โ† All Microsoft Certified: Azure Developer Associate Flashcard Decks

Azure Security, Identity, and Key Vault Flashcards

6 cards from real Microsoft Certified: Azure Developer Associate practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Azure Security, Identity, and Key Vault flashcards as text
  1. What is the purpose of the `on-behalf-of` (OBO) OAuth 2.0 flow in Azure AD?

    Answer: Allows a service to acquire tokens to call downstream APIs using the user's identity passed via an incoming token

    The OBO flow lets a middle-tier API exchange the user's incoming access token for a new token to call a downstream API, propagating the user's identity.

  2. What Azure AD Conditional Access signal can block token issuance if a user's device is not compliant with Intune policies?

    Answer: Device compliance condition

    Conditional Access can evaluate device compliance status (via Intune) and block or require remediation before granting tokens to apps.

  3. When storing a connection string in Azure Key Vault and referencing it in App Service, what is the format of a Key Vault reference?

    Answer: @Microsoft.KeyVault(SecretUri=https://...)

    App Service Key Vault references use the `@Microsoft.KeyVault(SecretUri=)` syntax in application settings to inject secrets at runtime.

  4. Which claim in a JWT access token issued by Azure AD uniquely identifies the user across all Azure AD tenants?

    Answer: oid (object ID)

    The `oid` claim is the immutable object ID of the user in Azure AD and is stable across tenant changes, unlike `sub` which is app-specific.

  5. What Azure AD application manifest property specifies which app roles are defined, enabling role-based access control within the application?

    Answer: appRoles

    `appRoles` in the Azure AD application manifest defines the roles that the application exposes, which can then be assigned to users, groups, or service principals.

  6. What is the recommended approach for rotating a Key Vault secret used by an Azure Function without downtime?

    Answer: Use Key Vault secret versioning with the latest version URI and allow App Service Key Vault references to auto-refresh

    Using the `latest` version URI in Key Vault references lets App Service/Functions automatically pick up the new secret version without restarts.