AZ-204 Practice Question: Connect to and consume Azure services and third-party services
Your company wants to send email notifications to users via a third-party email service (SendGrid) from an Azure Logic App. What is the recommended way to securely store the SendGrid API key?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Store the API key in Azure Key Vault and use a managed identity to retrieve it
Azure Key Vault securely stores secrets and can be accessed by Logic Apps via managed identity, providing the most secure and recommended approach. Option B is wrong because app settings are less secure and can be exposed in configuration files or logs. Option C is wrong because hardcoding secrets in workflow definitions is insecure and violates best practices. Option D is wrong because environment variables are not specifically designed for secret management and lack the security controls of Key Vault.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Store the API key in Azure Key Vault and use a managed identity to retrieve it
Why this is correct
Azure Key Vault stores the SendGrid API key as a protected secret, and the Logic App's managed identity authenticates to Key Vault without embedding credentials in the workflow definition. This satisfies the requirement to avoid hard-coded secrets while enabling secure retrieval.
- ✗
Store the API key in an App Setting of the Logic App
Why it's wrong here
App Settings are plain-text configuration values readable by anyone with access to the Logic App's configuration, so the API key is not encrypted at rest. Key Vault is the correct store. App Settings suit non-sensitive parameters such as endpoint URLs or feature flags.
- ✗
Hardcode the API key in the Logic App workflow definition
Why it's wrong here
Hardcoding places the key in the workflow definition, where it is visible in code, run history and source control, and cannot be rotated without editing the workflow. Key Vault stores and rotates secrets securely. Hardcoding suits non-sensitive constants, never credentials.
- ✗
Store the API key in an environment variable on the integration service environment
Why it's wrong here
An integration service environment is an isolated deployment host, not a secrets store; environment variables there remain unencrypted and visible to operators. Key Vault provides the encryption and access control required. ISE variables suit environment-specific settings, not credentials.
Go deeper
Related to this question
Learn chapter
API Management Developer Portal
Key term
Key Vault Secrets
Key Vault Secrets are secure containers in Microsoft Azure that store sensitive information like passwords, connection strings, and API keys, keeping them encrypted and accessible only to authorized applications and users.
Key term
Managed identity
A managed identity is an automatically managed service principal in Azure that allows your code to authenticate to any service that supports Microsoft Entra ID authentication without storing credentials.
About these practice questions
Courseiva writes every AZ-204 question from scratch — 883 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.