問題文
A company wants to eliminate long-lived secrets across its estate. Which order of work is most effective?
選択肢
- Find where credentials exist today, replace them with managed identities or federated credentials where possible, move the remainder into a key vault with rotation, and then disallow the credential paths that are no longer needed
- Disallow the credential paths with a deny policy first so that nothing new can be created, then work through the resources that break one by one and move each one to a managed identity only after the resulting outage has been reported by its owners
- Move every secret into a key vault, enable soft delete and purge protection, and treat the work as complete because the secrets are now stored and audited centrally
- Rotate every secret on a weekly schedule with automation so that a leaked credential is only valid for a short window, and keep the credentials in place