Microsoft Azure Fundamentals (AZ-900)Describe Azure identity, security, and networkingEasy

A developer is creating an application in Azure that needs to securely store connection strings, API keys, and cryptographic keys. These secrets must be accessible by the application but not directly exposed in code or configuration files. Which Azure service should be used?

  1. AAzure SQL Database
  2. BAzure Storage Account
  3. CAzure App Service
  4. DAzure Key Vault
Show answer & explanation

Correct answer: D. Azure Key Vault

Azure Key Vault is a service for securely storing and managing cryptographic keys, secrets (like passwords and connection strings), and SSL/TLS certificates.

Why the other options are wrong

  • A. Azure SQL Database is a relational database service.
  • B. Azure Storage Account stores unstructured and structured data but is not designed for secure secret management.
  • C. Azure App Service is a platform for building, deploying, and scaling web apps.

Azure Key Vault

Azure Key Vault is a cloud service for securely storing and managing secrets, cryptographic keys, and SSL/TLS certificates.

  • Protects sensitive data from unauthorized access
  • Supports hardware security modules (HSMs)
  • Integrates with other Azure services
  • Provides audit trails for secret access

Memory trick: Key Vault is your digital safe deposit box for all your application's sensitive keys.

More Describe Azure identity, security, and networking questions