exam questions

Exam AZ-400 All Questions

View all questions & answers for the AZ-400 exam

Exam AZ-400 topic 4 question 8 discussion

Actual exam question from Microsoft's AZ-400
Question #: 8
Topic #: 4
[All AZ-400 Questions]

SIMULATION -
You need to ensure that an Azure web app named az400-123456789-main can retrieve secrets from an Azure key vault named az400-123456789-kv1 by using a system managed identity.
The solution must use the principle of least privilege.
To complete this task, sign in to the Microsoft Azure portal.

Show Suggested Answer Hide Answer
Suggested Answer: See explanation below.
1. In Azure portal navigate to the az400-123456789-main app.
2. Scroll down to the Settings group in the left navigation.
3. Select Managed identity.
4. Within the System assigned tab, switch Status to On. Click Save.

Reference:
https://docs.microsoft.com/en-us/azure/app-service/overview-managed-identity

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Rams_84zO6n
Highly Voted 2 years, 1 month ago
web app must retrieve the secrets from KV. The solution stops short of that. It only create MI. It is missing the next step. The next step is go to KeyVault, access policies - click create, select permissions, select web app MI, click next and save. Do you agree?
upvoted 15 times
mshin
2 years, 1 month ago
Look at the 'Configure the web app to connect to Key Vault' section. It should clear up the doubts on how to setup az keyvault for web apps. KeyVault --> Access policies (Az Portal or Powershell) --> Select perms --> Select Object ID (Web app managed identity object) https://learn.microsoft.com/en-us/azure/key-vault/general/tutorial-net-create-vault-azure-web-app
upvoted 2 times
...
...
NgCK
Highly Voted 1 year, 6 months ago
1. Turn on System assigned managed identity for az400-123456789-main. (Based on role-based access control (RBAC) instead of access policy) 2. At the key vault az400-123456789-kv1, go to: Access control (IAM) > Add role assignment > Choose Key Vault Secrets User > choose assign access to managed identity > Click select members > Select the app system managed identity
upvoted 10 times
phantom31
11 months, 1 week ago
This is the way to do this in May 2024
upvoted 5 times
...
...
Christian_garcia_martin
Most Recent 2 months, 4 weeks ago
about the permissions to select question says "of least privilege" the question 9 of topic 4 "You create a Microsoft ASP.NET Core application. You plan to use Azure Key Vault to provide secrets to the application as configuration data. You need to create a Key Vault access policy to assign secret permissions to the application. The solution must use the principle of least privilege. Which secret permissions should you use?" the right answer is Get only , so in this lab in the section of Secret permissions only check Get and nothing else
upvoted 1 times
...
the permissions should be in secrets section , list and get
upvoted 1 times
...
chakanirban
10 months, 1 week ago
NO LAB on 6/21 - 9 am IST - 1 Case study , 6 new Q 1 YES NO series was new - 3 Q - I answered all No , because 2 will No and 1 Y JOB A depends JOB B JOB B on JOB C JOB C on JOB D who is dependent , who can run parallel 3 yes/ no
upvoted 4 times
...
ozbonny
1 year, 2 months ago
I followed the next steps in my own subscription: Create a web app set the identity in on, copy the identity id create a keyvault enable access policies because RBAC are set as default (you need to be user access admin or owner) go to add a new access policy select the permissions set the app identity id by pasting the identity id in the search box click on review and create and that's all
upvoted 3 times
...
meoukg
2 years, 5 months ago
I saw this question in the lab along with other 7 questions
upvoted 4 times
eliisiita1
2 years, 5 months ago
did you do the exam online?
upvoted 4 times
...
xda
1 year, 2 months ago
can comfirm the same (January 2024)
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago