Microsoft Certified: Azure Developer Associate (AZ-204)Develop Azure compute solutionsEasy

A developer is creating an Azure Function that needs to store and retrieve sensitive configuration settings, such as API keys and database connection strings, securely. The application also requires these secrets to be rotated periodically without redeploying the function. Which Azure service should the developer integrate for managing these secrets?

  1. AAzure SQL Database
  2. BAzure Key Vault
  3. CApplication Settings in Azure Function App
  4. DAzure Storage Account
Show answer & explanation

Correct answer: B. Azure Key Vault

Azure Key Vault is designed to securely store and manage secrets, keys, and certificates. It provides robust access control, auditing, and the ability to rotate secrets without modifying application code, which aligns with the requirements.

Why the other options are wrong

  • A. Azure SQL Database is for relational data storage, not for managing application secrets.
  • C. Application Settings in the Function App can store secrets, but lacks advanced features like auditing, fine-grained access control, and easy rotation without redeploying (though values can be updated, it's not the primary secure secret management tool).
  • D. Azure Storage Account is for storing data, not specifically designed for secure secret management and rotation.

Azure Key Vault

A cloud service for securely storing and managing secrets, cryptographic keys, and SSL/TLS certificates.

  • Centralized secret management
  • Hardware Security Module (HSM) backed protection
  • Access control and auditing
  • Supports secret rotation

Memory trick: Key Vault Guards All Secrets Very Well

More Develop Azure compute solutions questions