← All AZ-204 Flashcard Decks

Technology & Digital Applications Flashcards

7 cards from real AZ-204 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Technology & Digital Applications flashcards as text
  1. A developer needs to read a secret from Azure Key Vault in a .NET application using DefaultAzureCredential. The app runs locally using a developer account and in production using a managed identity. What is the correct NuGet package to add?

    Answer: Azure.Security.KeyVault.Secrets and Azure.Identity

    Azure.Security.KeyVault.Secrets provides the SecretClient class, and Azure.Identity provides DefaultAzureCredential, which supports both local developer auth and managed identity in production.

  2. You need to monitor the performance of an Azure Function and receive an alert when the average execution duration exceeds 2 seconds over a 5-minute window. What should you configure?

    Answer: Create an Azure Monitor metric alert on the FunctionExecutionTimeMs metric

    Azure Monitor provides a built-in FunctionExecutionTimeMs metric for Azure Functions, which supports metric alert rules with configurable aggregation windows.

  3. An Azure Service Bus topic has three subscriptions. A message published to the topic must be received by all three subscriptions. After processing, each subscription's copy of the message should be deleted independently. Is this the default behavior?

    Answer: Yes — each subscription receives its own independent copy of every message

    Service Bus topics create an independent copy of each message for every subscription by default, enabling pub/sub fan-out where each subscriber processes at its own pace.

  4. You need to cache the results of an expensive database query in an Azure Function for 10 minutes. The function runs on a Consumption plan. What is the recommended approach?

    Answer: Use Azure Cache for Redis with a 10-minute TTL

    Azure Cache for Redis provides reliable, distributed caching with native TTL support; static in-memory caches are unreliable on Consumption plans because instances can be recycled at any time.

  5. You are deploying a containerized application to Azure Kubernetes Service (AKS). The app needs to read a connection string stored in Azure Key Vault. What is the most secure way to provide this?

    Answer: Use the Azure Key Vault Provider for Secrets Store CSI Driver to mount the secret as a volume

    The Secrets Store CSI Driver integrates AKS with Key Vault to mount secrets as volumes, leveraging workload identity with no credentials stored in the cluster or image.

  6. A developer uses Azure API Management to expose a backend API. Some API operations should only be accessible to users with the 'admin' role in their JWT token. How should you enforce this in APIM?

    Answer: Add a validate-jwt inbound policy that checks the roles claim

    The validate-jwt inbound policy in APIM can inspect JWT claims, including roles, and return a 403 if the required role is absent — enforcing authorization at the gateway layer.

  7. You need to implement idempotent message processing for an Azure Service Bus queue consumer. A message contains an 'OrderId'. What is the recommended approach?

    Answer: Check the OrderId against a processed-orders store before executing business logic and skip if already processed

    Checking against a persistent processed-orders store and skipping already-processed messages is the standard idempotent consumer pattern, protecting against duplicate processing regardless of message delivery guarantees.