Courseiva

SC-100 Practice Question: Design security solutions for applications and data

A startup, Alpine Ski House, is developing a mobile app that allows users to book ski lessons. The app communicates with an Azure Function App backend via REST APIs. The function app stores data in Azure Cosmos DB. The company wants to secure the API endpoints using OAuth 2.0 with Microsoft Entra ID and ensure that only authenticated users can invoke the functions. The function app should also use a managed identity to access Cosmos DB. Which of the following configurations should you implement?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the function app to require authentication with Microsoft Entra ID, enforce HTTPS only, and use a system-assigned managed identity to access Cosmos DB.

It uses OAuth 2.0 with Entra ID for authentication, managed identity for database access, and enforces HTTPS. Option B is wrong because function keys are not secure for user authentication. Option C is wrong because client certificates do not provide user-level authentication. Option D is wrong because IP whitelisting is not a substitute for authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure the function app to require authentication with Microsoft Entra ID, enforce HTTPS only, and use a system-assigned managed identity to access Cosmos DB.

    Why this is correct

    Requiring Microsoft Entra ID authentication in the function app enables the OAuth 2.0 authorization code flow with OpenID Connect, so the mobile app's users are authenticated via tokens that the function app validates. Enforcing HTTPS-only ensures all API traffic is cryptographically protected in transit. Using a system-assigned managed identity gives the function app a dedicated Microsoft Entra ID identity to authenticate to Cosmos DB and grants least-privilege role-based access without storing or rotating database keys in code or configuration.

  • ✗

    Configure the function app to use function-level authorization keys, enforce HTTPS only, and use a connection string with a read-write key to access Cosmos DB.

    Why it's wrong here

    Function-level authorization keys (host or function keys) are shared static secrets that identify the calling client API, not the individual end user, so they cannot provide OAuth 2.0 or user-specific authorization. Storing a Cosmos DB connection string with a read-write key in application settings exposes a high-privilege key and fails to leverage Microsoft Entra ID managed identities, creating a broader blast radius if leaked. While HTTPS-only is useful, the lack of true user authentication and the use of key-based database access make this configuration insecure for a user-facing mobile app.

  • ✗

    Configure the function app to require client certificates, enforce HTTPS only, and use a managed identity to access Cosmos DB.

    Why it's wrong here

    Mutual TLS client certificates authenticate the device or application presenting the certificate, not the end user who is using the mobile app, so they do not fulfill the requirement for user identity or OAuth 2.0 tokens. Certificate enrollment and rotation on mobile clients is operationally complex, and the function app would still need a separate method to map a certificate to a user principal. Although managed identity secures Cosmos DB access, it does nothing to provide user-level authentication, leaving the app unable to enforce identity-based authorization.

  • ✗

    Configure the function app to use IP whitelisting, enforce HTTPS only, and use a managed identity to access Cosmos DB.

    Why it's wrong here

    IP whitelisting restricts incoming connections to a set of pre-defined source IP addresses, which is ineffective for mobile apps because users' IPs change frequently and are often shared via NAT or carrier-grade proxies. It does not authenticate a user or a client identity, nor does it issue any OAuth 2.0 tokens, so the function app cannot determine who is calling. Whitelisting can be bypassed by spoofed IPs or by compromising any allowed endpoint, and it adds no per-user security; the managed identity only protects the database connection, not the user-facing API.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.