Configure Site Settings with App Configuration

Implement Azure App Service Web Apps Implement secure Azure solutions
Answer Correct answer: A, C, D — Create a managed identity, create an Azure App Configuration store, and update the role assignments for the store to securely access centrally stored, encrypted settings without secrets.

Case study - This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided. To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study. At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section. To start the case study - To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. When you are ready to answer a question, click the Question button to return to the question. Background - Munson’s Pickles and Preserves Farm is an agricultural cooperative corporation based in Washington, US, with farms located across the United States. The company supports agricultural production resources by distributing seeds fertilizers, chemicals, fuel, and farm machinery to the farms. Current Environment - The company is migrating all applications from an on-premises datacenter to Microsoft Azure. Applications support distributors, farmers, and internal company staff. Corporate website - • The company hosts a public website located at http://www.munsonspicklesandpreservesfarm.com. The site supports farmers and distributors who request agricultural production resources. Farms - • The company created a new customer tenant in the Microsoft Entra admin center to support authentication and authorization for applications. Distributors - • Distributors integrate their applications with data that is accessible by using APIs hosted at http://www.munsonspicklesandpreservesfarm.com/api to receive and update resource data. Requirements - The application components must meet the following requirements: Corporate website - • The site must be migrated to Azure App Service. • Costs must be minimized when hosting in Azure. • Applications must automatically scale independent of the compute resources. • All code changes must be validated by internal staff before release to production. • File transfer speeds must improve, and webpage-load performance must increase. • All site settings must be centrally stored, secured without using secrets, and encrypted at rest and in transit. • A queue-based load leveling pattern must be implemented by using Azure Service Bus queues to support high volumes of website agricultural production resource requests. Farms - • Farmers must authenticate to applications by using Microsoft Entra ID. Distributors - • The company must track a custom telemetry value with each API call and monitor performance of all APIs. • API telemetry values must be charted to evaluate variations and trends for resource data. Internal staff - • App and API updates must be validated before release to production. • Staff must be able to select a link to direct them back to the production app when validating an app or API update. • Staff profile photos and email must be displayed on the website once they authenticate to applications by using their Microsoft Entra ID. Security - • All web communications must be secured by using TLS/HTTPS. • Web content must be restricted by country/region to support corporate compliance standards. • The principle of least privilege must be applied when providing any user rights or process access rights. • Managed identities for Azure resources must be used to authenticate services that support Microsoft Entra ID authentication. Issues - Corporate website - • Farmers report HTTP 503 errors at the same time as internal staff report that CPU and memory usage are high. • Distributors report HTTP 502 errors at the same time as internal staff report that average response times and networking traffic are high. • Internal staff report webpage load sizes are large and take a long time to load. • Developers receive authentication errors to Service Bus when they debug locally. Distributors - • Many API telemetry values are sent in a short period of time. Telemetry traffic, data costs, and storage costs must be reduced while preserving a statistically correct analysis of the data points sent by the APIs. You need to configure all site configuration settings for the corporate website. Which three actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

  1. Create a managed identity. Correct Answer
  2. Update the role assignments for the Azure Key Vault.
  3. Create an Azure App Configuration store. Correct Answer
  4. Update the role assignments for the Azure App Configuration store. Correct Answer
  5. Create an Azure Key Vault.

Community Votes

ACD
100%

100% of anonymous learners picked answer ACD. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the distinction between Azure App Configuration (for non-secret settings) and Key Vault (for secrets), requiring a managed identity for secure access.

This scenario establishes that to centrally store site settings encrypted at rest and in transit without using secrets, you must use Azure App Configuration with a managed identity. The correct actions are creating a managed identity, creating an App Configuration store, and updating its role assignments.

Choosing Azure Key Vault and its role assignments because of the encryption requirement, ignoring the explicit directive to secure settings without using secrets.

Community Discussion (4 comments)

AzDeveloper 👍 14 Selected: ACD
Why App Config? Because is required to be: "All site settings must be centrally stored, secured without using secrets, and encrypted at rest and in transit." Reference: Does App Configuration encrypt my data? https://learn.microsoft.com/en-us/azure/azure-app-configuration/faq
FeriAZ 👍 5 Selected: ACD
Create a managed identity: Managed identities in Azure are used for Azure service resources, providing an identity for applications to use when connecting to other Azure services. This helps in securely accessing other Azure resources without having to manage credentials in your code. Create an Azure App Configuration store: Azure App Configuration provides a service to centrally manage application settings and feature flags. It's a great way to handle configurations that need to be shared across several components or environments. Update the role assignments for the Azure App Configuration store: Similar to the Key Vault, setting up appropriate role assignments for the Azure App Configuration store is about controlling access based on the principle of least privilege. This action is crucial for ensuring that only authorized personnel or processes have access to the configuration data.
exeem 👍 1 Selected: AC
"All site settings must be centrally stored, secured without using secrets" - this excludes Azure Key Vault so we should focus on Azure App Config.
my_nickname2 👍 1 Selected: BCE
store app settings => App Config Store secure Settings encrypted => KeyVault access KeyVault => Update access assignments

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The requirement explicitly states that site settings must be centrally stored, secured without using secrets, and encrypted at rest and in transit. Azure App Configuration perfectly matches this by storing configurations centrally and encrypting them natively without treating them as secrets. To access this store securely without managing credentials, a managed identity (A) must be created, and it must be granted access via role assignments (D) on the App Configuration store (C).

Why the Other Options Are Wrong

Creating an Azure Key Vault (E) and updating its role assignments (B) are incorrect because Key Vault is designed specifically for storing secrets. The requirement explicitly mandates securing settings "without using secrets". While Key Vault does encrypt data, using it for standard configurations violates the architectural constraint of the requirement.

Community Comment Notes

Commenters highlight that App Configuration fulfills the requirement for settings to be "secured without using secrets" while still encrypting data, as AzDeveloper noted. FeriAZ added that managed identities provide secure access to Azure services without managing credentials in code, which aligns with the principle of least privilege.

Official Reference

Exam Strategy

Pay close attention to explicit constraints like "without using secrets" which rule out otherwise common services like Key Vault. Match the specific feature requirements (centralized, encrypted, non-secret settings) to the appropriate Azure service, which is App Configuration.

Related Analysis

← Back to AZ-204 Study Guide