Courseiva
Implement and Manage StoragemediumMultiple ChoiceObjective-mapped

AZ-104 Implement and Manage Storage Practice Question

A contractor needs temporary access to upload and download files in only one blob container for 8 hours. You do not want to share the storage account key, and you want to revoke access later without affecting other containers. What should you create?

⚠ Common exam trap

Many candidates confuse a container-level SAS with a stored access policy, thinking a SAS alone provides revocability, but without a stored access policy, a SAS token cannot be revoked before its expiry time.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A container-level SAS token backed by a stored access policy, so you can limit and revoke access.

A container-level SAS token backed by a stored access policy is the correct solution because it allows you to grant temporary, scoped access to a single blob container without exposing the storage account key. The stored access policy enables you to revoke the SAS token at any time by modifying or deleting the policy, which immediately invalidates all tokens associated with it, without affecting other containers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A storage account access key, because it can be limited to one container by policy.

    Why it's wrong here

    A storage account access key grants full administrative access to the entire storage account, including all containers, blobs, tables, queues, and the ability to regenerate keys or change firewall settings. You cannot scope an account key to a single container via policy; any key-based connection string or signed request built from the key bypasses fine-grained permissions. Rotating the key to revoke the contractor would also break access for any other applications using that key, and the key itself does not have a native expiration, making it a poor fit for temporary access.

    When this WOULD be correct

    If the requirement were to grant full administrative access to the entire storage account (e.g., for a storage administrator) and you need to rotate keys periodically, creating a storage account access key would be appropriate.

  • A container-level SAS token backed by a stored access policy, so you can limit and revoke access.

    Why this is correct

    A container-level SAS with a stored access policy is ideal for temporary access to one container. It avoids sharing the account key, limits permissions and lifetime to exactly what is needed, and gives you a revocation point through the stored access policy. That combination is safer than broad key-based access and more operationally flexible than changing account-wide settings.

  • Anonymous public access on the container, because it is the easiest way to time-limit access.

    Why it's wrong here

    Anonymous public access on a container does not support time-limited access at all; the container remains publicly readable (or writable, if configured) until you manually remove the anonymous permission, and you cannot set an expiration date. Even if you changed the access level temporarily, the ACL applies to everyone on the internet, so it is not a scoped credential for a specific contractor. Unlike a SAS token, anonymous access also cannot be revoked mid-session without re-configuring the container's public access setting, and it offers no audit trail of who used it.

    When this WOULD be correct

    If the requirement is to allow public read access to a container for hosting static website content without authentication, and no time limit or revocation is needed, anonymous public access would be correct.

  • Azure RBAC on the storage account only, because RBAC automatically expires after a few hours.

    Why it's wrong here

    Azure RBAC assignments on the storage account do not automatically expire after a few hours; expiration requires an external governance mechanism like Azure PIM (Privileged Identity Management) with a time-bound activation, which is not inherent to RBAC itself. Even with PIM, RBAC grants access by Azure AD identity, so the contractor would need to authenticate as a user or service principal, not just present a token. Scoping RBAC to the storage account level would also grant broad control over all containers and settings—far more than the contractor's upload/download needs—whereas a SAS with a stored access policy can be confined to a single container with precise actions.

    When this WOULD be correct

    A question where a user needs long-term, role-based access to manage multiple storage resources (e.g., blobs, queues, tables) across the entire storage account, and the organization uses Azure AD for identity management. For example: 'A team needs read/write access to all blob containers and queues in a storage account for ongoing operations. What should you assign?'

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

A container-level SAS token backed by a stored access policy, so you can limit and revoke access.Correct answer

Why this is correct

A container-level SAS with a stored access policy is ideal for temporary access to one container. It avoids sharing the account key, limits permissions and lifetime to exactly what is needed, and gives you a revocation point through the stored access policy. That combination is safer than broad key-based access and more operationally flexible than changing account-wide settings.

A storage account access key, because it can be limited to one container by policy.Wrong answer — click to see why

Why this is wrong here

A storage account access key grants full access to all containers in the storage account, not just one container. It cannot be scoped to a single container, and revoking it would affect all containers.

★ When this WOULD be the correct answer

If the requirement were to grant full administrative access to the entire storage account (e.g., for a storage administrator) and you need to rotate keys periodically, creating a storage account access key would be appropriate.

Why candidates choose this

Candidates may think that access keys can be restricted via policies or that they are the only way to provide temporary access, overlooking the container-level SAS with stored access policy.

Anonymous public access on the container, because it is the easiest way to time-limit access.Wrong answer — click to see why

Why this is wrong here

Anonymous public access cannot be time-limited and would allow anyone to access the container without authentication, violating the requirement to revoke access after 8 hours.

★ When this WOULD be the correct answer

If the requirement is to allow public read access to a container for hosting static website content without authentication, and no time limit or revocation is needed, anonymous public access would be correct.

Why candidates choose this

Candidates may think anonymous access can be easily enabled and disabled, but they overlook that it cannot be scoped to a specific time period and exposes the container to the public.

Azure RBAC on the storage account only, because RBAC automatically expires after a few hours.Wrong answer — click to see why

Why this is wrong here

Azure RBAC on the storage account does not automatically expire after a few hours; it requires manual removal. It also cannot be scoped to a single container without additional configuration, and it does not provide the temporary, revocable access needed for this scenario.

★ When this WOULD be the correct answer

A question where a user needs long-term, role-based access to manage multiple storage resources (e.g., blobs, queues, tables) across the entire storage account, and the organization uses Azure AD for identity management. For example: 'A team needs read/write access to all blob containers and queues in a storage account for ongoing operations. What should you assign?'

Why candidates choose this

Candidates may think RBAC is a modern, secure alternative to keys and assume it can be time-limited, or they may confuse RBAC with temporary access mechanisms like just-in-time access.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This AZ-104 question is part of Courseiva's 1,049-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.