← All AZ-204 Flashcard Decks

Professional Standards & Competencies Flashcards

7 cards from real AZ-204 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Professional Standards & Competencies flashcards as text
  1. A developer must protect an Azure Web API using OAuth 2.0. Which Azure service should they integrate to validate bearer tokens on incoming requests?

    Answer: Azure Active Directory with JWT bearer token validation middleware

    Integrating Azure AD JWT bearer token validation middleware ensures only requests with valid tokens issued by the configured authority are accepted.

  2. When writing unit tests for Azure Functions, which professional practice isolates the function logic from Azure SDK dependencies?

    Answer: Mocking Azure service clients and injecting them via dependency injection

    Mocking Azure SDK clients and injecting them via DI allows unit tests to run without real Azure resources, improving speed and reliability.

  3. An Azure developer is implementing feature flags for a progressive rollout. Which Azure service provides dynamic feature flag management without redeployment?

    Answer: Azure App Configuration with feature management

    Azure App Configuration's feature management capability allows feature flags to be toggled at runtime without requiring a new deployment.

  4. A developer needs to comply with SOC 2 controls by ensuring all data at rest in Azure Storage is encrypted. What is the correct professional action?

    Answer: Verify that Azure Storage Service Encryption is enabled, which is on by default

    Azure Storage Service Encryption encrypts all data at rest by default using AES-256, satisfying compliance requirements without additional configuration.

  5. A developer is following secure coding practices for an Azure-deployed web application. Which OWASP mitigation prevents SQL injection in Cosmos DB queries?

    Answer: Using parameterized queries with SqlQuerySpec in the Cosmos DB SDK

    Using SqlQuerySpec with named parameters prevents injection by separating query logic from user-supplied values in Cosmos DB SQL API queries.

  6. An Azure developer wants to adopt shift-left security by scanning for secrets in source code. Which tool integrates natively with Azure DevOps for this purpose?

    Answer: Microsoft Security DevOps extension with secret scanning in pipelines

    The Microsoft Security DevOps extension integrates secret scanning and static analysis tools directly into Azure DevOps pipelines during the build phase.

  7. A developer must implement structured logging in an Azure Function to enable efficient log querying in Application Insights. Which approach is correct?

    Answer: Use ILogger with message templates and structured property placeholders

    ILogger with message templates emits structured telemetry with named properties, enabling powerful filtering and analytics in Application Insights.