Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityEasy
A developer is implementing a new Azure App Service web application that needs to store sensitive configuration data, such as database connection strings and API keys. This data must be kept outside of the application's source code and configuration files. The solution must provide strong encryption for data at rest and allow for granular access control. Which Azure service is the most appropriate for securely storing and managing these secrets?
- AAzure Key Vault
- BAzure App Configuration
- CAzure Storage Account Blob Storage
- DAzure SQL Database
Show answer & explanationAnswer & explanation
Correct answer: A. Azure Key Vault
Azure Key Vault is specifically designed to securely store and manage cryptographic keys, secrets (like connection strings and API keys), and certificates. It provides hardware security module (HSM)-backed protection, granular access control, and auditing capabilities, making it ideal for sensitive configuration data.
Why the other options are wrong
- B. Azure App Configuration is for general application configuration management, but for truly sensitive secrets, it often integrates with Azure Key Vault, rather than storing them directly itself.
- C. Azure Storage Account Blob Storage is for storing large binary objects, not typically for actively managed application secrets with granular access control.
- D. Azure SQL Database is a relational database and not designed for secure secret management.
Azure Key Vault
A cloud service for securely storing and accessing secrets, keys, and certificates. It helps protect cryptographic keys and other secrets used by cloud applications and services.
- Centralized storage for application secrets.
- Hardware Security Module (HSM) backed protection (optional).
- Granular access control (RBAC & access policies).
- Integration with other Azure services.
Memory trick: Key Vault is where you keep all your secret keys safe.