Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsEasy
A software company is developing a new serverless application using Azure Functions. The application needs to securely store connection strings, API keys, and other sensitive configuration data. These secrets must be accessible by the Azure Function, but should not be stored directly in the application code or configuration files. Additionally, the solution must support secret rotation without redeploying the function. Which Azure service should be used to manage these secrets?
- AAzure Key Vault
- BAzure App Configuration
- CAzure Storage Account
- DEnvironment Variables
Show answer & explanationAnswer & explanation
Correct answer: A. Azure Key Vault
Azure Key Vault is designed for securely storing and managing secrets, keys, and certificates. It allows Azure Functions to access these secrets without hardcoding them, supports secret rotation, and integrates with Managed Identities for secure access.
Why the other options are wrong
- B. Azure App Configuration is for centralized application settings and feature flags, but while it can hold sensitive data, Key Vault is the dedicated secure secret store.
- C. Azure Storage Account is for storing data (blobs, files, queues, tables), not specifically designed for secure secret management with rotation capabilities.
- D. Environment Variables store secrets in the application's environment, but they are still part of the deployment and don't provide centralized management or seamless rotation without redeployment.
Azure Key Vault
A cloud service for securely storing and accessing secrets, cryptographic keys, and digital certificates.
- Provides centralized storage for sensitive application data.
- Supports secret rotation and versioning.
- Integrates with Managed Identities for secure access by Azure services.
- Protects against accidental exposure of credentials.
Memory trick: Key Vault: Your digital safe deposit box for secrets.