Azure Security, Identity, and Key Vault Flashcards
6 cards from real Microsoft Certified: Azure Developer Associate practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Azure Security, Identity, and Key Vault flashcards as text
What Azure AD consent type allows an administrator to grant permissions for all users in a tenant at once?
Answer: Admin consent
Admin consent grants an application's requested permissions to all users in the tenant, bypassing per-user consent for sensitive or organization-wide scopes.
What is the difference between delegated permissions and application permissions in Azure AD?
Answer: Delegated permissions act on behalf of a signed-in user; application permissions act as the application itself
Delegated permissions allow the app to act with the signed-in user's identity and privileges, while application permissions (app roles) allow the app to act as itself.
Which Azure Key Vault soft-delete feature protects against accidental deletion by retaining deleted vaults for a configurable period?
Answer: Soft delete
Soft delete retains deleted Key Vault resources for a retention period (default 90 days) during which they can be recovered.
What Azure service enables developers to use the `DefaultAzureCredential` class that automatically picks the best available credential?
Answer: Azure Identity SDK (`Azure.Identity`)
`DefaultAzureCredential` is part of the `Azure.Identity` library and tries a chain of credential sources (managed identity, env vars, CLI, etc.) in order.
What Azure AD feature issues short-lived access tokens scoped to a specific resource, reducing blast radius if a token is stolen?
Answer: Token lifetime policy
Token lifetime policies in Azure AD control how long access and refresh tokens are valid, limiting exposure if tokens are compromised.
Which Azure role must be assigned to allow an application's managed identity to read secrets from a Key Vault using RBAC authorization?
Answer: Key Vault Secrets User
The `Key Vault Secrets User` role grants read access to secret values, which is the minimum permission needed to retrieve secrets.