Microsoft Certified: Azure Developer Associate (AZ-204)Monitor, troubleshoot, and optimize Azure solutionsHard

You are managing an Azure API Management (APIM) instance that exposes several critical backend APIs. To enhance security, all backend APIs require client certificates for mutual TLS authentication. You need to configure APIM to present a client certificate when making calls to the backend. What is the correct sequence of steps to upload and associate a client certificate with a backend API in APIM?

  1. A1. Upload the certificate to APIM 'Certificates'. 2. Configure the 'Authentication' section of the API's backend settings to use the uploaded certificate.
  2. B1. Upload the certificate to Azure Key Vault. 2. Configure the 'Certificates' section of the APIM instance to reference the Key Vault certificate. 3. Configure the specific API's backend settings to use the referenced certificate.
  3. C1. Upload the certificate to APIM 'Named Values'. 2. Configure a 'Set header' policy on the API to include the certificate as a header.
  4. D1. Upload the certificate to the App Service hosting the backend API. 2. Configure the APIM 'Backend' settings for the API to bypass certificate validation.
Show answer & explanation

Correct answer: B. 1. Upload the certificate to Azure Key Vault. 2. Configure the 'Certificates' section of the APIM instance to reference the Key Vault certificate. 3. Configure the specific API's backend settings to use the referenced certificate.

The most secure and recommended way to manage certificates in Azure, especially for APIM, is to store them in Azure Key Vault. APIM can then reference these certificates. The sequence involves uploading to Key Vault, configuring APIM to access the Key Vault certificate, and finally associating that certificate with the specific backend API's authentication settings.

Why the other options are wrong

  • A. While APIM allows direct certificate upload, using Key Vault is more secure and recommended for certificate management, especially for production environments.
  • C. Named Values are for storing string values or secrets, not for managing and presenting client certificates for mutual TLS. A 'Set header' policy cannot present a client certificate for TLS handshake.
  • D. Uploading to the App Service hosting the backend is for the backend's server certificate, not for APIM's client certificate. Bypassing certificate validation would weaken security, not enhance it.

APIM Client Certificate Authentication

Azure API Management can be configured to present client certificates for mutual TLS authentication when calling backend services, enhancing security by verifying the identity of the APIM instance to the backend.

  • Requires certificates stored securely, ideally in Azure Key Vault.
  • Configured in the backend settings of an API or operation.
  • Enables mutual TLS between APIM and backend.

Memory trick: Key Vault holds the cert, APIM uses it for the backend's assert.

More Monitor, troubleshoot, and optimize Azure solutions questions