SC-100 Managed identity Practice Question
Your company is deploying a new AI-powered customer service chatbot using Azure OpenAI Service. The chatbot will access customer data stored in Azure Cosmos DB. The security team requires that all data in transit is encrypted, and that the chatbot only accesses data necessary for its function. Additionally, the chatbot must use managed identities to authenticate to Cosmos DB. You need to design the security architecture. Which combination of controls should you implement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable TLS enforcement on Cosmos DB. Use a managed identity for the chatbot and assign the Cosmos DB Built-in Data Reader role. Configure the chatbot to authenticate using the managed identity.
It enforces TLS for data in transit, uses a managed identity for authentication, and assigns the Cosmos DB Built-in Data Reader role to implement least privilege access. Option A is incorrect because IP restrictions alone do not provide authentication and the Account Reader role does not allow data access. Option B is incorrect because using a connection string exposes secrets and the Contributor role grants excessive permissions. Option D is incorrect because it uses a service principal instead of a managed identity, which is a requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Restrict network access to the chatbot's IP address. Use a system-assigned managed identity and assign the Cosmos DB Account Reader role.
Why it's wrong here
Restricting network access to the chatbot's IP address only limits the source of traffic; it does not prove that the caller is the chatbot or authorize it to read data. The Cosmos DB Account Reader role is an Azure RBAC role that gives read-only access to account metadata like throughput and region settings, not to documents in containers. Even with a system-assigned managed identity, the wrong role and lack of a data-plane permission path mean the chatbot cannot actually retrieve customer data.
- ✗
Use a connection string with the Cosmos DB account key and enforce TLS 1.2. Grant the chatbot's managed identity contributor role.
Why it's wrong here
Using a connection string with the Cosmos DB account key embeds a highly privileged credential in the chatbot's configuration, creating a serious secret-management and rotation burden, and it completely ignores the directive to authenticate with a managed identity. Granting the chatbot's managed identity Contributor role is an Azure Resource Manager role that applies to the Cosmos DB account's control plane, far exceeding the data read permission needed. This combination exposes both the master key and excessive management rights, making it insecure and non-compliant.
- ✓
Enable TLS enforcement on Cosmos DB. Use a managed identity for the chatbot and assign the Cosmos DB Built-in Data Reader role. Configure the chatbot to authenticate using the managed identity.
Why this is correct
Enabling TLS on Cosmos DB encrypts all data in transit, protecting the AI chatbot's queries and responses from interception. A system-assigned or user-assigned managed identity for the chatbot lets it authenticate to Microsoft Entra ID without storing any secrets in code or configuration. Assigning the Cosmos DB Built-in Data Reader role grants only read access to the actual data containers (the data plane), satisfying the function's read-only requirement while following least privilege.
- ✗
Use Microsoft Entra ID authentication with a service principal and assign the Cosmos DB Built-in Data Contributor role. Enforce TLS 1.2.
Why it's wrong here
Although Microsoft Entra ID authentication with a service principal avoids some of the risks of account keys, it still requires creating and securely managing a client secret or certificate, which contradicts the explicit requirement to use a managed identity. The Cosmos DB Built-in Data Contributor role allows write operations that the read-only chatbot does not need, violating least privilege. Enforcing TLS 1.2 only addresses transport encryption, not the authentication and authorization flaws.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.