SC-100 Practice Question: Design security solutions for applications and data
You are designing security for a web application that will be developed by an external vendor. The vendor will have access to the source code repository and the development environment. You need to ensure that no secrets (e.g., API keys, connection strings) are stored in the source code. What is the best approach to manage secrets for this application?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Azure Key Vault to store secrets and configure the application to use managed identity to retrieve them.
Using Azure Key Vault to store secrets and referencing them from the application is the standard best practice. The application can use managed identity to authenticate to Key Vault securely. Storing secrets in app settings is not secure if the repository is accessible. Using environment variables is better but still not as secure as Key Vault. Hardcoding is unacceptable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use Azure Key Vault to store secrets and configure the application to use managed identity to retrieve them.
Why this is correct
Azure Key Vault provides centralized, hardware-backed secret storage with granular access policies and full audit logging. Pairing it with a managed identity means the application authenticates to Microsoft Entra ID using a workload identity token, never needing a secret or connection string in code or configuration. This enables seamless secret rotation and supports the zero-standing-credentials principle, making it the only option that meets cloud-native security best practices.
- ✗
Store secrets in environment variables on the application server.
Why it's wrong here
Environment variables are stored as plaintext in the process memory block of the application server and are readable by any process running under the same user context. They are also visible in configuration dumps, crash reports, and debugging tools, and they lack audit trails, versioning, and fine-grained access control. On shared or misconfigured servers, a single local file read vulnerability can expose every secret, making this approach fundamentally insecure.
- ✗
Store secrets in Azure App Service application settings encrypted at rest.
Why it's wrong here
App Service application settings are encrypted at rest but are automatically decrypted and injected as environment variables into the running application, meaning they are not secret to the runtime or to anyone with management-plane access. Anyone with Contributor or even Website Contributor permissions can view or modify these settings through the Azure portal, CLI, or ARM API, and there is no audit trail tied to secret reads. They also promote secrets being stored in IaC templates or deployment pipelines, increasing the attack surface.
- ✗
Embed secrets in the compiled code using obfuscation.
Why it's wrong here
Obfuscation only renames symbols and encodes strings; it does not encrypt secrets, and modern .NET, Java, and Python decompilers can reconstruct the original logic, allowing attackers to extract embedded keys and passwords. Compiling secrets into binaries also makes rotation impractical because each rotation requires a new build, regression testing, and release. Security through obscurity is explicitly not a control because the secret will be in memory and on disk in recoverable form.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-100
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization is designing a security solution for a new web application that will be deployed on Azure App Service. The application will access an Azure SQL Database and an Azure Storage account. The security requirements include: (1) use managed identities for authentication, (2) encrypt data at rest and in transit, (3) restrict network access to the database and storage account to only the App Service, and (4) use Azure Key Vault for secrets management. Which TWO of the following should you implement?
medium- A.Configure the App Service to use a connection string with a storage account access key.
- ✓ B.Configure private endpoints for the SQL Database and Storage account.
- ✓ C.Configure the App Service to use a system-assigned managed identity.
- D.Use shared access signatures (SAS) for the App Service to access the Storage account.
- E.Configure service endpoints for the SQL Database and Storage account.
Why B: Option B is correct because private endpoints assign a private IP address from your virtual network to the Azure SQL Database and Storage account, so those PaaS services are reachable only through the private link and public network access can be disabled, satisfying the requirement to restrict network access to only the App Service (when the App Service is VNet-integrated). Option C is correct because a system-assigned managed identity gives the App Service an identity in Microsoft Entra ID, allowing it to authenticate to Azure SQL Database and Storage without storing credentials, which directly fulfills the managed-identity authentication requirement. Option A is incorrect because using a storage account access key in a connection string relies on a shared secret rather than a managed identity and exposes a highly privileged key. Option D is incorrect because SAS tokens are shared secrets with delegated permissions, not managed-identity authentication, and they do not restrict network access to the App Service. Option E is incorrect because service endpoints only extend the VNet identity to the PaaS service over the Azure backbone; they do not give the SQL Database or Storage account a private IP, and the service still exposes a public endpoint, so they do not meet the strict 'only the App Service' network restriction as well as private endpoints do.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.