Microsoft Azure Security Engineer Associate AZ-500 Practice Question
An Azure API Management (APIM) instance publishes several mission-critical APIs to external business partners. Security requirements are: callers must authenticate by presenting X.509 certificates issued by the company's internal CA, partners must not need to include subscription keys, and no changes can be made to the backend APIs. Which APIM configuration meets all the requirements?
Configure the API to require mutual TLS authentication and disable the subscription key requirement.
Apply a check-header inbound policy that verifies a shared-secret header provided to each partner.
Enable an Azure AD OAuth 2.0 authorization server and add a validate-jwt inbound policy.
Move the APIM instance to an internal virtual network and publish it through Azure Application Gateway with Web Application Firewall.
Requiring mutual TLS on an API forces clients to present a trusted X.509 certificate, satisfying the authentication requirement without modifying backend code. When the subscription key requirement is disabled for the API, callers no longer need to pass the key in a header or query string. Moving APIM behind a network appliance, validating JWTs, or checking a custom header do not meet the certificate-based authentication requirement, and they either still require subscription keys or introduce methods the scenario does not call for.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is mutual TLS authentication and how does it work in Azure API Management?
Open an interactive chat with Bash
How do X.509 certificates enable secure communication and authentication?
Open an interactive chat with Bash
Why is disabling the subscription key requirement in APIM important in this scenario?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .