You need to secure Azure Functions to meet the security requirements. Which two actions should you take? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Store the RSA-HSM key in Azure Key Vault and enable soft-delete and purge-protection., Create a standard-tier Azure App Configuration instance and assign it an Azure AD managed identity..
Why this is the answer
Storing RSA-HSM keys in Azure Key Vault with soft-delete and purge-protection enabled is a best practice for securing cryptographic keys. Key Vault is designed for secure storage and management of keys, secrets, and certificates, and soft-delete/purge-protection prevent accidental or malicious deletion. Creating a standard-tier Azure App Configuration instance and assigning it an Azure AD managed identity is correct because App Configuration centralizes application settings, and managed identities provide a secure, automatic way for Azure services to authenticate to other Azure AD-protected services without managing credentials. Storing keys in Blob Storage or Cosmos DB is not appropriate for cryptographic keys, as Key Vault is the dedicated secure solution. A free-tier App Configuration might lack necessary features for production, and registering a new service principal is less secure and more complex than using a managed identity.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed