AZ-305 exam dumps

AZ-305 practice question 36 of 243

Designing Microsoft Azure Infrastructure Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-305 Question 36

Single answer

Your organization operates several services across Azure Virtual Machines, Azure App Service, and Azure Kubernetes Service (AKS). These services need to securely store and manage SSL certificates, API keys, and encryption keys. Additionally, the company requires centralized audit logging, clear access control policies, and periodic rotation of secrets to meet compliance requirements. What is the most appropriate solution to recommend for managing these secrets, certificates, and keys in Azure?

  1. A

    Store all secrets in Azure App Service application settings and distribute them to other services as needed.

  2. B

    Use Azure Key Vault to store keys, certificates, and secrets, and leverage Azure Active Directory for access control.

  3. C

    Embed secrets in container images for AKS and rely on file-based storage for VMs.

  4. D

    Use Azure Storage accounts with a private container to store certificates and keys, and manually rotate them.

Show answer and explanation

Correct answer: B

Explanation

Azure Key Vault is the recommended service in Azure for centrally managing certificates, keys, and secrets. It integrates with Azure Active Directory and allows for policy-based access control and comprehensive auditing. Key Vault also supports secret rotation workflows, which helps organizations maintain compliance. For more details, refer to Microsoft documentation on Azure Key Vault (https://docs.microsoft.com/azure/key-vault/) and best practices for secure key management.

  • A. Incorrect.

    Option 1: Storing secrets in Azure App Service application settings can work for that specific App Service, but it doesn't provide centralized management, robust rotation capabilities, or consistent audit logs for multiple services.

  • B. Correct.

    Option 2: Azure Key Vault is purpose-built for securely managing keys, certificates, and secrets. It integrates with Azure Active Directory for precise access control, offers audit logs, and supports secret rotation for compliance requirements, making it the best fit for this scenario.

  • C. Incorrect.

    Option 3: Embedding secrets in container images is a security risk because secrets become part of the image layers. Also, file-based storage for VMs lacks centralized auditing and rotation features, making it unsuitable for company-wide secret management.

  • D. Incorrect.

    Option 4: While Azure Storage can store files securely, it is not designed for robust key and secret management. It does not offer native secret rotation or advanced access control for keys and certificates, leading to a more manual and less secure configuration.

Timed practice exam

Take a AZ-305 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam