Microsoft AI-200 Question Answer
You are developing an AI-powered API that retrieves connection strings and API keys from Azure Key Vault.
You must configure a solution that provides the following security functionality:
• The API must authenticate to Key Vault without storing credentials in any application configuration files
• The identity used by the API must have only the minimum permissions necessary to read secrets.
• The configuration must minimize the blast radius if an identity or credential is compromised.
You need to implement a secure access strategy for the API.
Which two actions should you perform? Each correct answer presents part of the solution. Choose two.
NOTE: Each correct selection is worth one point.
Microsoft AI-200 Summary
- Vendor: Microsoft
- Product: AI-200
- Update on: Sep 20, 2026
- Questions: 142

