Courseiva

Signing a .NET Assembly Using a Certificate Stored in Key Vault

You are designing a release pipeline for a .NET Core application that must comply with regulatory requirements. The pipeline must sign the assembly with a code-signing certificate stored in Azure Key Vault. Which THREE actions should you perform?

Quick Answer

Three steps make this work end to end: grant the pipeline's service principal access to Key Vault so it can retrieve the certificate, use the AzureKeyVault task to download it, and run a script step with signtool.exe to actually sign the assembly — the certificate itself should stay in Key Vault rather than being extracted into the build artifact.

⚠ Common exam trap

AZ-400 often tests whether candidates confuse 'storing the certificate in a secure file' (a legacy, non-compliant pattern) with the modern Key Vault task approach, and whether they understand signing must occur post-build but pre-packaging.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a step to download the certificate from Key Vault using the AzureKeyVault task.

Option A is correct because the AzureKeyVault task (AzureKeyVault@2) is the supported pipeline task for retrieving secrets, including a code-signing certificate, from an Azure Key Vault so the certificate can be used during the build. Option B is correct because after the assembly is built, a script or command-line step must invoke a signing tool such as signtool.exe with the certificate to apply the code-signing signature to the .NET Core assembly. Option C is correct because the Azure Pipelines service principal (or the identity running the pipeline) must be granted access to the Key Vault, typically via an access policy or Azure RBAC role such as Key Vault Secrets User, otherwise the AzureKeyVault task cannot retrieve the certificate. Option D is not correct because storing the certificate in a secure file in the build artifact does not satisfy the requirement to use a certificate stored in Azure Key Vault and can expose the private key in the artifact. Option E is not correct because packaging before signing would leave the package unsigned; signing must occur on the assembly before it is packaged so the signature is included in the final artifact.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Add a step to download the certificate from Key Vault using the AzureKeyVault task.

    Why this is correct

    The AzureKeyVault task retrieves the code-signing certificate from Key Vault into the pipeline agent, making it available to the signing step. This satisfies the regulatory requirement that the certificate stays in Key Vault rather than being stored insecurely in the repository.

  • ✓

    Use a script task to invoke the signing tool (e.g., signtool.exe) after the build.

    Why this is correct

    Invoking signtool.exe via a script task performs the actual cryptographic signing of the assembly after compilation. Downloading the certificate alone does not sign anything, so this step satisfies the regulatory requirement that the built assembly carries a valid code-signing signature.

  • ✓

    Grant the Azure Pipelines service principal access to the Key Vault.

    Why this is correct

    The pipeline's service principal needs explicit access permissions on the Key Vault, otherwise the AzureKeyVault task cannot retrieve the certificate. Granting that access satisfies the compliance constraint by enabling secure, auditable retrieval without embedding secrets in the pipeline.

  • ✗

    Store the certificate in a secure file in the build artifact.

    Why it's wrong here

    A secure file is a pipeline-library artefact, not a signing mechanism, and it exposes the certificate outside Key Vault, breaking the regulatory requirement. Secure files suit storing generic secrets or scripts; code signing needs the Azure Key Vault task, which signs using the vault-held certificate.

  • ✗

    Package the application before signing to avoid signature corruption.

    Why it's wrong here

    Packaging before signing leaves the assembly unsigned at build time, so the code-signing certificate in Key Vault never applies to the compiled output. Packaging is genuinely required when producing deployable artefacts such as NuGet packages or zip archives, but signing must occur on the assembly itself, after compilation and before packaging.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 696 original AZ-400 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on AZ-400

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your team uses Azure Pipelines for CI/CD. You need to enforce that all builds sign the assemblies with a code signing certificate stored in Azure Key Vault. What is the recommended approach?

medium
  • A.Store the certificate as a secure file in the pipeline library and use the 'Download Secure File' task.
  • B.Embed the certificate in the repository and use a script to sign.
  • ✓ C.Use the 'Azure Key Vault' task to download secrets and then a 'PowerShell' task to sign.
  • D.Use the 'Azure CLI' task to retrieve the certificate and then sign.

Why C: The recommended approach is to use the Azure Key Vault task to download the certificate as a secret into the pipeline, then use a PowerShell (or similar) task to sign the assemblies. This keeps the certificate out of the repository and leverages Key Vault's access controls and auditing.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.