Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium
A software company is developing a new cloud-native application that will frequently interact with other microservices and databases within Azure. They want to simplify the management of secrets and credentials for these interactions, ensuring secure communication without hardcoding authentication details. Which identity solution provides a centralized, secure way to manage and access these secrets?
- AAzure Sentinel
- BManaged Identities for Azure Resources
- CAzure Active Directory (AAD) User Accounts
- DAzure Key Vault
Show answer & explanationAnswer & explanation
Correct answer: D. Azure Key Vault
Azure Key Vault is designed to securely store and manage cryptographic keys, secrets (like API keys and database connection strings), and certificates. It provides a centralized and secure solution for applications to retrieve credentials without hardcoding them.
Why the other options are wrong
- A. Azure Sentinel is a Security Information and Event Management (SIEM) solution, not for secret management.
- B. Managed Identities allow Azure resources to authenticate without managing credentials, but Key Vault is where those secrets would typically be stored if not directly using Managed Identities for service-to-service auth.
- C. AAD User Accounts are for human users, not for managing application secrets.
Azure Key Vault
A cloud service for securely storing and accessing secrets, cryptographic keys, and SSL/TLS certificates.
- Centralizes secret management.
- Reduces risk of accidental secret exposure.
- Integrates with Azure services and applications.
Memory trick: Key Vault: 'The safe for all your digital secrets in Azure.'