Microsoft Cybersecurity Architect (SC-100)Design security for infrastructureMedium

An organization is migrating a financial application that uses a custom database to Azure. The application's security model dictates that database access credentials, API keys, and other secrets must be stored in a highly secure, centralized repository that is isolated from the public internet. The application must connect to this repository over a private, secure channel, and only authorized Azure resources should be able to retrieve secrets. Which Azure service and connectivity method should be used?

  1. AAzure Key Vault accessible via a public endpoint with network security groups (NSGs)
  2. BAzure Storage Account for secrets with Virtual Network service endpoints
  3. CAzure Key Vault with Azure Private Link
  4. DAzure App Configuration with managed identities
Show answer & explanation

Correct answer: C. Azure Key Vault with Azure Private Link

Azure Key Vault provides a secure repository for secrets, and Azure Private Link allows Azure resources to connect to Key Vault privately and securely over the Microsoft backbone network, isolating it from the public internet and ensuring only authorized resources can access it.

Why the other options are wrong

  • A. Public endpoint with NSGs still exposes Key Vault to the internet, albeit with filtering, which doesn't meet the 'isolated from the public internet' requirement.
  • B. Azure Storage Account is not designed for secret management and may not meet the security isolation requirements for cryptographic keys and secrets.
  • D. Azure App Configuration is for application settings, not highly sensitive secrets like database credentials, and managed identities are for authentication, not for providing private connectivity to the secret store itself.

Azure Private Link for PaaS

Azure Private Link enables you to access Azure PaaS services (like Azure Storage and Azure Key Vault) over a private endpoint in your virtual network. Traffic between your VNet and the service travels across the Microsoft backbone network, eliminating exposure to the public internet.

  • Connects to Azure PaaS services privately.
  • Traffic stays on the Microsoft backbone network.
  • Eliminates public internet exposure.
  • Enhances security by providing dedicated private access.

Memory trick: Private Link Leads to Isolated PaaS, Public Endpoints Have Risks.

More Design security for infrastructure questions