Azure Security, Identity, and Key Vault Flashcards
6 cards from real Microsoft Certified: Azure Developer Associate practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Azure Security, Identity, and Key Vault flashcards as text
What is the purpose of the `on-behalf-of` (OBO) OAuth 2.0 flow in Azure AD?
Answer: Allows a service to acquire tokens to call downstream APIs using the user's identity passed via an incoming token
The OBO flow lets a middle-tier API exchange the user's incoming access token for a new token to call a downstream API, propagating the user's identity.
What Azure AD Conditional Access signal can block token issuance if a user's device is not compliant with Intune policies?
Answer: Device compliance condition
Conditional Access can evaluate device compliance status (via Intune) and block or require remediation before granting tokens to apps.
When storing a connection string in Azure Key Vault and referencing it in App Service, what is the format of a Key Vault reference?
Answer: @Microsoft.KeyVault(SecretUri=https://...)
App Service Key Vault references use the `@Microsoft.KeyVault(SecretUri=)` syntax in application settings to inject secrets at runtime.
Which claim in a JWT access token issued by Azure AD uniquely identifies the user across all Azure AD tenants?
Answer: oid (object ID)
The `oid` claim is the immutable object ID of the user in Azure AD and is stable across tenant changes, unlike `sub` which is app-specific.
What Azure AD application manifest property specifies which app roles are defined, enabling role-based access control within the application?
Answer: appRoles
`appRoles` in the Azure AD application manifest defines the roles that the application exposes, which can then be assigned to users, groups, or service principals.
What is the recommended approach for rotating a Key Vault secret used by an Azure Function without downtime?
Answer: Use Key Vault secret versioning with the latest version URI and allow App Service Key Vault references to auto-refresh
Using the `latest` version URI in Key Vault references lets App Service/Functions automatically pick up the new secret version without restarts.