Microsoft Azure Developer Associate AZ-204 Practice Question
You manage an Azure API Management instance that exposes several internal REST APIs. A new security requirement states that only requests carrying an Azure AD-issued access token that contains the audience api://orders and the scope Orders.Read may invoke the Orders API. All other requests must be rejected automatically. What is the most appropriate way to enforce this requirement in Azure API Management?
Apply a rate-limit-by-key policy that uses the Authorization header as the key to block unauthenticated requests.
Add a validate-jwt policy in the API's inbound section and specify the issuer, audience api://orders, and required scope Orders.Read.
Enable Require client certificate on the API and upload the certificate chain that Azure AD uses for signing tokens.
Disable the Subscription required setting for the API and assign the API to a product that is visible only to authenticated users.
Azure AD tokens are not validated automatically by API Management. To reject requests that do not carry a valid token with the required audience and scope, you add a validate-jwt policy to the API's inbound processing section. The policy specifies the trusted issuer, audience (api://orders) and the required scope (Orders.Read). If the token is missing, invalid, or lacks the required claims, the request is blocked. Changing the Subscription required setting, configuring client certificates, or applying a rate-limit policy do not evaluate JWT claims and therefore cannot enforce the audience and scope requirements.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a validate-jwt policy in Azure API Management?
Open an interactive chat with Bash
What is the role of the audience and scope in a JWT token?
Open an interactive chat with Bash
Why can’t the Subscription required setting enforce audience and scope requirements?
Open an interactive chat with Bash
Microsoft Azure Developer Associate AZ-204
Connect to and consume Azure services and third-party services
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .