SC-100 Practice Question: Design security solutions for applications and data
A healthcare provider is building a new patient portal on Azure App Service. The portal calls a backend API hosted on Azure Functions. The security team requires that the API accept requests only from the portal, that the portal prove its identity to the API without storing secrets in code or configuration, and that the credentials rotate automatically. You need to recommend an authentication approach for the portal-to-API call. What should you recommend?
⚠ Common exam trap
The trap here is treating Key Vault as a complete answer to 'no secrets,' when the portal still has to possess and rotate a credential to reach the vault and the API.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable a system-assigned managed identity on the App Service and use it to request an access token for the Azure Functions app.
The cleanest way for one Azure compute resource to authenticate to another without secrets is a managed identity. The App Service obtains a Microsoft Entra ID token for the Functions app's audience, and the Functions app validates the token and authorizes the specific identity. The credential lifecycle is handled by the platform, which satisfies the automatic rotation requirement and eliminates secret sprawl.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store a client secret in Azure Key Vault and have the portal retrieve it at runtime to call the API.
Why it's wrong here
Key Vault removes secrets from source code but the portal still handles a long-lived secret and must be granted access to the vault, expanding the attack surface. Secrets must be rotated manually or via automation, and any compromise of the portal's vault access exposes the API credential. This does not meet the no-secret and auto-rotation requirements.
- ✗
Issue each portal instance a client certificate and configure mutual TLS between App Service and Azure Functions.
Why it's wrong here
Mutual TLS can authenticate the caller, but managing certificate issuance, distribution, and rotation for App Service adds significant operational burden and does not use the platform's identity system. It also does not produce a token the Functions app can use for fine-grained authorization, so it is a weaker fit than a managed identity.
- ✓
Enable a system-assigned managed identity on the App Service and use it to request an access token for the Azure Functions app.
Why this is correct
A system-assigned managed identity lets App Service obtain Microsoft Entra ID tokens without any secret in code or configuration, and the underlying credential is rotated by the platform. Azure Functions can validate the token and restrict callers to the portal's identity, satisfying both the no-secret and auto-rotation requirements.
- ✗
Configure IP restrictions on the Azure Functions app to allow only the App Service outbound IP addresses.
Why it's wrong here
IP allowlisting restricts network origin but does not authenticate the caller; any workload sharing those egress addresses could call the API. It also fails the requirement that the portal prove its identity, and outbound IPs can change with scale or slot swaps, making the allowlist brittle and insecure.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.