Microsoft Certified: Azure Developer Associate (AZ-204)Develop Azure compute solutionsEasy

A development team is building a new application that will use Azure Functions. They need to ensure that sensitive configuration information, such as API keys and database connection strings, is stored securely and accessed by the functions at runtime without being hardcoded or exposed in source control. Which Azure service should they integrate with their Azure Functions for this purpose?

  1. AAzure Key Vault
  2. BAzure Cosmos DB
  3. CAzure Storage Account
  4. DAzure Monitor
Show answer & explanation

Correct answer: A. Azure Key Vault

Azure Key Vault is designed to securely store and manage cryptographic keys, secrets (like API keys and connection strings), and certificates. It is the recommended service for Azure Functions to retrieve sensitive configuration information at runtime.

Why the other options are wrong

  • B. Azure Cosmos DB is a NoSQL database service, not for storing application secrets securely.
  • C. Azure Storage Account stores data but is not designed for secure secret management with fine-grained access control for application secrets.
  • D. Azure Monitor is for collecting, analyzing, and acting on telemetry data from Azure resources, not for secret storage.

Azure Key Vault for Functions

Azure Key Vault provides a secure and centralized store for sensitive data like API keys, connection strings, and certificates that Azure Functions can access at runtime.

  • Enhances security by separating secrets from code.
  • Provides fine-grained access control (RBAC).
  • Supports secret rotation and auditing.

Memory trick: Key Vault 'K'eeps 'K'eys 'K'onfidential.

More Develop Azure compute solutions questions