SC-100 Practice Question: Design security solutions for applications and data
Your organization, Adatum, is migrating its on-premises applications to Azure. The applications include a legacy .NET Framework web app that uses Windows authentication and a modern ASP.NET Core API that uses OAuth 2.0. You need to design a secure solution for these applications using Azure App Service. The security requirements include: (1) enforce HTTPS only, (2) restrict access to the web app based on the user's corporate identity, (3) allow the API to access an Azure SQL Database using a managed identity. Which of the following is the correct design?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure both apps to enforce HTTPS only, configure the web app to use Microsoft Entra ID authentication, and configure the API to use a system-assigned managed identity to access Azure SQL Database.
Option D is correct because it satisfies all three requirements: enabling HTTPS-only on both apps enforces TLS, configuring the web app with Microsoft Entra ID authentication restricts access based on corporate identity, and using a system-assigned managed identity lets the API authenticate to Azure SQL Database without storing credentials. Managed identity works with Azure SQL via Entra ID authentication, so no password is needed in the connection string. Option A is wrong because Microsoft Entra Domain Services-based Windows authentication is not the recommended App Service approach and SQL authentication with a managed identity is contradictory. Option B is wrong because a username/password connection string does not use managed identity. Option C is wrong because client certificates do not provide corporate identity-based access and SQL authentication does not meet the managed identity requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the web app to use Windows authentication via Microsoft Entra Domain Services, and the API to use SQL authentication with a managed identity.
Why it's wrong here
SQL authentication with a managed identity is contradictory: managed identities authenticate through Microsoft Entra ID, not SQL logins, so requirement 3 fails. This pairing is tempting because managed identities are the goal, but they must be granted database access via Microsoft Entra authentication, not SQL credentials.
- ✗
Configure the web app to use Microsoft Entra ID authentication with a built-in policy, and the API to use a connection string with a username and password.
Why it's wrong here
A username-and-password connection string stored in app settings cannot use a managed identity, failing requirement 3 and exposing static secrets. Connection strings are the right approach only when the database does not support Microsoft Entra authentication or managed identities.
- ✗
Configure the web app to require client certificates for authentication, and the API to use a connection string with SQL authentication.
Why it's wrong here
Client certificates authenticate devices, not corporate user identities, so requirement 2 goes unmet; SQL authentication also bypasses the managed identity requirement. Certificate authentication suits B2B or machine-to-machine scenarios where issuing and validating certificates is feasible, not browser-based Windows-authenticated users.
- ✓
Configure both apps to enforce HTTPS only, configure the web app to use Microsoft Entra ID authentication, and configure the API to use a system-assigned managed identity to access Azure SQL Database.
Why this is correct
Enforcing HTTPS on both apps meets requirement one, Microsoft Entra ID authentication on the web app restricts access by corporate identity, and a system-assigned managed identity lets the API reach Azure SQL Database without stored secrets.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.