Microsoft Certified: Azure Solutions Architect ExpertDesign infrastructure solutionsMedium

A global software development company uses Azure DevOps for its CI/CD pipelines. They need a secure way to store and manage secrets (e.g., API keys, connection strings, certificates) used by their applications and pipeline scripts. The solution must provide centralized management, granular access control, and audit logging. Which Azure service should be used to store these secrets?

  1. AAzure Storage Account
  2. BAzure Key Vault
  3. CAzure AD Identity Protection
  4. DAzure App Configuration
Show answer & explanation

Correct answer: B. Azure Key Vault

Azure Key Vault is a cloud service that provides a secure store for secrets, keys, and certificates. It offers centralized management, granular access control through Azure RBAC, and comprehensive audit logging, making it the ideal solution for securely managing secrets for applications and CI/CD pipelines.

Why the other options are wrong

  • A. Azure Storage Account is for storing data (blobs, files, tables, queues), not specifically designed for the secure storage and management of cryptographic keys and secrets with granular access control and audit logging.
  • C. Azure AD Identity Protection is a security feature of Azure AD that detects and remediates identity-based risks, not a service for storing application secrets.
  • D. Azure App Configuration is for managing application settings and feature flags, not for storing sensitive secrets like API keys and connection strings.

Azure Key Vault

A cloud service for securely storing and accessing secrets, keys, and certificates.

  • Centralized management of secrets.
  • Hardware Security Module (HSM) protected keys.
  • Granular access control and audit logging.

Memory trick: Key Vault: The 'Vault' for all your 'Keys' and secrets.

More Design infrastructure solutions questions