Azure Security & Identity Flashcards
6 cards from real AZ-204 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Azure Security & Identity flashcards as text
What is the purpose of Azure AD Application Roles defined in an app's manifest?
Answer: Implement role-based authorization within the application
Application Roles defined in the app manifest let you implement custom RBAC within your application using `roles` claims in the access token.
Which Azure Active Directory feature allows users from partner organizations to sign in to your application using their own credentials?
Answer: Azure AD B2B (External Identities)
Azure AD B2B (External Identities) lets you invite guest users from external organizations who authenticate with their own identity provider.
Which claim in an Azure AD access token uniquely identifies the tenant that issued the token?
Answer: tid
The `tid` claim contains the Azure AD tenant ID (GUID) of the directory that issued the token.
What Azure Key Vault feature enables automatic renewal of TLS certificates from supported certificate authorities?
Answer: Certificate auto-renewal (lifecycle action)
Key Vault certificates support lifecycle auto-renewal actions that automatically request a new certificate from DigiCert or GlobalSign before expiry.
Which Azure API Management policy enforces that incoming requests include a valid Azure AD JWT token?
Answer: validate-jwt
The `validate-jwt` policy in API Management validates the signature, issuer, audience, and expiration of a JWT bearer token.
Which Azure AD consent type must an administrator grant for an application to access organization-wide resources like all users' calendars?
Answer: Admin consent
Admin consent is required for application permissions and high-privilege delegated permissions that access data across the entire organization.