← All AZ-204 Flashcard Decks

Research & Evidence-Based Practice Flashcards

7 cards from real AZ-204 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Research & Evidence-Based Practice flashcards as text
  1. In Azure API Management, which policy scope applies to every API across all products within the APIM instance?

    Answer: Global scope

    Policies set at the global scope execute for every inbound and outbound call, making them the broadest applicable scope.

  2. Which Azure Key Vault object type manages the full lifecycle of an X.509 certificate, including its associated private key?

    Answer: Certificate

    The Key Vault Certificate object handles issuance, renewal, and storage of X.509 certificates along with their private keys.

  3. What is the key advantage of a user-assigned managed identity compared to a system-assigned managed identity?

    Answer: It can be shared across multiple Azure resources simultaneously

    A user-assigned managed identity has an independent lifecycle and can be attached to multiple resources, enabling identity reuse across services.

  4. Which OAuth 2.0 grant type is appropriate for a daemon or background service that must authenticate to an API without any user interaction?

    Answer: Client credentials

    The client credentials flow lets a service authenticate using its own credentials (client ID and secret/certificate), with no user involved.

  5. Which Azure API Management policy limits the number of calls a subscription can make within a specified time window to prevent abuse?

    Answer: rate-limit-by-key

    The rate-limit-by-key policy enforces a call-rate ceiling keyed on a value such as subscription ID, blocking requests that exceed the quota.

  6. In Azure Key Vault, what does enabling soft-delete allow you to do?

    Answer: Recover deleted vaults and objects within a retention period

    Soft-delete retains deleted Key Vault resources for a configurable period (7–90 days), allowing recovery before permanent purge.

  7. Which Azure API Management policy validates an OAuth 2.0 / OpenID Connect JWT and rejects requests with invalid or missing tokens?

    Answer: validate-jwt

    The validate-jwt policy inspects the Authorization header, verifies the token signature and claims, and returns 401 if validation fails.