Microsoft Certified: Fabric Analytics Engineer AssociatePrepare and transform data (20-25%)Medium
A data engineer is designing a Data Pipeline to ingest data from an external REST API that requires an API key for authentication, which should be securely managed. The API key must not be hardcoded in the pipeline. Which method should the engineer use to store and retrieve the API key within the Data Pipeline?
- AUse an Azure Key Vault-backed secret scope and reference the secret in the pipeline.
- BEmbed the API key in a linked service connection string.
- CPass the API key as a parameter during pipeline execution.
- DStore the API key directly in the Data Pipeline's JSON definition.
Show answer & explanationAnswer & explanation
Correct answer: A. Use an Azure Key Vault-backed secret scope and reference the secret in the pipeline.
Using Azure Key Vault (integrated with Fabric for secure secret management) is the recommended best practice for storing sensitive credentials like API keys. By referencing a Key Vault secret, the API key is never exposed in plain text within the pipeline definition, enhancing security.
Why the other options are wrong
- B. While linked services can use credentials, embedding the API key directly in a connection string within the linked service definition (without Key Vault integration) is still less secure than using a Key Vault secret.
- C. Passing sensitive information as a parameter during execution can still expose it in logs or execution details, making it less secure than Key Vault.
- D. Storing sensitive information directly in the pipeline's JSON definition is a major security risk and should be avoided.
Secure Credential Management in Fabric
For secure management of sensitive credentials like API keys in Microsoft Fabric Data Pipelines, Azure Key Vault is the recommended solution. Secrets are stored in Key Vault and referenced securely within pipeline activities and linked services.
- Prevents hardcoding sensitive information.
- Leverages Azure Key Vault for robust security.
- Secrets are referenced, not exposed in plain text.
- Enhances compliance and reduces security risks.
Memory trick: Key Vault locks API keys in the cloud.