Courseiva

SC-100 Practice Question: Design security solutions for applications and data

A healthcare provider is building a new patient portal on Azure App Service. The portal calls a backend API hosted on Azure Functions. The security team requires that the API accept requests only from the portal, that the portal prove its identity to the API without storing secrets in code or configuration, and that the credentials rotate automatically. You need to recommend an authentication approach for the portal-to-API call. What should you recommend?

⚠ Common exam trap

The trap here is treating Key Vault as a complete answer to 'no secrets,' when the portal still has to possess and rotate a credential to reach the vault and the API.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable a system-assigned managed identity on the App Service and use it to request an access token for the Azure Functions app.

The cleanest way for one Azure compute resource to authenticate to another without secrets is a managed identity. The App Service obtains a Microsoft Entra ID token for the Functions app's audience, and the Functions app validates the token and authorizes the specific identity. The credential lifecycle is handled by the platform, which satisfies the automatic rotation requirement and eliminates secret sprawl.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store a client secret in Azure Key Vault and have the portal retrieve it at runtime to call the API.

    Why it's wrong here

    Key Vault removes secrets from source code but the portal still handles a long-lived secret and must be granted access to the vault, expanding the attack surface. Secrets must be rotated manually or via automation, and any compromise of the portal's vault access exposes the API credential. This does not meet the no-secret and auto-rotation requirements.

  • ✗

    Issue each portal instance a client certificate and configure mutual TLS between App Service and Azure Functions.

    Why it's wrong here

    Mutual TLS can authenticate the caller, but managing certificate issuance, distribution, and rotation for App Service adds significant operational burden and does not use the platform's identity system. It also does not produce a token the Functions app can use for fine-grained authorization, so it is a weaker fit than a managed identity.

  • ✓

    Enable a system-assigned managed identity on the App Service and use it to request an access token for the Azure Functions app.

    Why this is correct

    A system-assigned managed identity lets App Service obtain Microsoft Entra ID tokens without any secret in code or configuration, and the underlying credential is rotated by the platform. Azure Functions can validate the token and restrict callers to the portal's identity, satisfying both the no-secret and auto-rotation requirements.

  • ✗

    Configure IP restrictions on the Azure Functions app to allow only the App Service outbound IP addresses.

    Why it's wrong here

    IP allowlisting restricts network origin but does not authenticate the caller; any workload sharing those egress addresses could call the API. It also fails the requirement that the portal prove its identity, and outbound IPs can change with scale or slot swaps, making the allowlist brittle and insecure.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.