Microsoft Certified: Azure Developer Associate (AZ-204)Connect to and consume Azure services and third-party servicesMedium
A company is building an API using Azure Functions and needs to expose it securely to external partners. The API requires custom authentication logic and should enforce usage quotas for different partners. Which Azure service should be used to manage and secure this Function App API?
- AAzure Front Door
- BAzure Application Gateway
- CAzure Load Balancer
- DAzure API Management
Show answer & explanationAnswer & explanation
Correct answer: D. Azure API Management
Azure API Management (APIM) is specifically designed to manage, publish, secure, and analyze APIs. It offers capabilities like custom authentication, usage quotas (rate limiting, subscriptions), caching, and transforming requests, which are all requirements for exposing an API to external partners.
Why the other options are wrong
- A. Azure Front Door is a global, scalable entry-point that uses the Microsoft global edge network to create fast, secure, and widely scalable web applications, primarily for global routing and WAF, not API management features like quotas or custom authentication.
- B. Azure Application Gateway is a web traffic load balancer that enables you to manage traffic to your web applications, primarily for Layer 7 load balancing and WAF, not for API management features like quotas or custom authentication.
- C. Azure Load Balancer is a Layer 4 load balancer that distributes traffic across healthy service instances, lacking the API management capabilities required.
Azure API Management (APIM)
A fully managed service that helps organizations publish, secure, transform, maintain, and monitor APIs.
- Acts as a facade for backend APIs (e.g., Azure Functions).
- Provides capabilities for authentication, authorization, usage quotas, and caching.
- Enables developers to expose APIs securely to internal and external consumers.
Memory trick: APIM is the 'bouncer' and 'manager' for your APIs.