Microsoft Azure Developer Associate AZ-204 Practice Question

You register a single-tenant web API named ContosoApi in Microsoft Entra ID. A separate daemon application will call the API by using the client-credentials grant. The API must authorize calls only when the incoming access token contains the role Orders.ReadWrite and there is no user context. Which configuration should you perform for ContosoApi in the Azure portal?

  • Create an application role named Orders.ReadWrite in ContosoApi and assign that role to the client application's service principal.

  • Define a delegated permission scope named Orders.ReadWrite in ContosoApi and require admin consent for the client application.

  • Create an Azure RBAC role assignment granting the client application Contributor access to the ContosoApi App Service.

  • Add optional JWT claims for roles in ContosoApi and mark the claim as essential.

Microsoft Azure Developer Associate AZ-204
Implement Azure security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot