Courseiva

SC-100 Design security solutions for infrastructure Practice Question

You are designing a security solution for Azure API Management. The requirements include: protecting APIs from abuse, throttling requests, and validating JSON payloads. Which combination of features should you use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Rate limiting policies, validate-json policy, and OAuth 2.0

API Management natively provides rate limiting and quota policies to throttle requests and protect against abuse, the validate-json policy to validate JSON payloads against a schema, and OAuth 2.0 support to secure API access via authorization servers. These features directly satisfy the stated requirements within the APIM gateway itself. Option A addresses identity and authentication but does not provide throttling or JSON schema validation. Option B offloads protection to Application Gateway WAF, which handles web attack patterns but not APIM-level rate limiting or JSON payload schema validation. Option D provides network-layer filtering with Azure Firewall and NSGs, which cannot inspect JSON payloads or apply API-level throttling.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Managed Identities and Microsoft Entra ID authentication

    Why it's wrong here

    Managed identities in Azure API Management are used to authenticate outbound calls to Azure resources like Key Vault or Storage, and when combined with Microsoft Entra ID they can authenticate incoming requests via OAuth 2.0. However, they only establish identity and access control; they do not perform per-API rate limiting or JSON payload validation. The correct design must add throttling policies, validate-json, and explicit OAuth 2.0 authorization to meet all three requirements.

  • ✗

    Azure Web Application Firewall (WAF) on Application Gateway

    Why it's wrong here

    Azure Web Application Firewall on Application Gateway runs at Layer 7 and protects against OWASP Top 10 attacks such as SQL injection and cross-site scripting using managed rule sets. It cannot enforce per-API or per-subscription rate limits, and it does not inspect the JSON body against a custom schema, nor does it validate OAuth 2.0 tokens or scopes. WAF is a complementary edge protection layer, but it does not replace API Management policies.

  • ✓

    Rate limiting policies, validate-json policy, and OAuth 2.0

    Why this is correct

    The correct combination applies API Management inbound policies in sequence: rate-limit or quota policies throttle requests per subscription, key, or IP address; validate-json verifies the JSON request body against a defined schema and rejects malformed payloads; and OAuth 2.0 with validate-jwt ensures access tokens are signed, unexpired, and carry the required scopes. Together these policies directly satisfy throttling, validation, and secure access control at the API gateway level.

  • ✗

    Azure Firewall and Network Security Groups

    Why it's wrong here

    Azure Firewall and Network Security Groups filter traffic based on IP addresses, ports, and protocols, establishing network-layer segmentation and blocking malicious flows. They cannot parse application-level API parameters such as subscription keys, JSON schemas, or per-API request rates, and they cannot verify JWT signatures or enforce OAuth 2.0 claims. Even with a firewall in place, API-specific throttling and validation must be implemented in API Management policies.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.