Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityHard
A healthcare company is developing an Azure Function App that processes patient health information (PHI). The Function App needs to store configuration settings, including connection strings to a highly secured database, in a secure manner. These settings must be accessible by the Function App but should never be exposed in plain text in source control or application settings. An additional requirement is that the settings should be automatically rotated every 90 days. Which Azure service should be used to store and manage these configuration settings?
- AAzure Key Vault
- BAzure App Configuration
- CAzure Storage Account (Blob Storage)
- DEnvironment Variables
Show answer & explanationAnswer & explanation
Correct answer: A. Azure Key Vault
Azure Key Vault is designed for securely storing and managing secrets, encryption keys, and certificates. It integrates directly with Azure Functions (especially when using Managed Identities) and provides features for secret rotation, including the ability to set expiration dates and automate rotation with Azure Event Grid and Azure Functions. This perfectly matches the requirement for secure storage, no plain text exposure, and automatic rotation.
Why the other options are wrong
- B. Azure App Configuration is primarily for centralized configuration management, including dynamic updates and feature flags. While it can store settings, it's not designed as a primary secret store with built-in robust rotation capabilities like Key Vault.
- C. Azure Storage Account (Blob Storage) is for storing large amounts of unstructured data. Storing sensitive configuration settings directly in Blob Storage is not recommended for security and lacks built-in secret management and rotation features.
- D. Environment Variables can store settings, but they are typically exposed in the application runtime and are not securely managed or rotated automatically, failing the 'never exposed in plain text' and 'automatically rotated' requirements.
Azure Key Vault for Secrets Management
A cloud service for securely storing and accessing secrets, such as API keys, passwords, connection strings, and cryptographic keys.
- Provides hardware security module (HSM) protected keys.
- Offers fine-grained access control with Azure RBAC and Key Vault access policies.
- Supports secret rotation, auditing, and monitoring of access.
Memory trick: Key Vault: The vault for turning secrets, not just storing them.