Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsEasy

A software company is developing a new serverless application using Azure Functions. The application needs to securely retrieve secrets (e.g., API keys, database connection strings) from a centralized, highly secure repository. These secrets must be accessible to the Function App at runtime without being hardcoded or stored in configuration files. Which Azure service should be used to store and manage these secrets?

  1. AAzure Storage Account.
  2. BApp Service Settings.
  3. CAzure SQL Database.
  4. DAzure Key Vault.
Show answer & explanation

Correct answer: D. Azure Key Vault.

Azure Key Vault is specifically designed to securely store and manage cryptographic keys, secrets, and certificates. It provides a centralized, highly secure solution for secrets management, allowing Azure Functions to retrieve them at runtime without hardcoding or storing them in plain text, leveraging managed identities for authentication.

Why the other options are wrong

  • A. Azure Storage Account is for general data storage (blobs, files, tables, queues), not designed as a secure secrets management solution.
  • B. App Service Settings (application settings) store configuration values, but for highly sensitive secrets requiring robust security features like access policies, auditing, and key rotation, Azure Key Vault is the recommended and more secure solution.
  • C. Azure SQL Database is a relational database, not a secure secrets management service.

Azure Key Vault

A cloud service for securely storing and accessing secrets, such as API keys, passwords, certificates, and cryptographic keys. It helps protect sensitive information from unauthorized access and provides centralized management.

  • Centralized secure storage for secrets, keys, and certificates.
  • Supports fine-grained access control using Azure RBAC.
  • Provides auditing and monitoring of access to secrets.
  • Integrates with Azure services (e.g., Functions, App Service) using Managed Identities.

Memory trick: Keep your cloud secrets safe in a vault, never out in the open.

More Secure data and applications questions