Signing a .NET Assembly Using a Certificate Stored in Key Vault
You are designing a release pipeline for a .NET Core application that must comply with regulatory requirements. The pipeline must sign the assembly with a code-signing certificate stored in Azure Key Vault. Which THREE actions should you perform?
Quick Answer
Three steps make this work end to end: grant the pipeline's service principal access to Key Vault so it can retrieve the certificate, use the AzureKeyVault task to download it, and run a script step with signtool.exe to actually sign the assembly — the certificate itself should stay in Key Vault rather than being extracted into the build artifact.
⚠ Common exam trap
AZ-400 often tests whether candidates confuse 'storing the certificate in a secure file' (a legacy, non-compliant pattern) with the modern Key Vault task approach, and whether they understand signing must occur post-build but pre-packaging.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a step to download the certificate from Key Vault using the AzureKeyVault task.
Option A is correct because the AzureKeyVault task (AzureKeyVault@2) is the supported pipeline task for retrieving secrets, including a code-signing certificate, from an Azure Key Vault so the certificate can be used during the build. Option B is correct because after the assembly is built, a script or command-line step must invoke a signing tool such as signtool.exe with the certificate to apply the code-signing signature to the .NET Core assembly. Option C is correct because the Azure Pipelines service principal (or the identity running the pipeline) must be granted access to the Key Vault, typically via an access policy or Azure RBAC role such as Key Vault Secrets User, otherwise the AzureKeyVault task cannot retrieve the certificate. Option D is not correct because storing the certificate in a secure file in the build artifact does not satisfy the requirement to use a certificate stored in Azure Key Vault and can expose the private key in the artifact. Option E is not correct because packaging before signing would leave the package unsigned; signing must occur on the assembly before it is packaged so the signature is included in the final artifact.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Add a step to download the certificate from Key Vault using the AzureKeyVault task.
Why this is correct
The AzureKeyVault task retrieves the code-signing certificate from Key Vault into the pipeline agent, making it available to the signing step. This satisfies the regulatory requirement that the certificate stays in Key Vault rather than being stored insecurely in the repository.
- ✓
Use a script task to invoke the signing tool (e.g., signtool.exe) after the build.
Why this is correct
Invoking signtool.exe via a script task performs the actual cryptographic signing of the assembly after compilation. Downloading the certificate alone does not sign anything, so this step satisfies the regulatory requirement that the built assembly carries a valid code-signing signature.
- ✓
Grant the Azure Pipelines service principal access to the Key Vault.
Why this is correct
The pipeline's service principal needs explicit access permissions on the Key Vault, otherwise the AzureKeyVault task cannot retrieve the certificate. Granting that access satisfies the compliance constraint by enabling secure, auditable retrieval without embedding secrets in the pipeline.
- ✗
Store the certificate in a secure file in the build artifact.
Why it's wrong here
A secure file is a pipeline-library artefact, not a signing mechanism, and it exposes the certificate outside Key Vault, breaking the regulatory requirement. Secure files suit storing generic secrets or scripts; code signing needs the Azure Key Vault task, which signs using the vault-held certificate.
- ✗
Package the application before signing to avoid signature corruption.
Why it's wrong here
Packaging before signing leaves the assembly unsigned at build time, so the code-signing certificate in Key Vault never applies to the compiled output. Packaging is genuinely required when producing deployable artefacts such as NuGet packages or zip archives, but signing must occur on the assembly itself, after compilation and before packaging.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Designing a Release Pipeline
Key term
Service principal
A service principal is an identity created for an application or automated tool to access cloud resources securely without using a human user account.
Key term
Release pipeline
A Release pipeline is an automated sequence of steps that takes software from code commit to production deployment, ensuring quality and consistency.
About these practice questions
One of 696 original AZ-400 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on AZ-400
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your team uses Azure Pipelines for CI/CD. You need to enforce that all builds sign the assemblies with a code signing certificate stored in Azure Key Vault. What is the recommended approach?
medium- A.Store the certificate as a secure file in the pipeline library and use the 'Download Secure File' task.
- B.Embed the certificate in the repository and use a script to sign.
- ✓ C.Use the 'Azure Key Vault' task to download secrets and then a 'PowerShell' task to sign.
- D.Use the 'Azure CLI' task to retrieve the certificate and then sign.
Why C: The recommended approach is to use the Azure Key Vault task to download the certificate as a secret into the pipeline, then use a PowerShell (or similar) task to sign the assemblies. This keeps the certificate out of the repository and leverages Key Vault's access controls and auditing.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.