← All AZ-204 Flashcard Decks

Azure Security & Identity Flashcards

6 cards from real AZ-204 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Azure Security & Identity flashcards as text
  1. What Azure AD object represents an application's identity and is used to authenticate against Azure AD to obtain tokens?

    Answer: Service principal

    A service principal is the local representation of an Azure AD application registration within a tenant, used for authentication and authorization.

  2. Which Microsoft Authentication Library (MSAL) method acquires a token silently from cache before making a network request?

    Answer: AcquireTokenSilent

    AcquireTokenSilent attempts to retrieve a valid token from the MSAL token cache without user interaction or a new network call.

  3. Which Azure Key Vault object type stores asymmetric cryptographic keys used for signing and encryption operations?

    Answer: Key

    Azure Key Vault Keys store RSA or EC cryptographic key material and support operations such as encrypt, decrypt, sign, and verify.

  4. Which Azure service enables you to centrally manage, rotate, and audit access to secrets across multiple applications and environments?

    Answer: Azure Key Vault

    Azure Key Vault provides centralized secret management with access logging, automated rotation, and RBAC-based access control.

  5. What header must a client include when calling an Azure AD-protected API to prove it has a valid access token?

    Answer: Authorization: Bearer {token}

    APIs protected by Azure AD expect the access token in the HTTP `Authorization` header using the `Bearer` scheme.

  6. Which Azure AD token type contains claims about the authenticated user and is intended to be read by the client application?

    Answer: ID token

    The ID token is a JWT issued by Azure AD that contains user identity claims such as name, email, and object ID for the client to consume.