A reviewer answers “secure Azure Container Apps” with a Dapr secret-store tutorial for the canal API. Which security-engineer controls should be emphasized instead?
Select an answer to reveal the explanation.
Short Explanation
Skip the Dapr secret-store cookbook. Give the Container App a system-assigned managed identity, watch ingress/system logs, and let Domain 2 own the public TLS/WAF edge.
Full Explanation
For Azure Container Apps, AZ-500-aligned security-engineer levers include using a system-assigned managed identity for the app and reviewing ingress/system logs for monitoring, while public TLS and WAF remain edge/networking concerns. Dapr secret-store tutorials and microservice binding recipes are AZ-204-style answers and are not the primary controls for this monitoring and identity bullet.