Which Azure App Service Apps Can Use an Uploaded Private Certificate?

Plan and implement security for public access to Azure resources
Answer Correct answer: B — App1 and App2 only can use Cert1 because they share the same resource group, region, and operating system webspace.

You have an Azure subscription that contains the Azure App Service web apps shown in the following table. You upload a private key certificate named Cert1.pfx to App1. Which apps can use Cert1? - image

  1. App1 only
  2. App1 and App2 only Correct Answer
  3. App1 and App4 only
  4. App1, App2, and App3 only
  5. App1, App2, App3, and App4

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the App Service webspace sharing rule for private certificates, and the common trap is assuming the certificate is isolated to the single app it was uploaded to.

When a private certificate is uploaded to an Azure App Service web app, it is stored in a deployment unit (webspace) bound to the resource group, region, and OS. This page establishes that apps sharing these three attributes can use the certificate.

Choosing App1 only (Option A) because one assumes an uploaded private certificate is exclusively bound to the specific app rather than shared across the webspace.

Community Discussion (5 comments)

Pamban 👍 9 Selected: A
I would go with as as per below explanation After you add a private certificate to an app, the certificate is stored in a deployment unit that's bound to the App Service plan's resource group, region, and operating system combination, internally called a webspace. That way, the certificate is accessible to other apps in the same resource group, region, and OS combination. Private certificates uploaded or imported to App Service are shared with App Services in the same deployment unit. Link: https://learn.microsoft.com/en-us/azure/app-service/configure-ssl-certificate?tabs=apex
Jimmy500 👍 3
After you add a private certificate to an app, the certificate is stored in a deployment unit that's bound to the App Service plan's resource group, region, and operating system combination, internally called a webspace. That way, the certificate is accessible to other apps in the same resource group, region, and OS combination. Private certificates uploaded or imported to App Service are shared with App Services in the same deployment unit. You can add up to 1000 private certificates per webspace. I think A
Apptech 👍 1
Store certificate in Azure Key Vault: make sure to use the same subscription and resource group as your App Service app. For that reason only App1 and App2 can use Certificate. https://learn.microsoft.com/en-us/azure/app-service/configure-ssl-app-service-certificate?tabs=portal
Alagong 👍 1
Why not A?
jaci 👍 1
When you upload a certificate to App Service, it's stored in the App Service instance's Key Vault. Key Vault is a global service in Azure, meaning it can be accessed from different regions.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The correct answer is B because when a private key certificate is uploaded to an Azure App Service app, it is stored in a deployment unit called a webspace. This webspace is bound to the App Service plan's resource group, region, and operating system combination. Since App1 and App2 share the same resource group, region, and OS, they exist in the same webspace and both can use the certificate.

Why the Other Options Are Wrong

Option A is incorrect because it assumes the certificate is only available to the app it was uploaded to, ignoring the webspace sharing behavior. Options C, D, and E are incorrect because they include App3 or App4, which reside in different regions or resource groups and therefore exist in different webspaces, making the certificate inaccessible to them.

Community Comment Notes

Several commenters referenced the official documentation stating that a private certificate is stored in a deployment unit bound to the "resource group, region, and operating system combination". As Apptech noted, "only App1 and App2 can use Certificate" because they share these three attributes. Some users mistakenly selected A despite quoting this shared webspace behavior.

Official Reference

Exam Strategy

For App Service certificate questions, remember the 'webspace' rule: private certificates are shared across apps in the same resource group, region, and OS combination. Do not assume certificates are isolated to a single app.

Related Analysis

← Back to AZ-500 Study Guide