Microsoft Certified: Azure Administrator AssociateDeploy and manage Azure compute resourcesHard
A company is migrating a legacy application to Azure App Service. The application relies on specific environment variables that are set during startup. Additionally, the application needs to connect to an Azure SQL Database using a connection string that contains sensitive credentials. You need to configure the App Service to manage these settings securely and efficiently.
- AStore both the environment variables and the connection string in plain text files within the application's deployment package.
- BHardcode the environment variables and connection string directly into the application's code.
- CUse a custom startup script to set environment variables and retrieve the connection string from a public GitHub repository.
- DStore the environment variables in the App Service Configuration section and the connection string in Key Vault, referencing it from App Service.
Show answer & explanationAnswer & explanation
Correct answer: D. Store the environment variables in the App Service Configuration section and the connection string in Key Vault, referencing it from App Service.
Azure App Service's Configuration section is designed for managing application settings and environment variables securely. For highly sensitive data like database connection strings, Azure Key Vault is the recommended secure storage, and App Service can easily reference Key Vault secrets.
Why the other options are wrong
- A. Storing credentials in plain text in the deployment package is a major security risk.
- B. Hardcoding is insecure, difficult to manage, and requires code changes for updates.
- C. Public GitHub is highly insecure for credentials, and a custom script for environment variables is less managed than App Service's built-in configuration.
Azure App Service Configuration
A feature within Azure App Service that allows you to manage application settings, connection strings, and environment variables, which are injected into the application at runtime.
- Provides secure storage for application settings.
- Connection strings are encrypted at rest.
- Can reference secrets stored in Azure Key Vault for enhanced security.
- Environment variables are automatically exposed to the application process.
Memory trick: Config for Env, Key Vault for Secrets.