- What is Azure Storage Account and what are its different storage types
Ans:- An Azure Storage Account is a Microsoft cloud service that provides a secure, scalable, and highly available space to store your data. It acts as a single container that groups together all of your data objects, giving them a unique namespace accessible from anywhere in the world via HTTP or HTTPS.
It is designed to handle massive volumes of data, automatically manage hardware failures, and scale up seamlessly as your application storage needs grow.
The Core Storage Types supported by Azure Storage- Azure Blobs (Object Storage): Optimized for storing massive amounts of unstructured data. This includes text or binary data like images, videos, audio, log files, backups, and documents. It is ideal for serving files directly to a browser or streaming media.
- Azure Files (Managed File Shares): Offers fully managed cloud file shares that you can access using standard network protocols like SMB (Server Message Block) or NFS. It allows you to lift-and-shift legacy on-premises file shares to the cloud without changing how your applications access data.
- Azure Queues (Messaging Storage): A messaging store used to send and process large volumes of messages asynchronously between different application components. It is commonly used to decouple components in microservices and serverless architectures (like Azure Functions).
- Azure Tables (NoSQL Storage): A key-attribute NoSQL datastore used for rapid development and fast access to massive quantities of structured, non-relational data. It is highly cost-effective for storing metadata, user logs, and web application state.
- How do you secure an Azure Storage Account from unauthorized access?
Ans:- I secure an Azure Storage Account using defense in depth. I prefer Microsoft Entra ID with RBAC and managed identities instead of account keys, apply least privilege, restrict network access using firewalls, VNets and private endpoints, disable public blob access, use short-lived SAS tokens when required, enable encryption and HTTPS, and monitor access through Azure Monitor and diagnostic logs. For data protection, I also enable blob soft delete, versioning, and immutability where appropriate.
- How do you store secrets without using appsettings.json?
Ans:- In .NET, I would avoid storing sensitive information like passwords, API keys, or connection strings directly in appsettings.json.
For local development, I would use .NET User Secrets, which keeps secrets outside the project and prevents them from being committed to source control.
For production, I would use a secret management service such as Azure Key Vault. Another option for containerized applications is environment variables, depending on the deployment environment.
The advantage is that the application can still access these values through IConfiguration, so the code doesn't need to know where the secret is actually stored.
- What is Azure Key Vault and why is it important?
Ans:- Azure Key Vault is a cloud-based service provided by Microsoft that securely stores, manages, and controls access to sensitive data such as cryptographic keys, application secrets, and digital certificates. It acts as a centralized digital safe, ensuring that developers do not have to hardcode sensitive information like passwords or database connection strings directly into their application source code.
- How do you connect an ASP.NET Core application to Azure Key Vault?
Ans:- To connect an ASP.NET Core application to Azure Key Vault, you should use the official Azure.Extensions.AspNetCore.Configuration.Secrets package. This approach automatically injects your Key Vault secrets directly into the standard IConfiguration system, allowing you to access them just like local appsettings.json variables.
- What is Managed Identity and how does it work with Azure Key Vault?
Ans:- Managed Identities for Azure Resources is a feature of Microsoft Entra ID (formerly Azure Active Directory) that solves a major security challenge by eliminating credentials, passwords, and API keys from your application source code.
Azure Key Vault is a secure cloud service used to encrypt and store sensitive items like connection strings, TLS certificates, and API tokens.
By combining Managed Identity with Azure Key Vault, you create a completely credential-free architecture. Your application can securely pull secrets out of Key Vault without needing a password to access Key Vault in the first place.
- What is Azure Service Bus?
Ans:- Azure Service Bus is a fully managed message broker from Microsoft Azure. It allows different applications or services to communicate asynchronously by sending messages through a queue or topic.
- What is the difference between Queue and Topic in Azure Service Bus?
Ans:- The core difference between a Queue and a Topic in Azure Service Bus is the number of consumers that receive and process each message.
- A Queue uses a one-to-one (point-to-point) delivery model. Each message sent to a queue is pulled and processed by exactly one consumer.
- A Topic uses a one-to-many (publish-subscribe) model. A single message published to a topic can be duplicated and received by multiple independent subscriptions.
- When would you choose Azure Service Bus over REST API communication?
Ans:- I would choose Azure Service Bus when I need asynchronous, reliable, and decoupled communication between services—for example, when the consumer might be temporarily unavailable, when I need buffering during traffic spikes, when processing is long-running, or when multiple services need to consume an event.
I would use REST when the caller needs a synchronous request-response interaction and an immediate result.
- What is Azure Event Grid?
Ans:-Azure Event Grid is a managed event-routing service used to build event-driven applications. It detects events from Azure services or custom applications and routes those events to subscribers such as Azure Functions, Logic Apps, or webhooks. It is best suited for reacting to events, whereas Azure Service Bus is better suited for reliable asynchronous message processing and business workflows.
- What is Azure Event Hub?
Ans:- Azure Event Hubs is a fully managed, highly scalable event ingestion service designed to collect and process huge volumes of real-time events and telemetry. It is commonly used for IoT data, application telemetry, logs, and streaming analytics. Unlike Event Grid, which is primarily for event notification and routing, and Service Bus, which is designed for reliable business messaging, Event Hubs is optimized for high-throughput event streaming.
- What is the difference between Azure Event Grid and Azure Event Hub?
Ans:- Azure Event Grid is primarily an event notification and routing service. It is used when something happens and you want to notify interested subscribers, such as when a blob is created. Azure Event Hubs is a high-throughput event ingestion and streaming service, designed for collecting and processing large volumes of telemetry, logs, IoT data, or clickstream events. Event Grid is about reacting to discrete events, while Event Hubs is about handling continuous, high-volume event streams.
- What is Azure API Management (APIM) and why is it used?
Ans:- Azure API Management is a managed API gateway and API management platform. It sits between API consumers and backend services and provides capabilities such as authentication, authorization, rate limiting, throttling, API versioning, transformation, monitoring, and developer documentation. We use APIM to securely expose and manage APIs while keeping common API-management concerns separate from backend business logic.
- How do you secure an ASP.NET Core Web API hosted in Azure?
Ans:- I would secure an ASP.NET Core Web API using defense in depth. First, enforce HTTPS. For authentication, I'd use Microsoft Entra ID and JWT bearer tokens, with authorization policies or roles for access control. I'd put Azure API Management in front of the API when appropriate for JWT validation, throttling, rate limiting, and API policies. Secrets would be stored in Azure Key Vault and accessed through Managed Identity rather than hard-coded credentials.
For sensitive workloads, I'd use VNet integration and Private Endpoints to restrict network access. At the application level, I'd validate input, use parameterized database access, apply least privilege, and avoid logging sensitive data. Finally, I'd use Azure Monitor/Application Insights and secure the CI/CD pipeline with appropriate permissions and secret management.
- How do you authenticate Azure APIs using Azure AD?
Ans:- I would register the ASP.NET Core Web API in Microsoft Entra ID and expose the required scopes or application permissions. The client authenticates with Entra ID and obtains an OAuth 2.0 access token.
It sends that token to the API using the Bearer authorization header. In ASP.NET Core, I use Microsoft.Identity.Web with JWT Bearer authentication to validate the token.
Then I use [Authorize], scopes, roles, or authorization policies to control access to individual endpoints. For service-to-service scenarios, I would typically use application permissions and client credentials, preferably with a secure credential such as a managed identity where applicable.
- What is Azure Monitor?
Ans:- Azure Monitor is Azure's monitoring and observability platform. It collects metrics, logs, and telemetry from Azure resources and applications and provides capabilities such as dashboards, log analysis, alerts, and troubleshooting. For application monitoring, Application Insights integrates with Azure Monitor to provide request tracking, exceptions, dependency monitoring, and distributed tracing.
- What is Application Insights?
Ans:- Application Insights is an Azure application performance monitoring and observability service. It collects telemetry such as HTTP requests, exceptions, dependencies, performance data, logs, and distributed traces from applications. For an ASP.NET Core API, it helps us monitor application health, troubleshoot failures, identify performance bottlenecks, and trace requests across distributed services. It is integrated with Azure Monitor.
- How do you configure centralized logging using Application Insights?
Ans:- I would configure Application Insights/Azure Monitor as the centralized telemetry destination for the ASP.NET Core APIs. The application would use the standard ILogger abstraction for structured application logging, with appropriate log-level filtering. For new applications, I would use the Azure Monitor OpenTelemetry integration for current instrumentation.
All API instances would send their telemetry to the same Application Insights resource, allowing us to centrally query traces, exceptions, requests, dependencies, and performance data using Azure Monitor and KQL. I would also configure alerts and dashboards for important errors and performance issues, while ensuring sensitive information isn't logged.
- How do you write KQL (Kusto Query Language) queries for troubleshooting
Ans:- I use KQL in Azure Monitor/Application Insights to troubleshoot application issues. I start by filtering telemetry by time using where and ago(), then identify failed requests and exceptions. I use summarize to find error trends and slow endpoints, and inspect dependencies to identify database or downstream-service problems. For individual failures, I use the operation or correlation ID to correlate requests, dependencies, traces, and exceptions. Finally, I use bin() to analyze trends over time and create alerts or dashboards for recurring problems.
- How do you troubleshoot performance issues in Azure App Service?
Ans:- So my approach is: first understand the symptoms, then check App Service metrics, use Application Insights to identify the slow component, investigate dependencies such as SQL or external APIs, check scaling and recent changes, apply the appropriate fix, and finally monitor the application to verify the improvement. I try to identify the actual bottleneck before scaling resources.
Thanks