Microsoft Azure Security Engineer Associate AZ-500 Practice Question
Your organization exposes internal REST APIs through an Azure API Management instance named contoso-apim. Security policy states that only Azure AD-issued OAuth 2.0 access tokens are accepted and that callers must never be allowed to authenticate by using subscription keys. Which Azure API Management configuration meets both requirements?
Enable OAuth 2.0 implicit grant on the Developer portal and require an API subscription for each caller.
Create an authorization server that integrates with Azure AD, add a validate-jwt policy to the APIs, and disable the Require subscription setting on the product.
Add a quota-by-key policy to the product, rotate the primary key, and delete the secondary key.
Enable mutual TLS authentication on the API gateway and upload the root CA certificate that chains to Azure AD.
Creating an authorization server entry that trusts Azure AD allows API Management to obtain and validate OAuth 2.0 access tokens. Applying the validate-jwt policy to each API ensures that only tokens issued by Azure AD are accepted at the gateway. Setting the product's Require subscription property to Off removes the need for, and effectively blocks the use of, primary or secondary subscription keys. Mutual TLS, quota-by-key, or requiring a subscription while enabling the Developer portal do not satisfy the requirement to eliminate subscription key usage.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the validate-jwt policy in Azure API Management?
Open an interactive chat with Bash
How does Azure AD integrate with authorization servers in Azure API Management?
Open an interactive chat with Bash
Why disable the 'Require subscription' setting in Azure API Management?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .