To meet these secure development requirements, you should use client certificates. Verifies Identity Individually: Mutual TLS (mTLS) allows the Azure API Management (APIM) gateway to uniquely map and verify the explicit identity of individual external callers. Minimizes Backend Changes: APIM can be configured to natively handle the TLS handshake and validation policy (validate-client-certificate) at the gateway layer. The backend APIs do not need code updates to handle cryptographic verification. Prevents Anonymous Access: Setting up a mandatory client certificate validation policy at the gateway ensures any requests without a valid certificate are rejected immediately. Easy to Block If Compromised: If a specific user's credential or private key is compromised, you can instantly block their access by removing their thumbprint from your gateway's validation list or checking against a Certificate Revocation List (CRL). Incorrect: [Not A, not C] API Keys & Query String Authentication: These methods transfer secrets in plain text or headers/URLs, which violates modern secure coding practices. They are easily intercepted, cached in logs, or forwarded inadvertently. [Not D] Shared Access Signatures (SAS): SAS is a mechanism designed primarily for delegating fine- grained access to Azure storage resources or specific service buses, rather than serving as a standard standard authentication framework for external consumer APIs. Reference: https://www.azadvertizer.net/azpolicyadvertizer/8ac833bd-f505-48d5-887e-c993a1d3eea0.html