Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsEasy
A development team is deploying a new web application to Azure App Service. The application needs to securely store connection strings, API keys, and other secrets. These secrets must be accessible by the App Service application but should not be hardcoded in the application's configuration files or source code. Which Azure service should be used to manage and provide secure access to these secrets?
- AAzure Monitor
- BAzure Storage Account
- CAzure SQL Database
- DAzure Key Vault
Show answer & explanationAnswer & explanation
Correct answer: D. Azure Key Vault
Azure Key Vault is designed to securely store and manage cryptographic keys, secrets (like passwords and connection strings), and certificates. It provides a centralized, cloud-based solution for secrets management, allowing applications to securely retrieve them at runtime without exposing them in code or configuration files.
Why the other options are wrong
- A. Azure Monitor collects telemetry and logs, it does not store application secrets.
- B. Azure Storage Account is for storing data, not specifically designed for secure secret management with granular access control for applications.
- C. Azure SQL Database is for relational data storage and is not suitable for managing application secrets.
Azure Key Vault
A cloud service for securely storing and accessing secrets, cryptographic keys, and SSL/TLS certificates.
- Centralized secret management.
- Provides hardware security module (HSM) protected keys.
- Offers granular access control and auditing capabilities.
Memory trick: Key Vault keeps your secrets safe, like a digital safe.