Microsoft Azure Fundamentals (AZ-900)Describe Azure identity, security, and networkingMedium
A development team is building a new application that requires storing sensitive configuration data, such as API keys, database connection strings, and certificates. They need a centralized and secure service in Azure to manage these secrets, ensuring they are protected against unauthorized access and are easily retrievable by authorized applications. Which Azure service should they use?
- AAzure Storage Account
- BAzure SQL Database
- CAzure Key Vault
- DAzure Monitor
Show answer & explanationAnswer & explanation
Correct answer: C. Azure Key Vault
Azure Key Vault is a cloud service for securely storing and accessing secrets. A secret is anything you want to tightly control access to, such as API keys, passwords, certificates, or cryptographic keys.
Why the other options are wrong
- A. Azure Storage Account is for storing large amounts of data (blobs, files, tables, queues), not primarily for secure secret management.
- B. Azure SQL Database is a relational database service, not for storing application secrets.
- D. Azure Monitor collects, analyzes, and acts on telemetry from your Azure and on-premises environments, not for secret storage.
Azure Key Vault
A cloud service for securely storing and accessing secrets, cryptographic keys, and SSL/TLS certificates.
- Protects sensitive data from unauthorized access.
- Centralized management of application secrets.
- Integrates with other Azure services for easy access.
Memory trick: Key Vault is the 'safe deposit box' for your 'Azure secrets'.