Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityEasy

A company is developing an Azure Function App that processes sensitive customer data. The function needs to store connection strings and API keys securely. Which Azure service should be used to manage these secrets?

  1. AAzure Storage Account
  2. BAzure Cosmos DB
  3. CAzure Key Vault
  4. DAzure SQL Database
Show answer & explanation

Correct answer: C. Azure Key Vault

Azure Key Vault is specifically designed to securely store and manage secrets like API keys, passwords, certificates, and encryption keys. It provides a centralized, cloud-based solution for lifecycle management of these critical assets.

Why the other options are wrong

  • A. Azure Storage Accounts are for storing data blobs, files, queues, and tables, not for secure secret management.
  • B. Azure Cosmos DB is a NoSQL database service, not designed for secure secret storage.
  • D. Azure SQL Database is a relational database service, not designed for secure secret storage.

Azure Key Vault

A cloud service for securely storing and accessing secrets, such as API keys, passwords, certificates, and cryptographic keys.

  • Centralized secret management
  • Hardware Security Module (HSM) backed protection
  • Integration with other Azure services

Memory trick: Key Vault: Your digital safe for secrets.

More Implement Azure security questions