Courseiva
Implement Azure security →mediumMultiple Choice

AZ-204 Implement Azure security Practice Question

You are developing an ASP.NET Core web API hosted on Azure App Service. The API must call a downstream REST service that requires a Microsoft Entra ID access token. Your team wants to avoid storing any credentials in code or configuration, and the App Service instance must be able to obtain the token without a signed-in user. You configure a user-assigned managed identity on the App Service. Which code should you use to acquire the token?

⚠ Common exam trap

The trap here is assuming that Easy Auth or App Configuration can supply an outbound token, when only a credential like managed identity can mint a token for a downstream service.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use DefaultAzureCredential from the Azure.Identity library and call GetTokenAsync with the downstream service scope.

DefaultAzureCredential is the recommended way to obtain tokens in Azure-hosted code because it chains credential types and automatically uses the managed identity when deployed to App Service. This satisfies the requirement to avoid stored credentials and works without a signed-in user, since the managed identity is the principal that requests the token.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the Microsoft.Identity.Client (MSAL) library with ClientSecretCredential and a client secret stored in App Service application settings.

    Why it's wrong here

    ClientSecretCredential requires a client secret, which the scenario explicitly forbids storing in code or configuration. Even if the secret were referenced from Key Vault, the requirement is to avoid storing credentials. Managed identity is the correct credential-free mechanism, so this approach does not meet the stated constraint.

  • ✗

    Use the Azure App Configuration client library to retrieve a pre-generated bearer token stored as a key-value pair.

    Why it's wrong here

    App Configuration is a configuration store, not a token issuer. Storing a bearer token there would still be storing a credential and would also expire quickly, requiring rotation. It does not use the managed identity to obtain a token and therefore fails the requirement to avoid credentials and to work without a signed-in user.

  • ✓

    Use DefaultAzureCredential from the Azure.Identity library and call GetTokenAsync with the downstream service scope.

    Why this is correct

    DefaultAzureCredential automatically discovers the managed identity when running in Azure App Service. It uses the token endpoint exposed by the App Service platform, so no secret is stored. Calling GetTokenAsync with the downstream API scope returns a valid access token that can be attached as a Bearer header, satisfying the requirement without credentials in configuration.

  • ✗

    Use the Azure App Service Authentication (Easy Auth) feature and read the X-MS-TOKEN-AAD-ACCESS-TOKEN header from the incoming request.

    Why it's wrong here

    Easy Auth handles inbound authentication of callers, not outbound token acquisition for downstream APIs. The X-MS-TOKEN-AAD-ACCESS-TOKEN header is populated from the caller's token, not a token for a downstream service. This does not provide a credential-free way for the API itself to obtain a token for another resource.

Go deeper

Related to this question

About these practice questions

This AZ-204 question is part of Courseiva's 883-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.