Microsoft Certified: Azure Developer Associate (AZ-204)Develop Azure compute solutionsMedium

A developer is creating an Azure Function that needs to access a secret (e.g., a database connection string) securely. The secret should not be hardcoded in the application code or stored directly in the Function App settings. The solution must follow best practices for secret management and integrate seamlessly with the Azure Function environment. Which Azure service should be used to store and retrieve the secret?

  1. AAzure Key Vault
  2. BAzure Cosmos DB
  3. CAzure Storage Account (Blob Storage)
  4. DAzure SQL Database
Show answer & explanation

Correct answer: A. Azure Key Vault

Azure Key Vault is designed for securely storing and managing secrets, encryption keys, and SSL certificates. Azure Functions can integrate with Key Vault using Managed Identities, allowing the function to retrieve secrets without hardcoding them, adhering to best practices for secret management.

Why the other options are wrong

  • B. Azure Cosmos DB is a NoSQL database service, not intended for secure secret management.
  • C. Blob Storage is for storing large binary objects and files, not designed for secure secret management with granular access control.
  • D. Azure SQL Database is for relational data storage, not for securely storing application secrets.

Azure Key Vault

A cloud service for securely storing and managing secrets, such as API keys, database connection strings, passwords, and cryptographic keys. It helps solve the problem of hardcoding sensitive information in applications.

  • Centralized secure storage for secrets
  • Hardware Security Module (HSM) backed protection
  • Granular access control (RBAC)
  • Integrates with Managed Identities for secure access

Memory trick: Key Vault locks your secrets tight, Managed Identity is the key, bringing them to light.

More Develop Azure compute solutions questions