Microsoft Certified: Fabric Analytics Engineer AssociatePrepare and transform data (20-25%)Hard
A data engineer is working on a Dataflow Gen2 to ingest product catalog data from an external REST API. The API requires an API key to be passed in the request header for authentication. To ensure secure credential management and avoid hardcoding the key, how should the API key be handled in the Dataflow Gen2?
- ACreate a secure connection in Microsoft Fabric and use it when configuring the Web source.
- BStore the API key as a parameter in the Dataflow Gen2 and reference it in the M code.
- CStore the API key in an Azure Key Vault and retrieve it using a Web.Contents call within the Dataflow.
- DEmbed the API key directly into the Power Query M code for the Web.Contents function.
Show answer & explanationAnswer & explanation
Correct answer: A. Create a secure connection in Microsoft Fabric and use it when configuring the Web source.
Microsoft Fabric's secure connection feature is explicitly designed for managing credentials like API keys, database connection strings, and OAuth tokens securely. When configuring a web source in Dataflows Gen2, you can select an existing secure connection that handles the API key, ensuring it's not exposed in the Dataflow code or parameters.
Why the other options are wrong
- B. While better than hardcoding, parameters are visible in the Dataflow settings and are not considered as secure as dedicated connection management for sensitive credentials.
- C. While Azure Key Vault is excellent for storing secrets, Dataflows Gen2 does not have a direct, native connector to retrieve secrets from Key Vault within the Power Query environment in a secure and integrated manner for API keys; the Fabric secure connection is the intended abstraction.
- D. Hardcoding credentials is a significant security risk and should be avoided.
Fabric Secure Connections
Microsoft Fabric's secure connection feature provides a centralized and secure way to manage credentials for data sources used across various Fabric items.
- Encrypts and stores sensitive connection details.
- Supports various authentication types (API Key, OAuth, Service Principal).
- Reusable across Dataflows, Data Pipelines, and other Fabric items.
Memory trick: Guard your data keys in a Fabric vault, not in plain sight.