Microsoft Azure Fundamentals (AZ-900)Describe Azure identity, security, and networkingMedium

A development team is building a new application that requires storing sensitive configuration data, such as API keys, database connection strings, and certificates. They need a centralized and secure service in Azure to manage these secrets, ensuring they are protected against unauthorized access and are easily retrievable by authorized applications. Which Azure service should they use?

  1. AAzure Storage Account
  2. BAzure SQL Database
  3. CAzure Key Vault
  4. DAzure Monitor
Show answer & explanation

Correct answer: C. Azure Key Vault

Azure Key Vault is a cloud service for securely storing and accessing secrets. A secret is anything you want to tightly control access to, such as API keys, passwords, certificates, or cryptographic keys.

Why the other options are wrong

  • A. Azure Storage Account is for storing large amounts of data (blobs, files, tables, queues), not primarily for secure secret management.
  • B. Azure SQL Database is a relational database service, not for storing application secrets.
  • D. Azure Monitor collects, analyzes, and acts on telemetry from your Azure and on-premises environments, not for secret storage.

Azure Key Vault

A cloud service for securely storing and accessing secrets, cryptographic keys, and SSL/TLS certificates.

  • Protects sensitive data from unauthorized access.
  • Centralized management of application secrets.
  • Integrates with other Azure services for easy access.

Memory trick: Key Vault is the 'safe deposit box' for your 'Azure secrets'.

More Describe Azure identity, security, and networking questions