Azure Security & Identity Flashcards
6 cards from real AZ-200 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Azure Security & Identity flashcards as text
What is an Azure AD application registration used for in development?
Answer: Representing an application in Azure AD to enable authentication and authorization via OAuth2/OIDC
An app registration creates an identity for an application in Azure AD, enabling it to authenticate users or other services using OAuth2 and OpenID Connect protocols.
Which Azure AD token type should be validated by a resource API to authorize incoming requests?
Answer: Access token
An API should validate the access token, which is issued by Azure AD and contains the caller's identity, roles, and scopes for authorization decisions.
What is the purpose of Azure AD Conditional Access policies for application developers?
Answer: Enforce additional security requirements (MFA, compliant device) when accessing applications
Conditional Access policies enforce security requirements like MFA or compliant device when users sign into applications, protecting against compromised credentials.
How should a developer rotate a secret stored in Azure Key Vault with zero downtime?
Answer: Create a new secret version, update the app to read the new version, then deactivate the old version
Best practice is to create a new version of the secret in Key Vault, deploy the application with the new version reference, then disable the old version after validation.
What Azure feature allows developers to verify that a request comes from a specific Azure service without checking credentials?
Answer: Managed Identity with Azure AD token validation
Using managed identity, a service obtains an Azure AD access token that the receiving service can validate cryptographically to confirm the caller's identity.
Which Azure service provides centralized secrets management with HSM-backed key storage and audit logging?
Answer: Azure Key Vault
Azure Key Vault provides a centralized, cloud-hosted vault for secrets, keys, and certificates with optional HSM backing, RBAC, and full audit logging via Azure Monitor.