Microsoft Certified: Azure Solutions Architect ExpertDesign infrastructure solutionsEasy

A global software development company uses Azure DevOps for its CI/CD pipelines. They need a secure way to store and manage secrets such as database connection strings, API keys, and certificates, which are used by their applications and deployment scripts. The solution must integrate seamlessly with Azure DevOps and support automated secret rotation. Which Azure service should they use?

  1. AAzure Storage Account
  2. BAzure Cosmos DB
  3. CAzure App Configuration
  4. DAzure Key Vault
Show answer & explanation

Correct answer: D. Azure Key Vault

Azure Key Vault is designed to securely store and manage cryptographic keys, secrets, and certificates. It integrates well with Azure DevOps for CI/CD pipelines and supports features like secret rotation, access policies, and auditing, which are crucial for managing sensitive application data.

Why the other options are wrong

  • A. Azure Storage Account is for storing data, not for securely managing secrets with rotation and access control.
  • B. Azure Cosmos DB is a NoSQL database, not a service for secret management.
  • C. Azure App Configuration is for managing application settings, not for highly sensitive secrets like database connection strings.

Azure Key Vault

A cloud service that provides secure storage for secrets, cryptographic keys, and SSL/TLS certificates.

  • Protects cryptographic keys and secrets
  • Integrates with Azure services like Azure DevOps
  • Supports automated secret rotation and access policies

Memory trick: Key Vault: Your digital safe for all secrets.

More Design infrastructure solutions questions