Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataMedium
A software development company is building a new microservices-based application on Azure Kubernetes Service (AKS). The application processes customer orders and integrates with several third-party APIs. The security architect needs to design a strategy to manage secrets (API keys, database connection strings) for the microservices securely and to ensure that only authorized services can access these secrets. The solution must also support automatic secret rotation and provide an audit trail of secret access. Which Azure service is the most appropriate for this requirement?
- AEnvironment variables configured directly within the Kubernetes Deployment manifests.
- BAzure Storage Account with Shared Access Signatures (SAS) for secret files.
- CAzure Key Vault integrated with AKS and Azure Active Directory (AAD) Pod Identity or Workload Identity.
- DAzure App Configuration with feature flags for secret management.
Show answer & explanationAnswer & explanation
Correct answer: C. Azure Key Vault integrated with AKS and Azure Active Directory (AAD) Pod Identity or Workload Identity.
Azure Key Vault is purpose-built for secure secret management, offering integration with AKS via AAD Pod Identity or Workload Identity for secure access, automatic rotation, and comprehensive auditing capabilities.
Why the other options are wrong
- A. Storing secrets as environment variables in deployment manifests is highly insecure, as they are easily exposed and lack rotation or auditing features.
- B. Azure Storage Account is not designed for secret management; SAS tokens have limited lifespan and auditing capabilities are not as robust as Key Vault.
- D. Azure App Configuration is primarily for managing application settings and feature flags, not for sensitive secrets, although it can reference Key Vault secrets.
Azure Key Vault
A cloud service for securely storing and accessing secrets, keys, and certificates. It provides a centralized, hardened, high-availability solution for managing cryptographic keys and other secrets.
- Encrypts secrets at rest and in transit.
- Supports automatic secret rotation and versioning.
- Integrates with other Azure services for secure access (e.g., Managed Identities, AAD Pod Identity/Workload Identity).
Memory trick: Key Vault: Your Secret's Safe Haven in the Cloud.