โ† All AZ-204 Flashcard Decks

Risk Assessment & Management Flashcards

7 cards from real AZ-204 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Assessment & Management flashcards as text
  1. Your Azure Function processes financial transactions and you need to detect anomalous spending patterns in near real-time. Which Azure service best supports this risk detection scenario?

    Answer: Azure Stream Analytics with anomaly detection

    Azure Stream Analytics has built-in ML-based anomaly detection operators (AnomalyDetection_SpikeAndDip, AnomalyDetection_ChangePoint) ideal for real-time risk pattern analysis.

  2. When using Azure Key Vault references in App Service, what happens if the Key Vault secret is deleted or access is revoked?

    Answer: App Service throws a startup exception and the app becomes unavailable

    If Key Vault access fails during application startup or secret refresh, App Service throws an exception and the application becomes unavailable, surfacing the access risk immediately.

  3. You are implementing retry logic in an Azure SDK client for Cosmos DB. Which transient fault should NOT be retried automatically?

    Answer: 403 Forbidden

    A 403 Forbidden indicates an authorization failure (wrong key or missing permission), which is a permanent error that retrying will not resolve.

  4. Your application uses Azure Service Bus. To mitigate the risk of poison messages causing infinite processing loops, which feature should you configure?

    Answer: Dead-letter queue with MaxDeliveryCount

    Setting MaxDeliveryCount on a Service Bus queue causes messages that exceed the delivery limit to be moved to the dead-letter queue, preventing infinite retry loops.

  5. In Azure API Management, which policy can you use to protect a backend API from being overwhelmed by a sudden spike in requests (rate-based risk)?

    Answer: rate-limit-by-key

    The rate-limit-by-key policy in APIM throttles requests based on a configurable key (e.g., subscription, IP), protecting the backend from traffic spikes.

  6. A developer stores a connection string directly in Azure App Service application settings. What is the primary security risk and recommended mitigation?

    Answer: Connection strings in App Settings can be read by anyone with Contributor role; use Key Vault references

    Anyone with Contributor or Owner role on the App Service can view application settings; Key Vault references combined with managed identity remove the secret from plain-sight access.

  7. Which Azure Monitor feature allows you to define an alert that fires when the number of failed dependency calls from your application exceeds a threshold, enabling proactive risk response?

    Answer: Metric Alert on dependencies/failed

    Application Insights emits the dependencies/failed metric, and a Metric Alert on that signal triggers when failed dependency call counts breach the configured threshold.