Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionEasy

A developer is creating a new Azure Function App that needs to securely store connection strings for a backend database and API keys for a third-party service. These secrets must not be hardcoded in the application's source code or configuration files. The solution must also support automatic rotation of these secrets. Which Azure service should the developer use?

  1. AAzure Key Vault
  2. BAzure App Configuration
  3. CAzure Cosmos DB
  4. DAzure Storage Account
Show answer & explanation

Correct answer: A. Azure Key Vault

Azure Key Vault is specifically designed to securely store and manage secrets, such as API keys and connection strings. It also supports features like automatic secret rotation and access control, making it the ideal choice for this scenario.

Why the other options are wrong

  • B. Azure App Configuration manages application settings and feature flags, but it's not primarily a secure secret store with rotation features like Key Vault.
  • C. Azure Cosmos DB is a NoSQL database service and not intended for storing application secrets in this manner.
  • D. Azure Storage Account is for storing data (blobs, files, tables, queues), not for securely managing application secrets with rotation capabilities.

Azure Key Vault for Secrets

Azure Key Vault provides a secure and centralized service for storing and managing access to secrets, keys, and certificates used by cloud applications and services.

  • Protects cryptographic keys and secrets used by cloud applications and services.
  • Supports hardware security modules (HSMs) for enhanced protection.
  • Enables automatic rotation of secrets and certificates.
  • Integrates with Azure AD for access control.

Memory trick: Keep your keys in the vault, safe and rotating.

More Implement platform protection questions