Courseiva

SC-100 Practice Question: Design security solutions for applications and data

Your organization uses Azure API Management (APIM) to expose APIs to external partners. You need to ensure that only authorized partners can access the APIs and that the API requests are rate-limited to prevent abuse. What should you implement?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a validate JWT policy to authenticate partners and a rate-limit by key policy to control request rates.

In Azure API Management, the validate-jwt policy validates OAuth 2.0/JWT bearer tokens issued by an identity provider (such as Microsoft Entra ID), ensuring only authorized partners with valid tokens can call the APIs, while the rate-limit-by-key policy throttles requests based on a key such as the subscription key or a claim (e.g., partner ID), directly preventing abuse. Together these policies satisfy both the authentication and rate-limiting requirements within the APIM policy pipeline. Option B does not fit because client certificate authentication alone does not provide token-based authorization and a global rate limit applies to all callers rather than per-partner, so one partner could exhaust the quota. Option C is insufficient because a subscription key is a shared secret that can be leaked and IP whitelisting is brittle and does not enforce per-partner request limits. Option D is incomplete because OAuth 2.0 tokens and Key Vault key storage address credential handling but do not themselves implement rate limiting in APIM.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use a validate JWT policy to authenticate partners and a rate-limit by key policy to control request rates.

    Why this is correct

    Validate JWT policy ensures that only requests carrying a valid JSON Web Token signed by a trusted identity provider reach the API, thereby authenticating each partner's identity. The rate-limit-by-key policy then uses the subscription key as the scope to apply per-partner request quotas, preventing any single partner from consuming all available capacity. This combination provides both secure identity verification and granular throttling, which is exactly what an API exposure to partners requires.

  • ✗

    Configure client certificate authentication and set a global rate limit in the APIM service.

    Why it's wrong here

    Client certificate authentication provides strong mutual TLS, but applying a global rate limit at the APIM service level lacks granularity for individual partners. If one partner exceeds the aggregate limit, all partners experience throttling, effectively creating a single point of failure. Furthermore, managing and distributing client certificates to many external partners adds significant operational overhead compared to token-based authentication, and a global limit cannot differentiate between high-traffic and low-traffic partners.

  • ✗

    Require a subscription key for each partner and configure IP whitelisting.

    Why it's wrong here

    Subscription keys are static shared secrets that can be easily compromised and used repeatedly without true identity verification, so they are not a secure authentication method for partners. IP whitelisting is inflexible because partners often have dynamic IP ranges, and it only checks the source network address rather than authenticating the caller. This approach would block legitimate partners when their IP changes and would not reliably protect the API if a key is leaked, making it an inadequate security solution.

  • ✗

    Use OAuth 2.0 tokens and store partner API keys in Azure Key Vault.

    Why it's wrong here

    OAuth 2.0 is a sound authentication framework, but pairing it with API keys stored in Key Vault is conceptually inconsistent because API keys are not part of the OAuth token flow. APIM can directly validate OAuth 2.0 access tokens (JWT) via the validate-jwt policy without the need to fetch partner API keys from an external vault, which adds latency and complexity. Storing API keys in Key Vault is good hygiene, but it does not solve the authentication problem; instead, you should use JWT validation for identity and subscription keys only for rate limiting.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.