โ† All AZ-200 Flashcard Decks

Azure Security & Identity Flashcards

6 cards from real AZ-200 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Azure Security & Identity flashcards as text
  1. What is a managed identity in Azure, and why should developers use it?

    Answer: An automatically managed Azure AD identity for Azure services, eliminating the need to store credentials in code

    Managed identities provide an Azure AD identity automatically managed by Azure, allowing services to authenticate to other Azure services without credentials in code.

  2. What is the difference between a system-assigned and user-assigned managed identity?

    Answer: System-assigned is tied to a single resource and deleted with it; user-assigned is standalone and reusable

    System-assigned identities are created and deleted with the resource, while user-assigned identities exist independently and can be assigned to multiple resources.

  3. Which Azure Key Vault object type should be used to store a database connection string?

    Answer: Secret

    Key Vault Secrets are designed to store sensitive string values like passwords, connection strings, and API keys securely.

  4. How does Azure AD OAuth2 client credentials flow work for service-to-service authentication?

    Answer: The app authenticates directly with Azure AD using its client ID and secret/certificate to obtain an access token

    Client credentials flow allows an application to authenticate as itself (not a user) by presenting its client ID and secret or certificate to Azure AD to get an access token.

  5. What is the purpose of RBAC role assignments in Azure?

    Answer: Grant a security principal (user/group/identity) specific permissions to an Azure resource

    RBAC role assignments attach a role definition to a security principal at a specific scope, granting the permissions defined in that role to the principal.

  6. Which Azure Key Vault soft-delete feature prevents accidental permanent deletion of secrets?

    Answer: Purge protection

    Purge protection prevents a soft-deleted Key Vault or its objects from being permanently purged during the retention period, even by administrators.