An organization wants to share a large file from a cloud storage bucket with an external partner for a limited time. They need to ensure that the partner can only access the specific file and that the access expires automatically. Which method should they use?
A pre-signed URL embeds temporary credentials in the link itself, granting time-limited access to one specific object without exposing bucket permissions or requiring the partner to hold Microsoft Entra ID credentials. The expiry parameter satisfies the automatic revocation constraint, while scoping to a single object meets the least-privilege requirement for external sharing.
Why this answer
A pre-signed URL provides temporary access to a specific object in a cloud storage bucket, with an expiration time. It grants the external partner permission to download the file without needing a cloud account, and access automatically expires. This meets the requirements of limited-time, specific-file access.
Exam trap
The trap is overlooking the need for automatic expiration and specific file access. Candidates might choose making the bucket public for simplicity, but that fails security and expiration requirements.
How to eliminate wrong answers
Option A is wrong because making the bucket public grants access to all objects indefinitely, violating the requirement for limited time and specific file. Option B is wrong because creating a new user account is more complex, may not automatically expire, and grants broader access than needed. Option C is wrong because cross-region replication copies data to another region but does not provide temporary access to an external partner.