AZ-305 Design infrastructure solutions Practice Question
You are designing a solution to securely store and manage secrets for multiple applications deployed in Azure. The solution must support automated rotation of secrets and provide audit logging. Which Azure service should you use?
⚠ Common exam trap
Candidates often confuse 'Key Vault references' (which only retrieve secrets at runtime) with the full secret management lifecycle (which includes automated rotation and audit logging), leading them to select Option B instead of the comprehensive solution in Option C.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Key Vault with managed identity and rotation policy
Azure Key Vault with a managed identity and a rotation policy is the correct choice because it provides a centralized, secure store for secrets, supports automated rotation via built-in policies or custom logic, and integrates with Azure Monitor for audit logging. Managed identities eliminate the need for hard-coded credentials, and the rotation policy ensures secrets are automatically updated without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra ID application registration
Why it's wrong here
Microsoft Entra ID application registration is fundamentally an identity construct, not a secret storage service; while it can hold client secrets, those secrets lack dedicated rotation policies, versioning, or fine-grained access control, and are instead tied to the application object with a fixed validity period that requires manual renewal or custom automation to rotate, making it unsuitable for securely managing stored secrets at scale.
- ✗
Azure App Service Key Vault references
Why it's wrong here
Azure App Service Key Vault references are a consumption feature that merely allow an App Service to retrieve a secret from Key Vault at runtime and inject it as an app setting; they do not create, update, or rotate the underlying secret, and rotation must be handled separately by Key Vault itself or an external process, so while references simplify connectivity, they cannot be the mechanism that manages secret rotation or lifecycle.
- ✓
Azure Key Vault with managed identity and rotation policy
Why this is correct
Azure Key Vault with a managed identity and an enabled rotation policy is the correct choice because it natively supports secret lifecycle management: the rotation policy automatically creates new versions of the secret on a schedule or by proximity to expiry, the managed identity provides secure, passwordless authentication for workloads to access those secrets without embedding credentials, and Key Vault's diagnostic settings enable audit logging of all secret operations for compliance and monitoring.
- ✗
Azure Automation with PowerShell runbooks
Why it's wrong here
Azure Automation with PowerShell runbooks can rotate secrets, but this approach requires you to write and maintain custom scripts to generate new values, update the secret in Key Vault, and potentially restart dependent applications; it also lacks built-in rotation policy integration, necessitating additional scheduling, error handling, and logging infrastructure, making it a feasible but operationally heavy alternative rather than a first-party managed rotation solution.
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.