Azure Security & Identity Flashcards
6 cards from real AZ-200 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Azure Security & Identity flashcards as text
What is the purpose of specifying API permissions (scopes) in an Azure AD app registration?
Answer: To declare what downstream APIs or Microsoft Graph resources the app is allowed to call
API permissions declare the OAuth2 scopes or roles the application needs to call downstream APIs, which must be consented to by users or admins.
How does DefaultAzureCredential in the Azure SDK simplify authentication across environments?
Answer: It chains multiple credential providers (environment variables, managed identity, Visual Studio, etc.) and uses the first that works
DefaultAzureCredential tries a chain of credential sources — environment variables, workload identity, managed identity, Visual Studio, CLI — enabling seamless auth in dev and production.
What is the difference between delegated permissions and application permissions in Azure AD?
Answer: Delegated permissions act on behalf of a signed-in user; application permissions allow an app to act as itself without a user
Delegated permissions allow the app to act on behalf of a signed-in user, while application permissions allow the app to access resources independently without a user context.
Which Azure AD feature allows multi-tenant applications to be accessed by users from other Azure AD tenants?
Answer: Azure AD Multi-Tenant Application support with common or organizations endpoints
Multi-tenant Azure AD apps use the /common or /organizations authority endpoints, allowing users from any Azure AD tenant to authenticate.
What is the recommended way to store secrets for an Azure Function running in production?
Answer: In Azure Key Vault, referenced via Key Vault references in application settings
Key Vault references in Azure Functions application settings allow secrets to be fetched securely from Key Vault at runtime without embedding them in code or config files.
Which Azure AD grant type is used when a user signs in interactively via a browser and the app receives an authorization code?
Answer: Authorization code flow
The authorization code flow is the standard interactive sign-in flow where Azure AD redirects the user's browser back to the app with an authorization code that is exchanged for tokens.