Microsoft Certified: DevOps Engineer ExpertImplement an instrumentation strategyEasy

A healthcare startup is building a new patient portal on Azure, leveraging Azure App Service for web applications and Azure SQL Database for data storage. They need to implement a secure and efficient way to store and retrieve application secrets like database connection strings and API keys without embedding them directly in code or configuration files. This solution must also integrate with Azure DevOps for automated deployments. Which Azure service should they use?

  1. AAzure Data Factory
  2. BAzure Storage Account
  3. CAzure Key Vault
  4. DAzure Content Delivery Network (CDN)
Show answer & explanation

Correct answer: C. Azure Key Vault

Azure Key Vault is designed to securely store and manage cryptographic keys, secrets (like passwords and connection strings), and certificates. It provides a centralized, highly available, and secure solution for secrets management, with strong integration capabilities with Azure App Service and Azure DevOps.

Why the other options are wrong

  • A. Azure Data Factory is an ETL service, unrelated to application secret management.
  • B. Azure Storage Account is for general data storage, not optimized for secure secret management.
  • D. Azure CDN is for content delivery, not for storing application secrets.

Azure Key Vault

A cloud service for securely storing and accessing secrets. A secret is anything you want to tightly control access to, such as API keys, passwords, certificates, or cryptographic keys. Key Vault helps you safeguard cryptographic keys and other secrets used by cloud applications and services.

  • Centralized secure storage for secrets, keys, certificates.
  • Reduces risk of hardcoding sensitive information.
  • Integrates with Azure services like App Service, Azure DevOps, and Managed Identities.

Memory trick: Key Vault keeps my secrets safe, like a digital safe.

More Implement an instrumentation strategy questions