AZ-204 Implement Azure security Practice Question
You are developing an ASP.NET Core web API that is protected by Microsoft Entra ID. The API must validate incoming access tokens, and you need to ensure that tokens issued for a different API cannot be used. The API is registered in Microsoft Entra ID with an Application ID URI of api://contoso-inventory. Which validation should you implement in the token validation parameters?
⚠ Common exam trap
The trap here is validating only signature and expiration, which accepts any token from the tenant even if it was issued for a completely different API.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Validate the audience claim against the Application ID URI api://contoso-inventory and validate the issuer against the tenant's token issuer.
A protected API must validate both the audience and the issuer. The audience must match the API's Application ID URI so tokens issued for other APIs are rejected, and the issuer must match the tenant so tokens from other tenants are rejected. Signature and expiration checks alone are not sufficient.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Validate the audience claim against the Application ID URI api://contoso-inventory and validate the issuer against the tenant's token issuer.
Why this is correct
Validating the audience against the API's Application ID URI ensures the token was issued for this API and not another. Validating the issuer confirms the token came from the expected Microsoft Entra ID tenant. Together these checks prevent token reuse across APIs and reject tokens from other tenants, which is the correct validation for this scenario.
- ✗
Validate only the signature and expiration of the token, and trust any token signed by Microsoft Entra ID.
Why it's wrong here
Validating only signature and expiration is insufficient because a token issued for a different API in the same tenant would still validate. Such a token could be replayed against this API, violating the requirement to prevent cross-API token use. Audience and issuer validation are necessary additional checks to scope tokens to this specific API.
- ✗
Validate the issuer against the common endpoint that accepts any tenant, and skip audience validation.
Why it's wrong here
Using the common issuer endpoint allows tokens from any tenant, which is inappropriate for a single-tenant API and weakens trust. Skipping audience validation removes the check that the token was issued for this API, so tokens for other APIs could be accepted. This combination fails the requirement to prevent tokens issued for a different API from being used.
- ✗
Validate the audience against the client application's client ID instead of the API's Application ID URI.
Why it's wrong here
The audience claim in a token issued for an API is the API's identifier, not the client's ID. Validating against the client ID would reject legitimate tokens, because the client ID appears in the authorized party or app ID claim, not the audience. This misconfiguration would cause all valid calls to fail authentication.
Go deeper
Related to this question
About these practice questions
One of 883 original AZ-204 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.