Designing And Implementing Microsoft DevOps Solutions (AZ-400) Practice

Access More Questions
When creating a Key Vault access policy for an ASP.NET Core application, which secret permission should you assign to adhere to the principle of least privilege?
Correct Answer:
Get only
Explanation:
Assigning the "Get only" secret permission for a Key Vault access policy in an ASP.NET Core application aligns with the principle of least privilege by providing the application with just enough permissions to function effectively without exposing unnecessary access. When an application only needs to retrieve specific secrets (like connection strings or API keys), granting permission to "Get" those secrets prevents it from performing any other actions, such as listing all secrets, which could expose sensitive information. This approach minimizes the risk of unauthorized access or misuse of secrets while ensuring that the application can still perform its intended operations. Following this principle helps maintain a secure environment, especially in scenarios where secrets might be sensitive or critical to the application's functionality. In contrast, wider permissions such as "List" or "Get and List" could inadvertently expose all secrets within the Key Vault, potentially leading to security vulnerabilities. Therefore, opting for the least amount of privilege necessary is key to developing secure applications in a cloud environment.

Access more questions from this quiz

Continue to Designing and Implementing Microsoft DevOps Solutions (AZ-400) Practice for more practice questions and the full quiz experience.

Access More Questions