AZ-204 · Question #247
AZ-204 Question #247: Real Exam Question with Answer & Explanation
The correct answer is A: Create a user-assigned managed identity and assign role-based access controls.. To give a managed identity access to an Azure resource, you need to add a role to the target resource for that identity. Note: To easily authenticate access to other resources that are protected by Azure Active Directory (Azure AD) without having to sign in and provide credential
Question
You develop and deploy an Azure Logic app that calls an Azure Function app. The Azure Function app includes an OpenAPI (Swagger) definition and uses an Azure Blob storage account. All resources are secured by using Azure Active Directory (Azure AD). The Azure Logic app must securely access the Azure Blob storage account. Azure AD resources must remain if the Azure Logic app is deleted. You need to secure the Azure Logic app. What should you do?
Options
- ACreate a user-assigned managed identity and assign role-based access controls.
- BCreate an Azure AD custom role and assign the role to the Azure Blob storage account.
- CCreate an Azure Key Vault and issue a client certificate.
- DCreate a system-assigned managed identity and issue a client certificate.
- ECreate an Azure AD custom role and assign role-based access controls.
Explanation
To give a managed identity access to an Azure resource, you need to add a role to the target resource for that identity. Note: To easily authenticate access to other resources that are protected by Azure Active Directory (Azure AD) without having to sign in and provide credentials or secrets, your logic app can use a managed identity (formerly known as Managed Service Identity or MSI). Azure manages this identity for you and helps secure your credentials because you don't have to provide or rotate secrets. If you set up your logic app to use the system-assigned identity or a manually created, user- assigned identity, the function in your logic app can also use that same identity for authentication. https://docs.microsoft.com/en-us/azure/logic-apps/create-managed-service-identity https://docs.microsoft.com/en-us/azure/api-management/api-management-howto-mutual- certificates-for-clients
Community Discussion
No community discussion yet for this question.