Courseiva

AZ-204 Practice Question: Connect to and consume Azure services and third-party services

Your company wants to send email notifications to users via a third-party email service (SendGrid) from an Azure Logic App. What is the recommended way to securely store the SendGrid API key?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Store the API key in Azure Key Vault and use a managed identity to retrieve it

Azure Key Vault securely stores secrets and can be accessed by Logic Apps via managed identity, providing the most secure and recommended approach. Option B is wrong because app settings are less secure and can be exposed in configuration files or logs. Option C is wrong because hardcoding secrets in workflow definitions is insecure and violates best practices. Option D is wrong because environment variables are not specifically designed for secret management and lack the security controls of Key Vault.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Store the API key in Azure Key Vault and use a managed identity to retrieve it

    Why this is correct

    Azure Key Vault stores the SendGrid API key as a protected secret, and the Logic App's managed identity authenticates to Key Vault without embedding credentials in the workflow definition. This satisfies the requirement to avoid hard-coded secrets while enabling secure retrieval.

  • ✗

    Store the API key in an App Setting of the Logic App

    Why it's wrong here

    App Settings are plain-text configuration values readable by anyone with access to the Logic App's configuration, so the API key is not encrypted at rest. Key Vault is the correct store. App Settings suit non-sensitive parameters such as endpoint URLs or feature flags.

  • ✗

    Hardcode the API key in the Logic App workflow definition

    Why it's wrong here

    Hardcoding places the key in the workflow definition, where it is visible in code, run history and source control, and cannot be rotated without editing the workflow. Key Vault stores and rotates secrets securely. Hardcoding suits non-sensitive constants, never credentials.

  • ✗

    Store the API key in an environment variable on the integration service environment

    Why it's wrong here

    An integration service environment is an isolated deployment host, not a secrets store; environment variables there remain unencrypted and visible to operators. Key Vault provides the encryption and access control required. ISE variables suit environment-specific settings, not credentials.

Go deeper

Related to this question

About these practice questions

Courseiva writes every AZ-204 question from scratch — 883 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.