Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionEasy

A company is deploying a new web application to Azure App Service. The application needs to securely store connection strings, API keys, and other sensitive configuration data. Developers should be able to retrieve these secrets programmatically without hardcoding them into the application code. Which Azure service should you recommend to meet these requirements?

  1. AAzure SQL Database
  2. BAzure Storage Account
  3. CAzure Cosmos DB
  4. DAzure Key Vault
Show answer & explanation

Correct answer: D. Azure Key Vault

Azure Key Vault is specifically designed to securely store and manage cryptographic keys, secrets, and certificates. It provides a centralized, cloud-based solution for securely storing sensitive data, making it ideal for connection strings and API keys.

Why the other options are wrong

  • A. Azure SQL Database is a relational database service, not designed for secret management.
  • B. Azure Storage Accounts are for storing general data, not specifically for secrets with secure access controls.
  • C. Azure Cosmos DB is a NoSQL database service, not suitable for storing application secrets securely.

Azure Key Vault for Secrets

Azure Key Vault is a cloud service for securely storing and managing secrets, keys, and certificates, providing centralized management and controlled access.

  • Stores secrets like API keys, connection strings, and passwords.
  • Provides hardware security module (HSM)-backed protection.
  • Integrates with other Azure services for secure access.
  • Offers logging and monitoring of secret access.

Memory trick: Key Vault: Your cloud safe for sensitive data.

More Implement platform protection questions