Microsoft Azure Developer Associate AZ-204 Practice Question

You manage an Azure API Management (APIM) instance that exposes several internal APIs to external partners. To reduce the risk of accidental exposure of subscription keys in browser history and logs, the security team requires that callers send the key only in the Ocp-Apim-Subscription-Key request header. Any request that includes the subscription-key query-string parameter must be rejected before it reaches the backend service. Which built-in APIM policy should you add to the inbound pipeline of the affected APIs to meet this requirement with the least custom code?

  • Add an inbound check-header policy that requires the key in Ocp-Apim-Subscription-Key.

  • Add an inbound validate-parameters policy that asserts the subscription-key query parameter does not exist.

  • Add an inbound rewrite-uri policy to remove the subscription-key parameter from the URL before forwarding.

  • Add an outbound rate-limit-by-key policy that throttles requests when the key appears in the query string.

Microsoft Azure Developer Associate AZ-204
Connect to and consume Azure services and third-party services
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot