Courseiva
Implement Azure security →mediumMultiple Choice

AZ-204 Implement Azure security Practice Question

You are developing an ASP.NET Core web API hosted in Azure App Service. The API must call Azure Key Vault at runtime to retrieve database credentials. You need to configure authentication so the app can access the vault without storing any secrets in code or app settings. What should you do?

⚠ Common exam trap

The trap here is assuming that any credential stored outside code, such as in App Configuration or a client secret, satisfies the no-secrets requirement when only a managed identity truly eliminates stored credentials.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable a system-assigned managed identity on the App Service and grant it access to the Key Vault.

A system-assigned managed identity is the correct approach because it provides an identity for the App Service in Microsoft Entra ID, allowing it to authenticate to Key Vault without any stored secrets. Granting that identity access via Key Vault access policies or Azure RBAC enables secure, credential-free retrieval of secrets at runtime, which is the standard pattern for this requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Register an app in Microsoft Entra ID and add a client secret to the app's configuration.

    Why it's wrong here

    Registering an app and using a client secret still requires storing that secret in configuration or code, which is exactly what the scenario says to avoid. Client secrets are long-lived credentials that can be leaked. This approach does not eliminate secrets; it just moves them into app settings, which violates the requirement.

  • ✗

    Store the Key Vault access key in Azure App Configuration and reference it from the app.

    Why it's wrong here

    Azure App Configuration is a configuration store, not a secret-less authentication mechanism. Storing a Key Vault access key there still means a credential must be retrieved and used, and App Configuration itself would need protection. This does not remove the need for a secret and does not provide an identity-based authentication path.

  • ✓

    Enable a system-assigned managed identity on the App Service and grant it access to the Key Vault.

    Why this is correct

    A system-assigned managed identity gives the App Service its own identity in Microsoft Entra ID. You can grant that identity access to Key Vault using an access policy or Azure RBAC role, and the app authenticates to Key Vault without any stored credentials. This directly satisfies the requirement of no secrets in code or configuration.

  • ✗

    Use the App Service's publishing profile credentials to authenticate to Key Vault.

    Why it's wrong here

    Publishing profile credentials are for deployment, not runtime authentication to other services. They are not recognized by Key Vault as an authentication method and would not grant access to vault secrets. Using them also exposes deployment credentials, which is a security risk and does not meet the no-secrets requirement.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

Go deeper

Related to this question

About these practice questions

This AZ-204 question is part of Courseiva's 883-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.