A fern-gully CORS header is required on one APIM operation, not the whole instance. At which policy scope should the developer apply it?
Select an answer to reveal the explanation.
Short Explanation
Don’t paint the whole house for one door. Apply the CORS policy at operation scope—APIM scopes (global, product, API, operation) let the more specific setting win.
Full Explanation
APIM policies can be attached at global, product, API, or operation scope (workspace scopes may also apply). A header needed on a single operation should be set at operation scope; more specific scopes override broader ones as documentation describes. AKS Ingress and Key Vault secrets are not APIM policy scopes.