โ† All AZ-204 Flashcard Decks

Azure Security & Identity Flashcards

6 cards from real AZ-204 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Azure Security & Identity flashcards as text
  1. Which Azure service allows an application to retrieve secrets without storing credentials in code or configuration files?

    Answer: Azure Key Vault

    Azure Key Vault centrally stores secrets, keys, and certificates so applications can retrieve them at runtime without hardcoding credentials.

  2. What type of Managed Identity is automatically created and tied to the lifecycle of a specific Azure resource?

    Answer: System-assigned managed identity

    A system-assigned managed identity is created automatically when you enable it on an Azure resource and is deleted when the resource is deleted.

  3. Which OAuth 2.0 flow should a daemon application use to acquire an Azure AD token when acting on its own behalf with no user interaction?

    Answer: Client Credentials flow

    The Client Credentials flow authenticates the application itself using a client ID and secret/certificate, with no user involved.

  4. What is the recommended way to allow an Azure App Service to read secrets from Azure Key Vault without managing credentials?

    Answer: Use a Key Vault reference with a system-assigned managed identity

    Key Vault references in App Service use the app's managed identity to fetch secrets automatically at runtime with no credential storage.

  5. Which Azure AD feature allows you to require multi-factor authentication for users accessing specific applications based on risk signals?

    Answer: Conditional Access

    Conditional Access policies evaluate signals such as user, location, device, and app to enforce access controls like MFA.

  6. Which role in Azure RBAC provides read-only access to Azure Key Vault secrets?

    Answer: Key Vault Secrets User

    The Key Vault Secrets User role grants read access (get, list) to secrets in Azure Key Vault using Azure RBAC permission model.