Microsoft Certified: Azure Developer Associate (AZ-204)Connect to and consume Azure services and third-party servicesMedium
A developer needs to create a serverless API that can be accessed by both internal and external consumers. The API must support custom authentication, request validation, and caching to improve performance and reduce load on the backend service. Which Azure service should be used to achieve these requirements efficiently?
- AAzure Logic Apps with HTTP Request trigger
- BAzure API Management
- CAzure App Service with a custom reverse proxy
- DAzure Functions with custom middleware
Show answer & explanationAnswer & explanation
Correct answer: B. Azure API Management
Azure API Management (APIM) provides a comprehensive solution for managing, securing, and publishing APIs. It offers out-of-the-box capabilities for custom authentication, request validation (e.g., schema validation), and caching policies, making it the most efficient choice for centralizing these concerns.
Why the other options are wrong
- A. Azure Logic Apps are for workflow automation and integration; while they can expose HTTP endpoints, they are not designed as a full-fledged API gateway for management, security, and performance optimization.
- C. Azure App Service can host APIs, but a custom reverse proxy would require considerable development and maintenance to replicate APIM's features.
- D. Azure Functions can host APIs, but implementing custom authentication, validation, and caching from scratch requires significant development effort and doesn't provide the centralized management of APIM.
API Management Policies
Declarative statements in Azure API Management that are executed sequentially on inbound or outbound requests, allowing for functionalities like authentication, caching, transformation, and rate limiting.
- Apply to inbound or outbound requests.
- Configurable at global, product, API, or operation scope.
- Enable security, performance, and transformation features.
Memory trick: APIM is the smart security guard and librarian for your APIs, checking IDs, validating requests, and quickly fetching cached answers.