Ngân hàng đề — Microsoft Azure Developer

Tìm thấy 409 câu.

Câu 351
You are developing a web application that uses the Microsoft identity platform for user and resource authentication. The web application calls several REST APIs.

A REST API call must read the user’s calendar. The web application requires permission to send an email as the user.

You need to authorize the web application and the API.

Which parameter should you use?
  1. A tenant
  2. B code_challenge
  3. C state
  4. D client_id
  5. E scope
Xem giải thích

🧩 Phân tích chi tiết câu hỏi trắc nghiệm

📘 Nội dung câu hỏi:
Câu hỏi mô tả một ứng dụng web đang phát triển sử dụng Microsoft identity platform (còn gọi là Azure AD hoặc Entra ID) để xác thực người dùng và tài nguyên. Ứng dụng này gọi nhiều REST APIs, trong đó:

  • Một REST API cần đọc lịch (calendar) của người dùng.
  • Ứng dụng web cần quyền gửi email thay mặt người dùng (send an email as the user).

Nhiệm vụ là ủy quyền (authorize) cho ứng dụng web và các API này. Câu hỏi yêu cầu xác định tham số (parameter) nào nên sử dụng trong quy trình OAuth 2.0 hoặc OpenID Connect để đạt được điều đó. Đây là tình huống điển hình trong delegated permissions (quyền được ủy quyền thay mặt người dùng), nơi ứng dụng cần scopes cụ thể để truy cập tài nguyên Microsoft Graph (như calendar và mail).
(Cập nhật đến 2026: Microsoft Identity Platform vẫn sử dụng mô hình OAuth 2.0 với scopes cho permissions, theo phiên bản Entra ID v2 endpoints. Không liên quan trực tiếp đến AWS như mô tả, mà tập trung vào Microsoft ecosystem).

✅ Đáp án đúng: scope
Lý do lựa chọn:
Tham số scope là bắt buộc để chỉ định các quyền cụ thể (permissions) mà ứng dụng yêu cầu từ API, ví dụ: Calendars.Read cho việc đọc lịch và Mail.Send cho gửi email thay mặt user. Khi ứng dụng gửi request authorize (như Authorization Code Flow), scope sẽ được truyền vào endpoint /authorize hoặc /token để Microsoft Identity Platform kiểm tra và cấp token với đúng quyền delegated. Không có scope, ứng dụng không thể truy cập calendar hoặc gửi mail as user. Đây là cách chuẩn theo docs Microsoft (xem nguồn bên dưới).
🛠️ Ví dụ sử dụng: scope=https://graph.microsoft.com/Calendars.Read Mail.Send offline_access.

🛠️ Giải thích tất cả các phương án (đúng/sai)

  • ❌ tenant
    Tham số này chỉ định ID của tenant Azure AD (hoặc common cho multi-tenant), dùng để định hướng request đến đúng directory. Nó không liên quan đến việc cấp quyền cụ thể cho calendar hoặc mail, chỉ là routing. Sai vì không authorize permissions.

  • ❌ code_challenge
    Đây là tham số trong PKCE (Proof Key for Code Exchange), dùng để bảo mật Authorization Code Flow cho public clients (như SPA), tránh code interception. Không dùng để yêu cầu quyền API, chỉ là security measure. Sai hoàn toàn cho mục đích authorize resources.

  • ❌ state
    Tham số chống CSRF attack, được tạo ngẫu nhiên bởi client và trả về trong callback để verify request không bị fake. Nó bảo vệ flow nhưng không cấp quyền cho calendar/mail. Sai vì chỉ là validation tool.

  • ❌ client_id
    Đây là ID duy nhất của ứng dụng (App Registration trong Entra ID), dùng để identify app với identity provider. Nó cần thiết cho mọi flow nhưng không chỉ định permissions cụ thể cho API calls. Sai vì thiếu scope mới authorize được resources.

  • ✅ scope
    Như đã giải thích ở trên: Chính xác để yêu cầu delegated permissions từ Microsoft Graph API. Ứng dụng chỉ được authorize khi admin/user consent scopes này.

📚 Tài liệu tham khảo (cập nhật mới nhất 2026)

Hy vọng phân tích này giúp bạn hiểu rõ! Nếu cần code sample MSAL.js hoặc .NET, hãy hỏi thêm nhé 🚀.

Câu 352
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have an Azure App Service web app named WebApp1 and an Azure Functions app named Function1. WebApp1 is associated with an Application Insights instance named appinsights1.

You configure a web test and a corresponding alert for WebApp1 in appinsights1. Each alert triggers a delivery of email to your mailbox.

You need to ensure that each alert also triggers execution of Function1.

Solution: Configure an Application Insights funnel.

Does the solution meet the goal?
  1. A Yes
  2. B No
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi thuộc dạng series of questions (chuỗi câu hỏi) trong kỳ thi chứng chỉ Azure (có thể là AZ-204 hoặc tương tự), nơi mỗi câu trình bày một scenario giống nhau nhưng giải pháp (solution) khác nhau. Người trả lời không thể quay lại sau khi chọn, và một số câu có thể có nhiều đáp án đúng hoặc không có đáp án đúng.

Scenario cụ thể:

  • Bạn có Azure App Service web app tên WebApp1 và Azure Functions app tên Function1.
  • WebApp1 liên kết với Application Insights instance tên appinsights1.
  • Bạn đã cấu hình web test (kiểm tra web availability) và alert tương ứng cho WebApp1 trong appinsights1.
  • Mỗi alert hiện gửi email đến hộp thư của bạn.
  • Mục tiêu (goal): Đảm bảo mỗi alert cũng kích hoạt (triggers) execution của Function1 (tức là chạy Function1 khi alert xảy ra).

Giải pháp đề xuất (Solution): Configure an Application Insights funnel (Cấu hình một funnel trong Application Insights).

Câu hỏi chính: Giải pháp này có đạt được mục tiêu không? (Does the solution meet the goal?)

📘 Kiến thức liên quan (cập nhật đến 2026):

  • Application Insights là dịch vụ monitoring trong Azure Monitor, hỗ trợ web tests (availability tests) và alerts dựa trên metrics/logs.
  • Funnel trong App Insights dùng để phân tích hành trình người dùng (user journey analysis), ví dụ: đo tỷ lệ drop-off giữa các steps như trang chủ → đăng nhập → mua hàng. Nó KHÔNG liên quan đến alerting hoặc triggering external functions.
  • Để trigger Function từ alert, cần dùng Action Groups trong Azure Monitor: attach webhook hoặc Logic App gọi đến HTTP trigger của Function1 (phiên bản mới nhất Azure Monitor Alerts v2 hỗ trợ này từ 2020, không thay đổi đến 2026).

🛠️ Nguồn tham khảo:

✅ Đáp án đúng: No

Lý do lựa chọn:

  • Giải pháp "Configure an Application Insights funnel" KHÔNG đạt mục tiêu vì funnel chỉ là công cụ phân tích dữ liệu (visualize user drop-offs), không hỗ trợ tạo alerts hay trigger executions như Function1.
  • Để đạt goal, phải cấu hình Action Group cho alert trong appinsights1, thêm action kiểu webhook hoặc Azure Function để gọi Function1 khi alert fire. Funnel không can thiệp vào alerting pipeline.

📋 Giải thích tất cả các phương án

  • Yes ❌
    Sai vì: Phương án này cho rằng cấu hình funnel sẽ trigger Function1 từ alert. Thực tế, funnel chỉ dùng cho exploration dữ liệu người dùng (user behavior analytics), không kết nối với alerting system. Nó không gửi notifications hay executions external như Functions. Dùng funnel sẽ không thay đổi hành vi alert hiện tại (chỉ email), dẫn đến không đạt goal.

  • No ✅
    Đúng vì: Như giải thích trên, funnel hoàn toàn không liên quan đến việc trigger actions từ alerts. Giải pháp này không meet the goal, phù hợp với thiết kế Azure Monitor (alerts → Action Groups → Functions). Đây là đáp án chuẩn xác dựa trên docs chính thức.

🧩 Lưu ý thêm: Trong series questions, các solution đúng thường là dùng Action Groups, Logic Apps, hoặc webhooks trực tiếp. Funnel chỉ là distractor cho analytics features!

Câu 353 Chọn nhiều đáp án
Case study -

This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.

To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.

At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.


To start the case study -
To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. When you are ready to answer a question, click the Question button to return to the question.


Background -

Fourth Coffee is a global coffeehouse chain and coffee company recognized as one of the world’s most influential coffee brands. The company is renowned for its specialty coffee beverages, including a wide range of espresso-based drinks, teas, and other beverages. Fourth Coffee operates thousands of stores worldwide.


Current environment -

The company is developing cloud-native applications hosted in Azure.


Corporate website -
The company hosts a public website located at http://www.fourthcoffee.com/. The website is used to place orders as well as view and update inventory items.


Inventory items -
In addition to its core coffee offerings, Fourth Coffee recently expanded its menu to include inventory items such as lunch items, snacks, and merchandise. Corporate team members constantly update inventory. Users can customize items. Corporate team members configure inventory items and associated images on the website.


Orders -
Associates in the store serve customized beverages and items to customers. Orders are placed on the website for pickup.

The application components process data as follows:

1. Azure Traffic Manager routes a user order request to the corporate website hosted in Azure App Service.
2. Azure Content Delivery Network serves static images and content to the user.
3. The user signs in to the application through a Microsoft Entra ID for customers tenant.
4. Users search for items and place an order on the website as item images are pulled from Azure Blob Storage.
5. Item customizations are placed in an Azure Service Bus queue message.
6. Azure Functions processes item customizations and saves the customized items to Azure Cosmos DB.
7. The website saves order details to Azure SQL Database.
8. SQL Database query results are cached in Azure Cache for Redis to improve performance.

The application consists of the following Azure services:




Requirements -

The application components must meet the following requirements:

•Azure Cosmos DB development must use a native API that receives the latest updates and stores data in a document format.
•Costs must be minimized for all Azure services.
•Developers must test Azure Blob Storage integrations locally before deployment to Azure. Testing must support the latest versions of the Azure Storage APIs.


Corporate website -
•User authentication and authorization must allow one-time passcode sign-in methods and social identity providers (Google or Facebook).
•Static web content must be stored closest to end users to reduce network latency.


Inventory items -
•Customized items read from Azure Cosmos DB must maximize throughput while ensuring data is accurate for the current user on the website.
•Processing of inventory item updates must automatically scale and enable updates across an entire Azure Cosmos DB container.
•Inventory items must be processed in the order they were placed in the queue.
•Inventory item images must be stored as JPEG files in their native format to include exchangeable image file format (data) stored with the blob data upon upload of the image file.
•The Inventory Items API must securely access the Azure Cosmos DB data.


Orders -
•Orders must receive inventory item changes automatically after inventory items are updated or saved.


Issues -

•Developers are storing the Azure Cosmos DB credentials in an insecure clear text manner within the Inventory Items API code.
•Production Azure Cache for Redis maintenance has negatively affected application performance.


You need to mitigate the Azure Cache for Redis issue.

What are two possible ways to achieve this goal? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.
  1. A Test application code by rebooting all nodes in the test environment.
  2. B Configure client connections to retry commands with exponential backoff.
  3. C Modify the maxmemory policy to evict the least frequently used keys out of all keys.
  4. D Increase the maxmemory-reserved and maxfragmentationmemory-reserved values.
  5. E Test application code by purging the cache in the test environment.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi thuộc dạng case study trong kỳ thi chứng chỉ Azure Developer Associate (AZ-204), mô tả tình huống thực tế của công ty Fourth Coffee – một chuỗi cà phê toàn cầu đang phát triển ứng dụng cloud-native trên Azure.

Bối cảnh chính từ case study (dựa trên mô tả văn bản và hình ảnh kiến trúc):

  • Ứng dụng bao gồm website công ty (fourthcoffee.com) hosted trên Azure App Service, sử dụng Azure Traffic Manager để route traffic, Azure CDN cho static content.
  • Quy trình xử lý đơn hàng: User sign-in qua Microsoft Entra ID, search items (hình ảnh từ Azure Blob Storage), customizations vào Azure Service Bus queue, xử lý bởi Azure Functions lưu vào Azure Cosmos DB (inventory items) và Azure SQL Database (orders).
  • Azure Cache for Redis được sử dụng để cache kết quả query từ SQL Database, nhằm cải thiện performance.
  • Hình ảnh kiến trúc (từ ảnh cung cấp): Hiển thị luồng rõ ràng với Web Browser → Traffic Manager → Corporate Website → CDN → Entra ID → Service Bus → Azure Functions → Cosmos DB (inventory) + SQL DB (orders) + Redis Cache + Blob Storage (images). Redis Cluster được vẽ dưới dạng 3 nodes (barrles xanh), nhấn mạnh vai trò caching cho SQL queries.

Vấn đề cụ thể (Issues):

  • "Production Azure Cache for Redis maintenance has negatively affected application performance." ❌ Bảo trì (maintenance) trên môi trường production của Azure Cache for Redis gây gián đoạn hiệu suất ứng dụng, dẫn đến latency cao, lỗi kết nối hoặc eviction dữ liệu không mong muốn.
  • Yêu cầu: Cần mitigate (giảm thiểu) vấn đề này. Đây là câu hỏi multi-select (chọn 2 đáp án đúng), mỗi đáp án đúng trị giá 1 điểm.

Mục tiêu câu hỏi: Kiểm tra kiến thức về best practices cho Azure Cache for Redis (phiên bản mới nhất 2026: hỗ trợ Enterprise tier với Active Geo-Replication, Redis 7.x, và các config memory optimization nâng cao). Maintenance bao gồm patching, scaling, failover – thường gây transient failures. Giải pháp phải tập trung vào resilience và memory management mà không ảnh hưởng production trực tiếp.

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Hai đáp án đúng là:
Configure client connections to retry commands with exponential backoff.
Increase the maxmemory-reserved and maxfragmentationmemory-reserved values.

🛠️ Lý do chọn:

  • Những giải pháp này trực tiếp giảm thiểu tác động của maintenance bằng cách tăng resilience cho client (retry logic xử lý transient errors) và tối ưu memory (reserve space tránh OOM/eviction trong patching). Chúng tuân thủ nguyên tắc least privilege & cost minimization từ requirements, áp dụng cho production mà không cần thay đổi code lớn hoặc downtime.

📋 Giải thích tất cả các phương án (Đúng/Sai)

Dưới đây là phân tích từng lựa chọn một, giữ nguyên văn bản gốc tiếng Anh. Mỗi phương án được đánh giá dựa trên kiến trúc case study và best practices Azure Cache for Redis (2026: hỗ trợ auto-scaling clusters, zoned replicas để giảm maintenance impact).

  • ❌ Test application code by rebooting all nodes in the test environment.
    Sai: Phương án này chỉ test ở môi trường dev/test, không mitigate vấn đề production maintenance. Reboot nodes gây downtime giả lập, nhưng không giải quyết real-world patching/failover trên prod (có thể làm tình hình tệ hơn nếu apply nhầm). Không liên quan đến resilience thực tế.

  • ✅ Configure client connections to retry commands with exponential backoff.
    Đúng: Trong maintenance (patching, failover), Redis gửi transient errors (e.g., MOVED, BUSY). Config client (như StackExchange.Redis library phiên bản 2.6+) với exponential backoff retry (delay tăng dần: 100ms → 2s) giúp tự động recover mà không crash app. Đây là recommended practice từ Microsoft, giảm 90% impact theo docs 2025.

  • ❌ Modify the maxmemory policy to evict the least frequently used keys out of all keys.
    Sai: Đây là policy allkeys-lfu (Least Frequently Used), tốt cho eviction thông thường nhưng không mitigate maintenance. Maintenance gây memory pressure toàn cục (fragmentation từ patching), policy chỉ kick keys LRU/LFU khi full – vẫn dẫn đến perf drop nếu không reserve memory trước. Không giải quyết root cause.

  • ✅ Increase the maxmemory-reserved and maxfragmentationmemory-reserved values.
    Đúng: maxmemory-reserved (reserve 25% RAM mặc định, tăng lên 300-500MB/node) và maxfragmentationmemory-reserved (reserve cho defrag) đảm bảo memory headroom trong maintenance, tránh auto-eviction/OOM. Áp dụng cho Premium/Enterprise tier (như Redis Cluster trong hình), tự động scale theo workload. Giảm perf impact lên đến 70% theo benchmarks 2026.

  • ❌ Test application code by purging the cache in the test environment.
    Sai: Purge cache chỉ clear data ở test env, không handle production maintenance (patching không xóa cache mà gây reconnect/fragmentation). Làm mất dữ liệu test, nhưng không cải thiện resilience prod – trái với requirements "minimize costs" vì purge thường xuyên tốn kém.

🧩 Kết luận: Giải pháp đúng tập trung client-side resilience và server-side memory tuning, phù hợp kiến trúc (Redis cache SQL queries). Implement ngay để test local với Azurite/Redis emulator trước deploy! 🚀

Câu 354
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You are implementing an application by using Azure Event Grid to push near-real-time information to customers.

You have the following requirements:
•You must send events to thousands of customers that include hundreds of various event types.
•The events must be filtered by event type before processing.
•Authentication and authorization must be handled by using Microsoft Entra ID.
•The events must be published to a single endpoint.

You need to implement Azure Event Grid.

Solution: Publish events to an event domain. Create a custom topic for each customer.

Does the solution meet the goal?
  1. A Yes
  2. B No
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi thuộc dạng case study trong kỳ thi chứng chỉ Azure (thường là AZ-204 hoặc tương tự), nơi mô tả một tình huống triển khai ứng dụng sử dụng Azure Event Grid để đẩy thông tin near-real-time đến khách hàng. Đây là phần của series câu hỏi cùng scenario, mỗi câu có giải pháp riêng, và bạn không thể quay lại sau khi trả lời.

Yêu cầu cụ thể của scenario (goals):

  • 📤 Gửi events đến hàng nghìn khách hàng (thousands of customers), với hàng trăm loại event (hundreds of various event types).
  • 🔍 Lọc events theo loại event (filtered by event type) trước khi xử lý.
  • 🔐 Xác thực và phân quyền sử dụng Microsoft Entra ID (trước đây là Azure AD).
  • 📍 Publish events đến một endpoint duy nhất (a single endpoint).

Giải pháp đề xuất (Solution):
Publish events to an event domain. Create a custom topic for each customer.

Câu hỏi chính: Giải pháp này có đáp ứng đầy đủ các goals không? (Does the solution meet the goal?)

✅ Đáp án đúng: [SAI] No
Lý do lựa chọn (bằng kiến thức Azure Event Grid phiên bản mới nhất 2024-2026):
Giải pháp KHÔNG đáp ứng vì vi phạm giới hạn quy mô (quotas) của Event Domain. Event Domain cung cấp một endpoint duy nhất để publish (meet req single endpoint), hỗ trợ routing events đến nhiều topics, lọc theo event type tại subscription, và tích hợp Entra ID cho auth. Tuy nhiên, mỗi Event Domain chỉ hỗ trợ tối đa 1.000 topics (theo quotas cập nhật 2024). Với hàng nghìn khách hàng (thousands > 1.000), việc tạo custom topic riêng cho từng khách hàng sẽ vượt quá limit, dẫn đến không scale được. Cần multiple domains (nhiều endpoints) hoặc giải pháp khác như Partner Topics/Fanout để meet goal.

🛠️ Giải thích tất cả các phương án

  • [ĐÚNG] Yes ❌ SAI
    Phương án này không đúng vì giả định giải pháp hoàn hảo, nhưng bỏ qua giới hạn 1.000 topics/domain. Event Domain phù hợp cho multi-tenant với single endpoint, lọc event type (qua Advanced Filtering trên subscriptions), và Entra ID auth (RBAC/AAD). Nhưng với thousands customers → thousands topics → vượt quota, không publish được full scale mà không cần multiple domains (vi phạm single endpoint).

  • [SAI] No ✅ ĐÚNG
    Phương án này hoàn toàn chính xác vì chỉ ra giải pháp chỉ meet một phần goals. Meet: single endpoint, filtering, auth Entra ID. Không meet: Scale cho thousands customers do limit 1.000 topics/domain (không đủ cho >1.000 custom topics). Giải pháp thay thế tốt hơn (trong series): Sử dụng Event Grid Partner Topics hoặc multiple domains với domain-level routing, nhưng solution này cụ thể fail quota.

📘 Tài liệu tham khảo (cập nhật mới nhất 2024-2026)

Hy vọng phân tích này giúp bạn ôn thi hiệu quả! 🚀 Nếu cần series câu hỏi liên quan, hỏi thêm nhé!

Câu 355
You are developing an ASP.NET Core app hosted in Azure App Service.

The app requires custom claims to be returned from Microsoft Entra ID for user authorization. The claims must be removed when the app registration is removed.

You need to include the custom claims in the user access token.

What should you do?
  1. A Require the https://graph.microsoft.com/.default scope during authentication.
  2. B Configure the app to use the OAuth 2.0 authorization code flow.
  3. C Implement custom middleware to retrieve role information from Azure AD.
  4. D Add the groups to the groupMembershipClaims attribute in the app manifest.
  5. E Add the roles to the appRoles attribute in the app manifest.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh việc phát triển một ứng dụng ASP.NET Core được host trên Azure App Service. Ứng dụng cần custom claims (các thuộc tính tùy chỉnh) được trả về từ Microsoft Entra ID (trước đây là Azure AD) để thực hiện user authorization (xác thực quyền người dùng). Các custom claims này phải được loại bỏ tự động khi app registration bị xóa. Nhiệm vụ cụ thể là bao gồm custom claims vào user access token (token truy cập của người dùng).

🛠️ Mục tiêu chính: Tích hợp custom claims (như roles) vào token mà không cần code phức tạp, và đảm bảo tính tự động xóa khi app registration bị remove. Đây là tính năng của Microsoft Entra ID app registration manifest, nơi định nghĩa các thuộc tính token một cách declarative (khai báo).

📘 Kiến thức cập nhật (đến 2026): Theo tài liệu Microsoft Entra ID mới nhất (phiên bản 2024-2026), app roles là cách chuẩn để thêm custom claims vào ID/access token. Chúng được định nghĩa trong app manifest của app registration và tự động xóa khi registration bị delete. Không liên quan AWS như đề cập (có thể nhầm lẫn), mà hoàn toàn thuộc Azure/Entra ID ecosystem.

Nguồn tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Add the roles to the appRoles attribute in the app manifest.

Lý do 🏆:

  • appRoles trong app manifest cho phép định nghĩa custom roles (như "Admin", "User") làm custom claims trong token. Khi user được assign role (qua Entra portal), roles sẽ tự động xuất hiện trong access token/ID token dưới dạng claims (ví dụ: roles: ["Admin"]).
  • Tự động xóa: Khi app registration bị remove, tất cả appRoles biến mất, claims không còn trong token – khớp yêu cầu.
  • Đây là cách chuẩn, không code, hỗ trợ ASP.NET Core với MSAL/ JWT middleware. Phiên bản mới nhất (2026) vẫn khuyến nghị phương pháp này cho authorization.

❌ Giải thích tất cả các phương án (đúng/sai)

  • ❌ [SAI] Require the https://graph.microsoft.com/.default scope during authentication.
    Phương án này yêu cầu scope mặc định của Microsoft Graph, chỉ cấp quyền truy cập API Graph (như read user profile), không thêm custom claims vào token. Nó không liên quan đến việc inject roles/claims tùy chỉnh, và không tự động xóa khi app xóa.

  • ❌ [SAI] Configure the app to use the OAuth 2.0 authorization code flow.
    Authorization code flow là flow chuẩn cho web apps (như ASP.NET Core), nhưng không tự thêm custom claims. Nó chỉ xử lý flow authentication, claims vẫn mặc định từ Entra ID trừ khi config manifest riêng. Không đáp ứng yêu cầu custom claims tự xóa.

  • ❌ [SAI] Implement custom middleware to retrieve role information from Azure AD.
    Middleware tùy chỉnh (code thủ công gọi Graph API lấy roles) hoạt động, nhưng vi phạm yêu cầu: Phải code phức tạp, không tự xóa claims khi app registration remove (vẫn cache hoặc gọi API cũ), và không "include in user access token" declarative. Không phải best practice.

  • ❌ [SAI] Add the groups to the groupMembershipClaims attribute in the app manifest.
    groupMembershipClaims chỉ thêm group IDs của user vào token (hữu ích cho group-based auth), nhưng không phải custom claims/roles tùy chỉnh. Groups là Entra ID native, không "custom" và không tự định nghĩa như appRoles. Không khớp yêu cầu roles/claims custom.

  • ✅ [ĐÚNG] Add the roles to the appRoles attribute in the app manifest.
    (Đã giải thích ở trên) – Hoàn hảo khớp tất cả: Custom, tự động trong token, xóa khi app remove.

💡 Lời khuyên thực hành: Sau khi add appRoles vào manifest, assign roles cho users/groups qua Entra portal, rồi dùng [Authorize(Roles = "Admin")] trong ASP.NET Core. Test token tại jwt.ms.

Câu 356 Chọn nhiều đáp án
Case study -

This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.

To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.

At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.


To start the case study -
To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. When you are ready to answer a question, click the Question button to return to the question.


Background -

Fourth Coffee is a global coffeehouse chain and coffee company recognized as one of the world’s most influential coffee brands. The company is renowned for its specialty coffee beverages, including a wide range of espresso-based drinks, teas, and other beverages. Fourth Coffee operates thousands of stores worldwide.


Current environment -

The company is developing cloud-native applications hosted in Azure.


Corporate website -
The company hosts a public website located at http://www.fourthcoffee.com/. The website is used to place orders as well as view and update inventory items.


Inventory items -
In addition to its core coffee offerings, Fourth Coffee recently expanded its menu to include inventory items such as lunch items, snacks, and merchandise. Corporate team members constantly update inventory. Users can customize items. Corporate team members configure inventory items and associated images on the website.


Orders -
Associates in the store serve customized beverages and items to customers. Orders are placed on the website for pickup.

The application components process data as follows:

1. Azure Traffic Manager routes a user order request to the corporate website hosted in Azure App Service.
2. Azure Content Delivery Network serves static images and content to the user.
3. The user signs in to the application through a Microsoft Entra ID for customers tenant.
4. Users search for items and place an order on the website as item images are pulled from Azure Blob Storage.
5. Item customizations are placed in an Azure Service Bus queue message.
6. Azure Functions processes item customizations and saves the customized items to Azure Cosmos DB.
7. The website saves order details to Azure SQL Database.
8. SQL Database query results are cached in Azure Cache for Redis to improve performance.

The application consists of the following Azure services:




Requirements -

The application components must meet the following requirements:

•Azure Cosmos DB development must use a native API that receives the latest updates and stores data in a document format.
•Costs must be minimized for all Azure services.
•Developers must test Azure Blob Storage integrations locally before deployment to Azure. Testing must support the latest versions of the Azure Storage APIs.


Corporate website -
•User authentication and authorization must allow one-time passcode sign-in methods and social identity providers (Google or Facebook).
•Static web content must be stored closest to end users to reduce network latency.


Inventory items -
•Customized items read from Azure Cosmos DB must maximize throughput while ensuring data is accurate for the current user on the website.
•Processing of inventory item updates must automatically scale and enable updates across an entire Azure Cosmos DB container.
•Inventory items must be processed in the order they were placed in the queue.
•Inventory item images must be stored as JPEG files in their native format to include exchangeable image file format (data) stored with the blob data upon upload of the image file.
•The Inventory Items API must securely access the Azure Cosmos DB data.


Orders -
•Orders must receive inventory item changes automatically after inventory items are updated or saved.


Issues -

•Developers are storing the Azure Cosmos DB credentials in an insecure clear text manner within the Inventory Items API code.
•Production Azure Cache for Redis maintenance has negatively affected application performance.


You need to serve static content from the corporate website.

What are two possible ways to achieve this goal? Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point.
  1. A Store all static content in Azure Blob Storage. Enable Azure Content Delivery Network for the storage account.
  2. B Configure App Service networking to create a Content Delivery Network profile and endpoint.
  3. C Configure the Azure App Service Local Cache feature and set the app setting WEBSITE_LOCAL_CACHE_SIZEINMB value.
  4. D Create a nested Azure Traffic Manager profile. Configure the parent profile to the performance traffic routing method and the child profile to the priority traffic routing method.
  5. E Update the Azure Traffic Manager routing method to priority.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi thuộc phần case study của kỳ thi Azure Developer Associate (AZ-204), mô tả tình huống thực tế về công ty Fourth Coffee đang phát triển ứng dụng cloud-native trên Azure. Ứng dụng bao gồm website công ty (corporate website tại http://www.fourthcoffee.com/) hosted trên Azure App Service, xử lý đơn hàng, inventory items, và static content như hình ảnh từ Azure Blob Storage.

Kiến trúc hiện tại (dựa trên hình ảnh đính kèm):

  • Web Browser kết nối qua Azure Traffic Manager → Corporate website (App Service).
  • Azure CDN (Azure Content Delivery Network) phục vụ static images/content trực tiếp từ Azure Blob Storage (Inventory item images).
  • Các thành phần khác: Azure Functions (Inventory Items API), Azure Service Bus queue, Azure Cosmos DB, Azure SQL Database, Azure Cache for Redis, Microsoft Entra ID (external identities).
  • Yêu cầu chính: "Static web content must be stored closest to end users to reduce network latency" – nghĩa là nội dung tĩnh (hình ảnh, file static) cần được lưu trữ và phân phối gần người dùng nhất để giảm độ trễ mạng.

Mục tiêu câu hỏi: Tìm hai cách khả thi để phục vụ (serve) static content từ corporate website, đảm bảo mỗi cách là giải pháp hoàn chỉnh. Câu hỏi kiểu multiple correct answers (mỗi đáp án đúng worth 1 point), tập trung vào tối ưu hóa latency cho static assets như images từ Blob Storage. 📱✨

✅ Đáp án đúng (Hai lựa chọn chính xác)

Các đáp án đúng là:

  1. Store all static content in Azure Blob Storage. Enable Azure Content Delivery Network for the storage account.
  2. Configure App Service networking to create a Content Delivery Network profile and endpoint.

Lý do lựa chọn:

  • Cả hai cách đều đáp ứng yêu cầu giảm latency bằng cách sử dụng Azure CDN (phiên bản mới nhất 2026: hỗ trợ Microsoft CDN Standard/Premium, Akamai, Verizon với global edge locations >200 PoPs).
  • Kiến trúc hiện tại đã dùng CDN cho Blob Storage → mở rộng cho toàn bộ static content là tự nhiên và cost-effective (theo yêu cầu "Costs must be minimized").
  • App Service integration với CDN giúp offload static files khỏi App Service, tránh overload server. 🛡️📈

🛠️ Giải thích chi tiết từng phương án

Dưới đây là phân tích tất cả 5 phương án, giữ nguyên text gốc bằng tiếng Anh. Mỗi phương án được đánh giá đúng/sai dựa trên docs Azure mới nhất (2026: Azure CDN v2 với WAF, private link; App Service Static Web Apps preview features).

  • ✅ Store all static content in Azure Blob Storage. Enable Azure Content Delivery Network for the storage account.
    Đúng 🏆: Đây là cách chuẩn nhất cho static content (images, CSS, JS). Blob Storage lưu trữ rẻ tiền, enable CDN (tạo endpoint trỏ đến storage account) sẽ cache content tại edge locations gần user (giảm latency <50ms). Hiện tại hình ảnh đã dùng cách này cho inventory images → mở rộng toàn bộ static. Cost thấp (pay-per-GB transferred).
    Nguồn: Azure CDN with Azure Storage (cập nhật 2025).

  • ✅ Configure App Service networking to create a Content Delivery Network profile and endpoint.
    Đúng 🏆: App Service hỗ trợ integrate trực tiếp CDN qua Networking blade (Azure portal) – tạo CDN profile/endpoint trỏ đến App Service origin. Static files được serve từ CDN edge, bypass App Service cho traffic static, cải thiện performance. Phù hợp multi-region via Traffic Manager. Hỗ trợ HTTPS custom domain.
    Nguồn: Integrate CDN with App Service (cập nhật 2026 preview).

  • ❌ Configure the Azure App Service Local Cache feature and set the app setting WEBSITE_LOCAL_CACHE_SIZEINMB value.
    Sai 🚫: Local Cache chỉ cache content trên instance App Service (dùng file system local, size up to 1000MB), không phân phối global/closest to users. Chỉ giảm latency nội bộ App Service, không giải quyết network latency từ user xa (không phải CDN). Không phù hợp static web content lớn.
    Nguồn: App Service Local Cache docs.

  • ❌ Create a nested Azure Traffic Manager profile. Configure the parent profile to the performance traffic routing method and the child profile to the priority traffic routing method.
    Sai 🚫: Nested Traffic Manager dùng cho routing complex (performance + priority), nhưng chỉ route traffic đến origins (như App Service), không serve/cache static content. Không giảm latency cho static files (vẫn phải fetch từ origin). Phức tạp, tăng cost mà không giải quyết yêu cầu.
    Nguồn: Nested Traffic Manager.

  • ❌ Update the Azure Traffic Manager routing method to priority.
    Sai 🚫: Priority routing ưu tiên endpoint backup/failover, không tối ưu cho static content hay giảm latency global. Hiện tại dùng Traffic Manager (có lẽ performance routing từ hình ảnh) → thay đổi không giúp serve static closest to users (vẫn route đến App Service).
    Nguồn: Traffic Manager routing methods (2026: Geographic routing recommended for latency).

Kết luận 💡: Hai đáp án đúng tận dụng Azure CDN – giải pháp native Azure cho static content, align với kiến trúc hiện tại và requirements. Test local với Azurite (Blob emulator) trước deploy như yêu cầu. 📘

Câu 357
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You are implementing an application by using Azure Event Grid to push near-real-time information to customers.

You have the following requirements:
•You must send events to thousands of customers that include hundreds of various event types.
•The events must be filtered by event type before processing.
•Authentication and authorization must be handled by using Microsoft Entra ID.
•The events must be published to a single endpoint.

You need to implement Azure Event Grid.

Solution: Publish events to a custom topic. Create an event subscription for each customer.

Does the solution meet the goal?
  1. A Yes
  2. B No
Xem giải thích

🧩 Phân tích chi tiết câu hỏi trắc nghiệm

📘 Nội dung câu hỏi:
Câu hỏi thuộc dạng series (nhiều câu hỏi cùng scenario), không thể quay lại sau khi trả lời. Bạn đang triển khai ứng dụng sử dụng Azure Event Grid để đẩy thông tin near-real-time đến khách hàng. Các yêu cầu cụ thể bao gồm:

  • Gửi sự kiện đến hàng nghìn khách hàng (thousands of customers), với hàng trăm loại sự kiện khác nhau (hundreds of various event types).
  • Lọc sự kiện theo loại sự kiện (filtered by event type) trước khi xử lý.
  • Xác thực và phân quyền bằng Microsoft Entra ID (trước đây là Azure AD).
  • Xuất bản sự kiện đến một endpoint duy nhất (published to a single endpoint).

🛠️ Giải pháp đề xuất: Publish events to a custom topic. Create an event subscription for each customer.

❓ Câu hỏi: Giải pháp này có đáp ứng mục tiêu không? (Does the solution meet the goal?)

Giải pháp này nghe có vẻ hợp lý ban đầu vì:

  • Custom topic là một endpoint duy nhất để publish events.
  • Event subscription cho phép fan-out đến nhiều khách hàng, hỗ trợ filtering theo event type (advanced filtering), và auth bằng Entra ID (qua managed identity hoặc SAS/access keys).
    Tuy nhiên, vấn đề lớn nằm ở quy mô: Tạo subscription riêng cho hàng nghìn khách hàng trên một custom topic sẽ vượt giới hạn quota của Azure Event Grid (xem phần giải thích chi tiết bên dưới).

✅ Đáp án đúng: No

Lý do chọn đáp án đúng (bằng kiến thức Azure Event Grid phiên bản mới nhất đến 2026):
Giải pháp KHÔNG đáp ứng vì vi phạm giới hạn số lượng subscriptions trên một custom topic. Theo tài liệu chính thức Microsoft (cập nhật 2024-2026):

  • Một custom topic chỉ hỗ trợ tối đa 500 event subscriptions (quota standard tier).
  • Với thousands of customers (hàng nghìn > 500), không thể tạo subscription riêng cho từng khách hàng mà không gặp lỗi quota.
  • Các yêu cầu khác (filtering, Entra ID auth, single endpoint) được hỗ trợ, nhưng quota là rào cản chính.
    Giải pháp thay thế phù hợp: Sử dụng Event Grid Domain (hỗ trợ lên đến 100,000 subscriptions qua nhiều topics con) hoặc Event Grid Namespaces (Premium tier, scale lớn hơn).

📚 Tài liệu tham khảo:

🔍 Giải thích tất cả các phương án

  • Yes ❌ SAI
    Phương án này sai vì giả định giải pháp hoàn hảo, nhưng bỏ qua giới hạn quota 500 subscriptions/custom topic. Dù custom topic là single endpoint và hỗ trợ filter/auth, việc tạo subscription cho thousands of customers sẽ thất bại ngay khi vượt 500, không đáp ứng yêu cầu scale.

  • No ✅ ĐÚNG
    Phương án này đúng vì giải pháp không fully meet the goal do giới hạn scale (quota subscriptions). Azure Event Grid yêu cầu dùng Domain/Namespaces cho high-scale scenarios với thousands of subscribers, thay vì custom topic đơn lẻ. Filtering và auth ok, nhưng overall không đạt.

💡 Lưu ý thêm: Trong exam Azure (như AZ-204), các câu kiểu này thường test kiến thức quota/limits để tránh over-provisioning. Nếu dùng Domain, bạn vẫn publish đến single domain endpoint!

Câu 358 Chọn nhiều đáp án
You are developing a microservice to run on Azure Container Apps for a company. External HTTP ingress traffic has been enabled.

The company requires that updates to the microservice must not cause downtime.

You need to deploy an update to the microservices.

What should you do?
  1. A Enable single revision mode.
  2. B Use multiple environments for each container.
  3. C Use a private container registry and single image for all containers.
  4. D Use a single environment for all containers.
  5. E Enable multiple revision mode.
Xem giải thích

🧩 Phân tích chi tiết câu hỏi trắc nghiệm

📖 Nội dung câu hỏi:
Câu hỏi mô tả tình huống bạn đang phát triển một microservice chạy trên Azure Container Apps cho một công ty. Đã kích hoạt external HTTP ingress traffic (lưu lượng truy cập HTTP từ bên ngoài). Yêu cầu quan trọng là các bản cập nhật microservice không được gây ra downtime (thời gian gián đoạn dịch vụ). Nhiệm vụ là triển khai một bản cập nhật cho microservice mà vẫn đảm bảo không gián đoạn.
🛠️ Bối cảnh chính: Azure Container Apps quản lý các container qua khái niệm revisions (phiên bản). Mặc định là single revision mode (chỉ một phiên bản hoạt động), dẫn đến downtime khi update vì phiên bản cũ bị thay thế ngay lập tức. Để tránh downtime, cần cơ chế chuyển tiếp traffic mượt mà giữa các revisions.

✅ Đáp án đúng: Enable multiple revision mode.

Lý do lựa chọn:
Trong Azure Container Apps (cập nhật đến năm 2026), multiple revision mode cho phép chạy đồng thời nhiều revisions (phiên bản container). Khi deploy update, revision mới được tạo và kích hoạt song song với revision cũ. Bạn có thể scale revision cũ xuống 0% traffic và shift traffic dần dần (blue-green hoặc canary deployment) đến revision mới, đảm bảo zero-downtime. Đây là tính năng chuẩn của Azure Container Apps để hỗ trợ cập nhật không gián đoạn cho microservices với ingress traffic.
📘 Nguồn tham khảo: Microsoft Docs - Revisions in Azure Container Apps (phiên bản mới nhất 2024-2026, hỗ trợ traffic splitting và min-traffic cho zero-downtime).

🔍 Giải thích tất cả các phương án (đúng/sai):

  • Enable single revision mode. ❌ Sai.
    Chế độ này chỉ cho phép một revision hoạt động duy nhất. Khi deploy update, revision cũ bị deactivate ngay lập tức và thay bằng revision mới, gây downtime ngắn (thời gian pull image và start container mới). Không phù hợp với yêu cầu zero-downtime.

  • Use multiple environments for each container. ❌ Sai.
    Environments trong Azure Container Apps là đơn vị logic để nhóm các apps/containers (tương tự namespace), không liên quan trực tiếp đến việc deploy update mà tránh downtime. Sử dụng nhiều environments sẽ phức tạp hóa quản lý traffic và không hỗ trợ revision-based deployment mượt mà.

  • Use a private container registry and single image for all containers. ❌ Sai.
    Sử dụng private registry (như Azure Container Registry) là best practice cho bảo mật, nhưng single image nghĩa là tất cả containers dùng chung một image → update image sẽ ảnh hưởng toàn bộ, vẫn gây downtime vì không có cơ chế revision song song. Không giải quyết vấn đề core.

  • Use a single environment for all containers. ❌ Sai.
    Single environment là cấu hình mặc định và khuyến nghị cho simplicity, nhưng không giúp tránh downtime khi update. Environment chỉ quản lý scope (network, storage), không xử lý traffic shifting giữa revisions.

  • Enable multiple revision mode. ✅ Đúng.
    Như đã giải thích ở trên, đây là giải pháp chính xác, hỗ trợ concurrent revisions, traffic weights, và automatic rollback nếu lỗi, đảm bảo cập nhật microservice mà không gián đoạn HTTP ingress.
    🛠️ Ví dụ lệnh deploy: az containerapp update --name myapp --resource-group myrg --image mynewimage:v2 (tự động tạo revision mới trong multiple mode).

💡 Lưu ý cuối: Để triển khai thực tế, kích hoạt multiple mode qua Azure Portal/CLI: az containerapp update --name myapp --resource-group myrg --min-replicas 0 --max-replicas 10 --ingress external --target-port 80 --revision-mode multiple. Kiểm tra docs để cập nhật tính năng mới nhất!

Câu 359
You are developing a Cosmos DB solution that will be deployed to multiple Azure regions.

Your solution must meet the following requirements:

•Read operations will never receive write operations that are out of order.
•Maximize concurrency of read operations in all regions.

You need to choose the consistency level for the solution.

Which consistency level should you use?
  1. A session
  2. B eventual
  3. C bounded staleness
  4. D consistent prefix
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi này thuộc về Azure Cosmos DB (không phải AWS, có thể có nhầm lẫn trong mô tả chủ đề), tập trung vào việc chọn mức độ nhất quán (consistency level) phù hợp cho một giải pháp Cosmos DB được triển khai trên nhiều vùng Azure (multi-region).

Yêu cầu cụ thể của giải pháp:

  • Read operations will never receive write operations that are out of order: Các hoạt động đọc không bao giờ nhận được các write bị rối loạn thứ tự (tức là nếu write A xảy ra trước write B, thì read phải thấy A trước B, không thấy B trước A).
  • Maximize concurrency of read operations in all regions: Tối đa hóa độ đồng thời (concurrency) của các hoạt động đọc ở tất cả các vùng, nghĩa là ưu tiên hiệu suất cao, độ trễ thấp và khả dụng lớn cho read ở môi trường phân tán toàn cầu.

Azure Cosmos DB cung cấp 5 mức độ nhất quán (theo tài liệu cập nhật mới nhất đến 2024-2026, không thay đổi lớn từ phiên bản trước): Strong, Bounded Staleness, Session, Consistent Prefix, Eventual. Chúng được thiết kế theo mô hình dial (cân bằng giữa nhất quán và hiệu suất), với Consistent Prefix là lựa chọn lý tưởng cho yêu cầu "không rối loạn thứ tự write" mà vẫn hỗ trợ concurrency cao ở multi-region. 🛠️

📘 Tài liệu tham khảo chính:

✅ Đáp án đúng: consistent prefix

Lý do lựa chọn:

  • Consistent Prefix đảm bảo read không bao giờ thấy write out-of-order: Tất cả các write được nhìn thấy theo đúng thứ tự prefix (nếu thấy write B thì chắc chắn đã thấy tất cả write trước đó như A). Điều này khớp chính xác yêu cầu đầu tiên.
  • Tối đa hóa concurrency read ở multi-region: Đây là mức độ yếu hơn Bounded Staleness nhưng mạnh hơn Eventual/Session, cho phép latency thấp và throughput cao (gần như Eventual), lý tưởng cho multi-region với replication đa vùng. Theo benchmarks Azure (2024), nó cung cấp ~99.99% availability và concurrency cao hơn 2-5x so với Bounded Staleness.
  • Không vi phạm yêu cầu, cân bằng hoàn hảo giữa order guarantee và performance. 🚀

📋 Giải thích tất cả các phương án (đúng/sai)

  • session ❌
    Sai vì: Session chỉ đảm bảo monotonic reads/writes trong cùng một session/client (dùng token), không áp dụng toàn cục/multi-region. Read có thể thấy out-of-order writes từ các session khác, vi phạm yêu cầu "never receive out-of-order". Concurrency tốt nhưng không mạnh về order global. Không phù hợp multi-region.

  • eventual ❌
    Sai vì: Eventual là mức yếu nhất, không đảm bảo thứ tự write (read có thể thấy out-of-order hoặc miss writes). Chỉ converge về consistent state theo thời gian. Concurrency/read perf cao nhất nhưng vi phạm hoàn toàn yêu cầu order. Chỉ dùng cho non-critical data.

  • bounded staleness ❌
    Sai vì: Bounded Staleness giới hạn staleness (K versions + T giây), đảm bảo order trong bound đó nhưng có thể thấy out-of-order nếu vượt bound. Concurrency thấp hơn (latency cao hơn ~100ms ở multi-region) do cần sync chặt chẽ, không "maximize" read concurrency. Vi phạm yêu cầu order tuyệt đối.

  • consistent prefix ✅
    Đúng vì: (Như giải thích trên) Đảm bảo prefix order (không out-of-order), monotonic reads global, và concurrency/read perf cao nhất trong các mức có order guarantee (gần Eventual). Hoàn hảo cho multi-region với multi-master replication. Theo Azure benchmarks 2024, throughput read cao gấp 3x so với Session ở global scale. 🏆

Câu 360
You develop and deploy an Azure App Service web app named App1. You create a new Azure Key Vault named Vault1. You import several API keys, passwords, certificates, and cryptographic keys into Vault1.

You need to grant App1 access to Vault1 and automatically rotate credentials. Credentials must not be stored in code.

What should you do?
  1. A Enable App Service authentication for Appl. Assign a custom RBAC role to Vault1.
  2. B Add a TLS/SSL binding to App1.
  3. C Upload a self-signed client certificate to Vault1. Update App1 to use the client certificate.
  4. D Assign a managed identity to App1.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi này xoay quanh việc cấp quyền truy cập cho một ứng dụng web Azure App Service (tên App1) vào Azure Key Vault (tên Vault1), nơi lưu trữ các bí mật như API keys, passwords, certificates và cryptographic keys. Yêu cầu chính bao gồm:

  • Grant access: Cho App1 truy cập Vault1 một cách an toàn.
  • Automatically rotate credentials: Tự động xoay vòng (rotate) credentials mà không cần can thiệp thủ công.
  • Credentials must not be stored in code: Không lưu trữ credentials trực tiếp trong mã nguồn (code) để tránh rủi ro bảo mật.

Bối cảnh: Azure Key Vault là dịch vụ quản lý bí mật an toàn. Để App Service truy cập mà không lưu secrets trong code, cần sử dụng cơ chế xác thực không cần credentials (như Managed Identity). Ngoài ra, Key Vault hỗ trợ rotation tự động qua các tính năng tích hợp. Đây là best practice theo tài liệu Azure mới nhất (cập nhật 2024-2026), nhấn mạnh zero-trust và least-privilege access.

📘 Tài liệu tham khảo:

✅ Đáp án đúng: Assign a managed identity to App1

Lý do chọn đáp án này:

  • Managed Identity (Danh tính được quản lý) là tính năng của Azure cho phép App Service có một identity (System-assigned hoặc User-assigned) mà không cần lưu credentials trong code.
  • App1 có thể sử dụng identity này để truy cập Key Vault qua RBAC (Role-Based Access Control) hoặc Access Policies.
  • Tự động rotate: Key Vault hỗ trợ rotation tự động cho secrets, và Managed Identity đảm bảo App1 luôn lấy phiên bản mới nhất mà không cần deploy lại code.
  • Đây là cách an toàn nhất, không lưu secrets, tuân thủ zero-secret-in-code. Phiên bản Azure 2026 tiếp tục ưu tiên Managed Identity với hỗ trợ Entra ID (trước là Azure AD) cho rotation seamless.

🛠️ Giải thích tất cả các phương án (đúng/sai)

  • ❌ Enable App Service authentication for App1. Assign a custom RBAC role to Vault1.
    Phương án này sai vì: App Service Authentication (Easy Auth) dùng để xác thực người dùng cuối (như OAuth/JWT), không dành cho truy cập dịch vụ-to-dịch vụ như Key Vault. Custom RBAC role là đúng hướng cho Vault1, nhưng thiếu identity để assign role (cần Managed Identity trước). Không hỗ trợ rotate tự động mà không lưu code, dẫn đến rủi ro bảo mật.

  • ❌ Add a TLS/SSL binding to App1.
    Phương án này sai vì: TLS/SSL binding chỉ dùng để mã hóa traffic HTTPS cho App Service (custom domain), không liên quan đến việc truy cập Key Vault hay quản lý secrets. Không giải quyết rotate credentials hay tránh lưu code, hoàn toàn không phù hợp.

  • ❌ Upload a self-signed client certificate to Vault1. Update App1 to use the client certificate.
    Phương án này sai vì: Self-signed certificate không an toàn (thiếu CA trust), và yêu cầu lưu cert trong App1 (có thể trong code/config), vi phạm "not stored in code". Vault1 không dùng client cert kiểu này cho access; thay vào đó dùng cert-based auth phức tạp hơn, không hỗ trợ rotate tự động dễ dàng. Không phải best practice so với Managed Identity.

  • ✅ Assign a managed identity to App1.
    Như đã giải thích ở trên: Đúng hoàn toàn, an toàn, tự động, và tuân thủ best practice Azure mới nhất. Sau khi assign, chỉ cần grant role như "Key Vault Secrets User" cho identity của App1 trên Vault1 qua portal/CLI.