A financial institution uses Azure API Management (APIM) to expose its APIs to partner applications. They need to ensure that the partner applications do not overwhelm the backend systems by making too many requests within a short period. Each partner application has a different agreed-upon request limit. Which APIM policy should be implemented?
- Aauthentication-managed-identity
- Brate-limit-by-key
- Ccache-lookup
- Dset-header
Show answer & explanationAnswer & explanation
Correct answer: B. rate-limit-by-key
The 'rate-limit-by-key' policy in Azure API Management allows you to enforce request limits based on a specific key (e.g., partner ID), which can be extracted from the request context. This directly addresses the requirement of different request limits for each partner application to prevent backend overload. Cache lookup is for performance, set header modifies headers, and managed identity is for authentication.
Why the other options are wrong
- A. The 'authentication-managed-identity' policy is for authenticating requests using Azure Managed Identities, not for controlling request volume.
- C. The 'cache-lookup' policy is used to retrieve responses from a cache to improve performance, not to limit incoming requests.
- D. The 'set-header' policy is used to add, append, or replace HTTP headers in requests or responses, not for rate limiting.
APIM rate-limit-by-key Policy
The Azure API Management 'rate-limit-by-key' policy restricts the number of API calls a consumer can make within a specified time period, with the limit dynamically determined by a key value extracted from the request context.
- Enforces request quotas on a per-key basis.
- Key can be an expression (e.g., user ID, IP address, header value).
- Prevents backend systems from being overwhelmed.
- Configurable for different time periods and call limits.
Memory trick: A traffic cop limiting cars based on their unique license plate.