AZ-204 Implement Azure security Practice Question
You are developing an ASP.NET Core web API hosted in Azure App Service. The API must call Azure Key Vault at runtime to retrieve database credentials. You need to configure authentication so the app can access the vault without storing any secrets in code or app settings. What should you do?
⚠ Common exam trap
The trap here is assuming that any credential stored outside code, such as in App Configuration or a client secret, satisfies the no-secrets requirement when only a managed identity truly eliminates stored credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable a system-assigned managed identity on the App Service and grant it access to the Key Vault.
A system-assigned managed identity is the correct approach because it provides an identity for the App Service in Microsoft Entra ID, allowing it to authenticate to Key Vault without any stored secrets. Granting that identity access via Key Vault access policies or Azure RBAC enables secure, credential-free retrieval of secrets at runtime, which is the standard pattern for this requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Register an app in Microsoft Entra ID and add a client secret to the app's configuration.
Why it's wrong here
Registering an app and using a client secret still requires storing that secret in configuration or code, which is exactly what the scenario says to avoid. Client secrets are long-lived credentials that can be leaked. This approach does not eliminate secrets; it just moves them into app settings, which violates the requirement.
- ✗
Store the Key Vault access key in Azure App Configuration and reference it from the app.
Why it's wrong here
Azure App Configuration is a configuration store, not a secret-less authentication mechanism. Storing a Key Vault access key there still means a credential must be retrieved and used, and App Configuration itself would need protection. This does not remove the need for a secret and does not provide an identity-based authentication path.
- ✓
Enable a system-assigned managed identity on the App Service and grant it access to the Key Vault.
Why this is correct
A system-assigned managed identity gives the App Service its own identity in Microsoft Entra ID. You can grant that identity access to Key Vault using an access policy or Azure RBAC role, and the app authenticates to Key Vault without any stored credentials. This directly satisfies the requirement of no secrets in code or configuration.
- ✗
Use the App Service's publishing profile credentials to authenticate to Key Vault.
Why it's wrong here
Publishing profile credentials are for deployment, not runtime authentication to other services. They are not recognized by Key Vault as an authentication method and would not grant access to vault secrets. Using them also exposes deployment credentials, which is a security risk and does not meet the no-secrets requirement.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Service Bus Sessions and Duplicate Detection
Key term
Managed identity
A managed identity is an automatically managed service principal in Azure that allows your code to authenticate to any service that supports Microsoft Entra ID authentication without storing credentials.
Key term
Key Vault Secrets
Key Vault Secrets are secure containers in Microsoft Azure that store sensitive information like passwords, connection strings, and API keys, keeping them encrypted and accessible only to authorized applications and users.
About these practice questions
This AZ-204 question is part of Courseiva's 883-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.