Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataEasy

A company is developing a new serverless application using Azure Functions. The application will process sensitive customer data and store it in an Azure SQL Database. The security architect needs to ensure that the Azure Functions can securely connect to the Azure SQL Database without exposing credentials in the function code or configuration. Which method should the architect recommend for secure database connectivity?

  1. AUse an Azure Key Vault secret to store the connection string and retrieve it at runtime using Managed Identity.
  2. BUse a public IP address whitelist on the Azure SQL Database firewall to allow Azure Function access.
  3. CEmbed the connection string directly in the Azure Function's C# code.
  4. DStore the SQL connection string in the Azure Function's application settings.
Show answer & explanation

Correct answer: A. Use an Azure Key Vault secret to store the connection string and retrieve it at runtime using Managed Identity.

Using Azure Key Vault with Managed Identity is the most secure method. Managed Identity provides an Azure Function with an AAD identity, allowing it to authenticate to Key Vault to retrieve the connection string without storing credentials anywhere visible.

Why the other options are wrong

  • B. While public IP whitelisting can restrict network access, it does not secure the credentials themselves and is less granular/dynamic than identity-based access.
  • C. Embedding credentials directly in code is a major security vulnerability and should never be done.
  • D. Storing connection strings in application settings is better than hardcoding, but still exposes them to anyone with access to the function's configuration.

Azure Managed Identities

Automatically managed identities in Azure Active Directory (AAD) that applications can use to authenticate to cloud services without needing to manage credentials.

  • Eliminate the need for developers to manage credentials.
  • Are securely stored in Azure AD.
  • Can be assigned to Azure resources like VMs, App Services, Azure Functions, etc.

Memory trick: Managed Identity + Key Vault = No Exposed Secrets.

More Design security for applications and data questions