Microsoft Certified: Azure Developer Associate (AZ-204)Monitor, troubleshoot, and optimize Azure solutionsMedium

A development team is implementing an API using Azure API Management (APIM). They need to ensure that specific sensitive information (e.g., API keys, connection strings) used within APIM policies is not hardcoded and can be securely managed and rotated. Additionally, these values should be accessible to policies without exposing them directly in the policy XML. Which APIM feature, combined with an Azure security service, should they use?

  1. AAPIM Policies using `set-header` and `set-body`
  2. BAPIM Diagnostics settings for logging to Log Analytics
  3. CAPIM Properties (Named Values) linked to Azure Key Vault
  4. DAPIM Backends configured with 'Always-on' setting
Show answer & explanation

Correct answer: C. APIM Properties (Named Values) linked to Azure Key Vault

APIM Named Values (formerly Properties) allow you to securely store and reference configuration values. By linking a Named Value to an Azure Key Vault secret, sensitive information can be securely stored, managed, and rotated in Key Vault, and then referenced in APIM policies without exposing the actual secret in the policy definition.

Why the other options are wrong

  • A. set-header and set-body policies are for manipulating HTTP requests/responses, not for securely managing sensitive configuration values within APIM itself.
  • B. Diagnostics settings are for monitoring and logging APIM operations, not for securely storing and referencing secrets in policies.
  • D. The 'Always-on' setting for backends is related to keeping backend services warm, not for managing sensitive configuration data for APIM policies.

APIM Named Values with Key Vault

Azure API Management Named Values (Properties) can be linked to Azure Key Vault secrets to securely store and reference sensitive configuration data within APIM policies.

  • Provides a centralized way to manage secrets.
  • Enables secret rotation without policy changes.
  • Values are securely retrieved at runtime by APIM.

Memory trick: Name your secrets, link to Key Vault, keep policies clean, without any fault.

More Monitor, troubleshoot, and optimize Azure solutions questions