Courseiva
Develop for Azure storage →mediumMultiple Choice

AZ-204 Develop for Azure storage Practice Question

You are developing an Azure Web App that needs to access an Azure Storage account. The app must authenticate without storing credentials in code or configuration. You need to implement the solution using the latest Azure Identity library. What should you do?

⚠ Common exam trap

The trap here is thinking that storing a secret in Key Vault or using a SAS token is sufficient to avoid credentials in configuration, but those still involve managing a secret.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable managed identity for the Web App and use DefaultAzureCredential in the application code.

Managed identity provides an identity for the Azure Web App in Microsoft Entra ID, and DefaultAzureCredential automatically uses it to authenticate to Azure Storage. This eliminates the need to store any secrets in code or configuration. The other options involve storing or managing credentials, which does not meet the requirement. Using managed identity is the most secure and recommended approach for Azure-to-Azure authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable managed identity for the Web App and use DefaultAzureCredential in the application code.

    Why this is correct

    Enabling a system-assigned or user-assigned managed identity for the Azure Web App allows the app to authenticate to Azure Storage without any credentials in code or configuration. The DefaultAzureCredential class from the Azure Identity library automatically detects the managed identity when running in Azure and uses it to obtain a token. You then grant the managed identity the appropriate role (e.g., Storage Blob Data Contributor) on the storage account. This approach is secure, requires no secret management, and is the recommended practice for Azure-hosted applications.

  • ✗

    Use the storage account's primary key and store it in the Web App's application settings.

    Why it's wrong here

    Storing the storage account primary key in application settings is a common but less secure practice. The key is a shared secret that grants full access to the storage account, and if the app's configuration is compromised, the key is exposed. It also requires manual rotation. The scenario explicitly asks to avoid storing credentials in code or configuration. Managed identity with DefaultAzureCredential eliminates the need to store any secret, providing better security and manageability. Therefore, using the primary key does not meet the requirement.

  • ✗

    Generate a shared access signature (SAS) token and include it in the application configuration.

    Why it's wrong here

    A SAS token is a time-limited credential that grants specific permissions on storage resources. While it is more granular than the account key, it still needs to be stored in configuration and managed for expiration and rotation. The scenario requires avoiding credentials in configuration, and a SAS token is a credential. Managed identity with DefaultAzureCredential avoids storing any credential altogether. SAS tokens are useful for granting limited access to external clients, but they are not the best choice for an Azure-hosted app that can use managed identity.

  • ✗

    Create a service principal and store its client secret in Azure Key Vault, then retrieve it at runtime.

    Why it's wrong here

    Using a service principal with a client secret stored in Key Vault is a valid approach, but it still requires managing a secret and adding code to retrieve it from Key Vault. This adds complexity and potential for secret leakage. The Azure Identity library provides DefaultAzureCredential, which can automatically use managed identity when running in Azure, eliminating the need for secrets entirely. For an Azure Web App, managed identity is the most secure and simplest method. Storing secrets in Key Vault is better than hardcoding, but it is not the most streamlined solution for this scenario.

Go deeper

Related to this question

About these practice questions

This AZ-204 question is part of Courseiva's 883-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.