Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionEasy

A company is hosting a critical web application in Azure App Service. This application needs to retrieve database connection strings, API keys, and other sensitive configuration values at runtime. The security team insists that these secrets must be stored securely, centrally, and be accessible only by the application, without being hardcoded or exposed in configuration files. Which Azure service is the most appropriate for managing these application secrets?

  1. AAzure SQL Database
  2. BAzure App Configuration
  3. CAzure Storage Account
  4. DAzure Key Vault
Show answer & explanation

Correct answer: D. Azure Key Vault

Azure Key Vault is the dedicated service for securely storing and managing application secrets like connection strings and API keys. It provides centralized storage, strong access control (via Azure AD), and ensures that secrets are not hardcoded, making it the most appropriate choice.

Why the other options are wrong

  • A. Azure SQL Database is a relational database service and is not designed for storing application configuration secrets.
  • B. Azure App Configuration manages application settings and feature flags, but for truly sensitive secrets, Key Vault is the more secure and appropriate solution, often integrated with App Configuration.
  • C. Azure Storage Account is for general data storage (blobs, files, etc.), not for secure, centralized management of application secrets with fine-grained access control.

Azure Key Vault for Application Secrets

Azure Key Vault provides a secure, centralized store for application secrets like connection strings, API keys, and passwords, protecting them from unauthorized access.

  • Eliminates the need to hardcode secrets in application code.
  • Integrates with Azure AD for identity-based access control.
  • Supports secret versioning and soft-delete.
  • Used by Azure App Service, Azure Functions, VMs, and other services.

Memory trick: Keep your app's secrets in the 'Key Vault' to keep them safe and sound.

More Implement platform protection questions