Courseiva

AZ-204 Develop Azure compute solutions Practice Question

You are developing a solution that uses Azure Container Apps to host a microservices application. The application consists of multiple services that need to communicate with each other. You need to configure the services to meet the following requirements: (1) Services must be able to discover each other by name, (2) Communication between services must be secure and encrypted, (3) You want to minimize the need for managing certificates. Which two actions should you perform? (Choose two.)

⚠ Common exam trap

The trap here is thinking that external load balancers or custom DNS are needed for internal service communication, when Container Apps provides native mTLS and service discovery.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable mutual TLS (mTLS) for the Container Apps environment.

To enable secure service-to-service communication with discovery by name and minimal certificate management, you should enable mutual TLS for the Container Apps environment and use the built-in service discovery. mTLS automatically encrypts and authenticates traffic between container apps, and the platform manages certificates. Built-in service discovery allows services to find each other using the app name without additional configuration. Together, these features provide a secure and simplified microservices communication setup.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy an Azure Application Gateway in front of the Container Apps environment to handle internal traffic.

    Why it's wrong here

    Azure Application Gateway is a layer-7 load balancer for external HTTP traffic. It is not designed for internal service-to-service communication within a Container Apps environment. Using Application Gateway would add unnecessary complexity and cost, and it does not provide automatic encryption or service discovery for internal traffic. The requirements are better met by native Container Apps features like mTLS and built-in service discovery. Therefore, this action is not appropriate.

  • ✓

    Enable mutual TLS (mTLS) for the Container Apps environment.

    Why this is correct

    Mutual TLS in Azure Container Apps provides automatic encryption and authentication between services within the environment. When enabled, each container app receives a certificate issued by the platform, and communication between apps is encrypted and authenticated without manual certificate management. This satisfies the requirement for secure, encrypted communication and minimizes certificate management because the platform handles certificate issuance and rotation. Enabling mTLS is a key step to secure service-to-service communication in a microservices architecture hosted on Container Apps.

  • ✗

    Store service endpoints in Azure Key Vault and retrieve them at runtime.

    Why it's wrong here

    Azure Key Vault is used for storing secrets, keys, and certificates, not for service discovery. While you could store service endpoints as secrets, this would require manual updates and does not provide dynamic discovery. It also does not address encryption between services. The requirement for service discovery by name is already met by Container Apps' built-in feature. Using Key Vault for endpoints would be an anti-pattern and does not simplify certificate management.

  • ✗

    Configure a custom DNS name for each container app and use it for service discovery.

    Why it's wrong here

    While custom DNS names can be used for external access, they are not required for internal service discovery. Azure Container Apps provides built-in service discovery using the app name within the environment. Using custom DNS names would add complexity and might not provide the secure, automatic encryption required. Moreover, custom DNS names are typically for external ingress, not for internal service-to-service communication. Therefore, this action does not meet the requirements and is not necessary.

  • ✓

    Use Azure Container Apps' built-in service discovery by referring to other services using their app name.

    Why this is correct

    Azure Container Apps includes built-in service discovery based on the container app name. When services are in the same environment, they can communicate using the app name as the hostname. This eliminates the need for a separate service registry or custom DNS configuration. Combined with mTLS, this provides secure and encrypted communication. This action directly addresses the requirement for services to discover each other by name, and it is a native feature that simplifies microservices communication.

About these practice questions

This AZ-204 question is part of Courseiva's 883-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.