AZ-305 exam dumps

AZ-305 practice question 37 of 243

Designing Microsoft Azure Infrastructure Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-305 Question 37

Single answer

A software company runs multiple applications in Azure that each require access to various secrets, certificates, and keys. The company wants to centralize management of these sensitive assets so that they can control access policies, automatically rotate secrets, and simplify certificate renewal. Which single solution should they implement to meet these requirements?

  1. A

    Use Azure Key Vault to securely store these assets and configure role-based access control (RBAC)

  2. B

    Store all secrets in Azure Blob storage with private endpoints

  3. C

    Embed secrets directly in an Azure App Service configuration file

  4. D

    Maintain an on-premises Hardware Security Module (HSM) and distribute keys to each application

Show answer and explanation

Correct answer: A

Explanation

Azure Key Vault is recommended for securely managing secrets, keys, and certificates in the Azure ecosystem. It simplifies operations by offering tight integration with Azure services, streamlined secret rotation, and granular access controls. For more information, refer to the official Microsoft documentation: https://learn.microsoft.com/azure/key-vault/general/overview.

  • A. Correct.

    Option 1 is correct because Azure Key Vault allows you to securely store and manage secrets, keys, and certificates in a centralized location. It offers features such as RBAC, configurable access policies, secret versioning, and automatic certificate renewal, making it the primary choice for secure secrets management in Azure.

  • B. Incorrect.

    Option 2 is incorrect because even though you can store data in Azure Blob storage and secure it using private endpoints and encryption, it is not designed to rotated secrets automatically or manage certificates with renewal capabilities. Blob storage does not provide the same specialized secrets, certificates, and key management functionalities that Key Vault does.

  • C. Incorrect.

    Option 3 is incorrect because embedding secrets in an Azure App Service configuration file still risks exposure of sensitive data and does not facilitate automated rotation or centralized policy management. It requires manual updates and lacks dedicated secrets management features.

  • D. Incorrect.

    Option 4 is incorrect because an on-premises HSM is not a cloud-native solution and will not easily integrate with Azure’s built-in secrets and certificate management features. While HSMs can provide a high level of security, the approach would add complexity and limit the benefits of an entirely cloud-based solution for scaling and automation.

Timed practice exam

Take a AZ-305 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam