โ† All Microsoft Certified: Azure Developer Associate Flashcard Decks

Azure Security, Identity, and Key Vault Flashcards

6 cards from real Microsoft Certified: Azure Developer Associate practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Azure Security, Identity, and Key Vault flashcards as text
  1. What is a managed identity in Azure, and what problem does it solve?

    Answer: A user account managed by Azure AD for service-to-service auth, eliminating stored credentials

    Managed identities are Azure AD identities automatically managed by Azure for services, removing the need to store and rotate credentials in code.

  2. What Azure Key Vault object type stores sensitive string values like API keys and connection strings?

    Answer: Secret

    Key Vault Secrets store arbitrary string values such as connection strings, passwords, and API keys with access control and audit logging.

  3. Which Azure AD application registration element proves the app's identity to Azure AD when requesting tokens?

    Answer: Client secret or certificate (credential)

    A client secret or certificate is the credential that proves the application's identity to Azure AD during the OAuth 2.0 client credentials flow.

  4. What OAuth 2.0 flow should a confidential server-side web app use to authenticate users via Azure AD?

    Answer: Authorization code flow

    The authorization code flow is the recommended OAuth flow for server-side apps, exchanging a code for tokens securely on the back channel.

  5. What Azure Key Vault feature automatically renews certificates before they expire?

    Answer: Certificate autorenew lifetime action

    Key Vault certificates support lifetime action policies that trigger automatic renewal a set number of days before expiry.

  6. Which MSAL (Microsoft Authentication Library) method acquires a token silently from the cache before falling back to interactive login?

    Answer: AcquireTokenSilent

    `AcquireTokenSilent` returns a cached or refreshed access token without user interaction, only prompting when silent acquisition fails.