AZ-204 Implement Azure security Practice Question
You are developing an ASP.NET Core web API hosted on Azure App Service. The API must call a downstream REST service that requires a Microsoft Entra ID access token. Your team wants to avoid storing any credentials in code or configuration, and the App Service instance must be able to obtain the token without a signed-in user. You configure a user-assigned managed identity on the App Service. Which code should you use to acquire the token?
⚠ Common exam trap
The trap here is assuming that Easy Auth or App Configuration can supply an outbound token, when only a credential like managed identity can mint a token for a downstream service.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use DefaultAzureCredential from the Azure.Identity library and call GetTokenAsync with the downstream service scope.
DefaultAzureCredential is the recommended way to obtain tokens in Azure-hosted code because it chains credential types and automatically uses the managed identity when deployed to App Service. This satisfies the requirement to avoid stored credentials and works without a signed-in user, since the managed identity is the principal that requests the token.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the Microsoft.Identity.Client (MSAL) library with ClientSecretCredential and a client secret stored in App Service application settings.
Why it's wrong here
ClientSecretCredential requires a client secret, which the scenario explicitly forbids storing in code or configuration. Even if the secret were referenced from Key Vault, the requirement is to avoid storing credentials. Managed identity is the correct credential-free mechanism, so this approach does not meet the stated constraint.
- ✗
Use the Azure App Configuration client library to retrieve a pre-generated bearer token stored as a key-value pair.
Why it's wrong here
App Configuration is a configuration store, not a token issuer. Storing a bearer token there would still be storing a credential and would also expire quickly, requiring rotation. It does not use the managed identity to obtain a token and therefore fails the requirement to avoid credentials and to work without a signed-in user.
- ✓
Use DefaultAzureCredential from the Azure.Identity library and call GetTokenAsync with the downstream service scope.
Why this is correct
DefaultAzureCredential automatically discovers the managed identity when running in Azure App Service. It uses the token endpoint exposed by the App Service platform, so no secret is stored. Calling GetTokenAsync with the downstream API scope returns a valid access token that can be attached as a Bearer header, satisfying the requirement without credentials in configuration.
- ✗
Use the Azure App Service Authentication (Easy Auth) feature and read the X-MS-TOKEN-AAD-ACCESS-TOKEN header from the incoming request.
Why it's wrong here
Easy Auth handles inbound authentication of callers, not outbound token acquisition for downstream APIs. The X-MS-TOKEN-AAD-ACCESS-TOKEN header is populated from the caller's token, not a token for a downstream service. This does not provide a credential-free way for the API itself to obtain a token for another resource.
Go deeper
Related to this question
Learn chapter
Azure OpenAI Service for Developers
Key term
Key Vault Secrets
Key Vault Secrets are secure containers in Microsoft Azure that store sensitive information like passwords, connection strings, and API keys, keeping them encrypted and accessible only to authorized applications and users.
Key term
Managed identity
A managed identity is an automatically managed service principal in Azure that allows your code to authenticate to any service that supports Microsoft Entra ID authentication without storing credentials.
About these practice questions
This AZ-204 question is part of Courseiva's 883-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.