Courseiva
Manage identity and access →mediumMultiple Select

AZ-500 Manage identity and access Practice Question

A managed identity is used by an Azure Function to access Key Vault. Which two configurations are required?

⚠ Common exam trap

A common mix-up: candidates assume a client secret (Option A) is required for any Microsoft Entra ID authentication, failing to recognize that managed identities provide a passwordless, credential-free authentication mechanism via Microsoft Entra ID tokens.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A system-assigned or user-assigned managed identity enabled on the function app

A managed identity (either system-assigned or user-assigned) provides an Microsoft Entra ID-authenticated identity for the function app, eliminating the need for credentials like client secrets. This identity is used to obtain an Microsoft Entra ID access token for authenticating to Key Vault. Option D is also required because the managed identity must be granted explicit Key Vault permissions (e.g., via an access policy or RBAC role) to read secrets; without these permissions, token-based authentication will fail with a 403 Forbidden error.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A client secret stored in the function app settings

    Why it's wrong here

    A client secret stored in the function app settings does not use a managed identity; it is a manually managed credential that must be rotated and protected in configuration. This approach still requires handling a secret, whereas the stated requirement is to authenticate via an Microsoft Entra ID managed identity, so it fails the core requirement and introduces a security risk.

  • ✓

    A system-assigned or user-assigned managed identity enabled on the function app

    Why this is correct

    Enabling a system-assigned or user-assigned managed identity on the function app creates an Microsoft Entra ID identity automatically managed by Azure and tied to the app's lifecycle. The function can then request an access token from the Azure Instance Metadata Service (IMDS) endpoint without any stored secrets, which is exactly the mechanism required to securely authenticate to an Azure key vault.

  • ✗

    A public IP address on the function app

    Why it's wrong here

    A public IP address on the function app is a network-level attribution, not an identity; it cannot authenticate to Azure Key Vault or prove that the request comes from that specific function's managed identity. Even if you restrict the Key Vault firewall by IP address, the function still lacks a credential or token for authentication, so this fails the requirement entirely.

  • ✓

    Key Vault permissions granted to that managed identity

    Why this is correct

    Granting Key Vault permissions to that managed identity is an essential companion step: without an access policy or an RBAC role such as 'Key Vault Secrets User,' the enabled managed identity will receive a 403 Forbidden when attempting to read the key. This authorization step binds the principal (the managed identity) to a specific data plane action, making it correct as part of the overall solution, though it is not the enabling step itself.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.