AZ-305 exam dumps

AZ-305 practice question 39 of 243

Designing Microsoft Azure Infrastructure Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-305 Question 39

Single answer

You are designing a multi-tier application hosted on Azure Web Apps and Azure Virtual Machines. The application requires secure storage of SSL/TLS certificates for custom domain communication, as well as database credentials that need periodic rotation. You want to ensure minimal administrative overhead while maintaining strict access controls and audit capabilities. Which solution should you recommend to manage these secrets, certificates, and keys?

  1. A

    Store all secrets in Azure Key Vault and configure role-based access for principal identities

  2. B

    Embed the secrets within the application configuration files stored in Azure Repos

  3. C

    Keep the secrets in environment variables on each Azure Web App and VM

  4. D

    Use a shared file system for certificates and credentials, secured by Azure Storage encryption

Show answer and explanation

Correct answer: A

Explanation

Azure Key Vault is the recommended solution for securely managing secrets, certificates, and keys in Azure. It offers fine-grained access control, auditing, continuous monitoring, and integration with various Azure services, reducing manual overhead. According to Microsoft documentation (https://learn.microsoft.com/azure/key-vault/general/basic-concepts), Azure Key Vault also enables secure certificate management and automated rotation, helping you maintain compliance and security best practices.

  • A. Correct.

    Option 1 is correct because Azure Key Vault securely stores and manages secrets, certificates, and keys with access policies and auditing. It also supports features such as automatic certificate rotation and integration with Azure services, reducing administrative overhead.

  • B. Incorrect.

    Option 2 is incorrect because storing secrets in configuration files, even in a private repository, increases the risk of accidental exposure and does not provide enterprise-grade secret rotation or rich auditing capabilities.

  • C. Incorrect.

    Option 3 is incorrect because relying solely on environment variables for each service is less secure, difficult to audit across multiple Web Apps and VMs, and does not offer built-in rotation or versioning.

  • D. Incorrect.

    Option 4 is incorrect because a shared file system does not provide granular access controls or advanced secret management capabilities. While Azure Storage encryption protects data at rest, it does not address secret rotation or least-privileged access controls.

Timed practice exam

Take a AZ-305 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam