooling credentials first and falls back to managed identity in Azure, so the same SecretClient code works locally and in the container without any stored secret.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Instantiate SecretClient with a ClientSecretCredential using a client secret from an environment variable.

    Why it's wrong here

    ClientSecretCredential requires a client secret, which is a stored credential. Even if placed in an environment variable, it must be provisioned and rotated, and it does not use the developer's Azure CLI identity or the container's managed identity. This violates the requirement to avoid stored credentials and does not provide one unified code path.

  • ✗

    Instantiate SecretClient with a ManagedIdentityCredential and rely on it working on the developer workstation.

    Why it's wrong here

    ManagedIdentityCredential only works in environments that expose a managed identity endpoint, such as Azure-hosted compute. It fails on a developer workstation because no such endpoint exists. While it works in the container, it does not satisfy the requirement for a single code path that also works during local development with the Azure CLI.

  • ✓

    Instantiate SecretClient with a DefaultAzureCredential and pass the Key Vault URI.

    Why this is correct

    DefaultAzureCredential chains multiple credential sources. On a workstation it picks up the Azure CLI sign-in, and in Azure Container Instances it uses the managed identity. This gives one code path that works in both environments without embedding secrets, exactly matching the requirement to avoid stored credentials in code or configuration.

  • ✗

    Instantiate SecretClient with an InteractiveBrowserCredential so the developer and the container can both prompt for sign-in.

    Why it's wrong here

    InteractiveBrowserCredential opens a browser for interactive sign-in, which is not possible in a headless container. It also requires user interaction, so it cannot run unattended in Azure Container Instances. This approach fails the container scenario and does not use the managed identity that is already available.

Go deeper

Related to this question

About these practice questions

One of 883 original AZ-204 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.