Microsoft Certified: Azure Solutions Architect ExpertDesign infrastructure solutionsEasy

A global software development company uses Azure DevOps for its CI/CD pipelines. They need a secure way to store and manage sensitive information such as API keys, database connection strings, and certificates, which are used by their build and release pipelines. This solution must adhere to strict security best practices, including automatic key rotation and granular access control. Which Azure service should be recommended?

  1. AAzure App Configuration
  2. BAzure SQL Database
  3. CAzure Storage Account
  4. DAzure Key Vault
Show answer & explanation

Correct answer: D. Azure Key Vault

Azure Key Vault is designed to securely store and manage cryptographic keys, secrets (like API keys and connection strings), and certificates. It provides features like hardware security module (HSM)-backed storage, automatic key rotation, and granular access control through Azure AD integration, making it ideal for CI/CD pipeline secrets.

Why the other options are wrong

  • A. Azure App Configuration is for centralizing application settings and feature flags, not primarily for storing highly sensitive secrets with HSM-backed security and key rotation.
  • B. Azure SQL Database is a relational database service and is completely unsuitable for managing application secrets and keys securely.
  • C. Azure Storage Account stores data blobs, files, queues, and tables, but is not designed for secure secret management with features like automatic key rotation and granular access specific to secrets.

Azure Key Vault

A cloud service for securely storing and accessing secrets, such as API keys, passwords, certificates, or cryptographic keys.

  • Provides centralized storage for application secrets.
  • Supports hardware security modules (HSMs) for enhanced security.
  • Offers automatic key rotation and granular access control (RBAC).

Memory trick: Key Vault: Your 'Key' to 'Vault'ed secrets.

More Design infrastructure solutions questions