Research & Evidence-Based Practice Flashcards
7 cards from real AZ-204 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Research & Evidence-Based Practice flashcards as text
In Azure API Management, which policy scope applies to every API across all products within the APIM instance?
Answer: Global scope
Policies set at the global scope execute for every inbound and outbound call, making them the broadest applicable scope.
Which Azure Key Vault object type manages the full lifecycle of an X.509 certificate, including its associated private key?
Answer: Certificate
The Key Vault Certificate object handles issuance, renewal, and storage of X.509 certificates along with their private keys.
What is the key advantage of a user-assigned managed identity compared to a system-assigned managed identity?
Answer: It can be shared across multiple Azure resources simultaneously
A user-assigned managed identity has an independent lifecycle and can be attached to multiple resources, enabling identity reuse across services.
Which OAuth 2.0 grant type is appropriate for a daemon or background service that must authenticate to an API without any user interaction?
Answer: Client credentials
The client credentials flow lets a service authenticate using its own credentials (client ID and secret/certificate), with no user involved.
Which Azure API Management policy limits the number of calls a subscription can make within a specified time window to prevent abuse?
Answer: rate-limit-by-key
The rate-limit-by-key policy enforces a call-rate ceiling keyed on a value such as subscription ID, blocking requests that exceed the quota.
In Azure Key Vault, what does enabling soft-delete allow you to do?
Answer: Recover deleted vaults and objects within a retention period
Soft-delete retains deleted Key Vault resources for a configurable period (7–90 days), allowing recovery before permanent purge.
Which Azure API Management policy validates an OAuth 2.0 / OpenID Connect JWT and rejects requests with invalid or missing tokens?
Answer: validate-jwt
The validate-jwt policy inspects the Authorization header, verifies the token signature and claims, and returns 401 if validation fails.