AZ-305 Design infrastructure solutions Practice Question
Your company is deploying a web application on Azure App Service. The application must be able to read secrets from Azure Key Vault without storing credentials in application code. Which feature should you enable?
⚠ Common exam trap
Many exam-takers confuse App Service Authentication/Authorization (EasyAuth) with Managed Identity, but EasyAuth is for user authentication, not for the app's own identity to access Azure resources like Key Vault.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Managed Identity
Managed Identity (C) is correct because it allows the App Service to authenticate to Azure Key Vault without storing any credentials in code or configuration. Azure automatically manages the identity lifecycle, and the app uses the Azure Identity SDK to obtain tokens for Key Vault access via the IMDS endpoint (169.254.169.254). This eliminates the need for secrets or certificates in the application.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Key Vault access policies
Why it's wrong here
Key Vault access policies are an authorization layer, not an authentication mechanism. They map Microsoft Entra ID principals (users, groups, service principals) to permissions such as `get`, `list`, and `set` for secrets, keys, and certificates. However, the App Service still needs its own Microsoft Entra ID identity to obtain a token before those permissions can be evaluated; access policies alone do not provision or configure that identity. Therefore, choosing this option leaves the fundamental authentication problem unresolved.
- ✗
Microsoft Entra ID Application Registration with client secret
Why it's wrong here
Microsoft Entra ID Application Registration with a client secret does create a service principal that could be used to acquire a token for Key Vault, but it forces you to store the secret in App Service configuration settings. This approach introduces credential sprawl, secret rotation overhead, and an increased risk of leakage because the secret can appear in logs, source code, or backup snapshots. Managed identity avoids these pitfalls by eliminating the client secret entirely, which is why this option is not recommended.
- ✓
Managed Identity
Why this is correct
Managed Identity is correct because it gives the App Service an Microsoft Entra ID-backed service principal that is automatically created and managed by Azure. The application retrieves a token from the Azure Instance Metadata Service (IMDS) endpoint without any secrets in code or configuration. After enabling the identity, you simply grant it read (`list` and `get`) permissions on the Key Vault via an access policy or RBAC, and the runtime calls Key Vault with that identity. This is the recommended Azure pattern for passwordless, secure access between Azure resources.
- ✗
App Service Authentication / Authorization
Why it's wrong here
App Service Authentication/Authorization (EasyAuth) is an inbound feature that validates tokens presented by the end user's browser or client to protect the app's routes. It does nothing to alter the outbound identity that the application uses when calling downstream services like Key Vault. Even when you enable EasyAuth, the app still runs under the original managed identity or service principal, and outbound token acquisition is unaffected. Thus, this option is irrelevant to the requirement of authenticating the app itself to Key Vault.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.