Courseiva

AZ-104 Implement and Manage Storage Practice Question

A contractor needs to upload files into one blob container for six hours. The administrator must avoid sharing the storage account key and wants the access to expire automatically. Which two actions should the administrator take? Select two.

⚠ Common exam trap

Watch out — candidates often confuse a service SAS (which requires the account key) with a user delegation SAS (which uses Microsoft Entra ID), leading them to select Option B instead of A, missing the key requirement to avoid sharing the storage account key.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Generate a user delegation SAS for the contractor.

Option A is correct because a user delegation SAS is signed with Microsoft Entra ID credentials (a user delegation key obtained via the Blob service) rather than the storage account key, so the contractor never receives the account key. Option C is correct because the SAS token includes a signed expiry field (se=), and setting it to six hours ensures the access automatically expires after the required upload window. Option B is wrong because a service SAS signed with the account key requires exposing the storage account key, which the administrator explicitly wants to avoid. Option D is wrong because anonymous blob access grants unauthenticated, non-expiring public access and does not provide time-limited write permissions. Option E is wrong because creating a separate storage account access key still shares a long-lived account-level credential that does not expire automatically.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Generate a user delegation SAS for the contractor.

    Why this is correct

    A user delegation SAS is signed with Microsoft Entra ID credentials rather than the storage account key, so the contractor never receives that key. This satisfies the stem's constraint while still granting scoped upload permission to the blob container.

  • ✗

    Generate a service SAS by using the account key.

    Why it's wrong here

    A service SAS signed with the account key still requires the key to sign it, so the administrator would handle the key and the contractor could not self-generate it. Service SAS is correct when the administrator controls signing and delegates access to a single service.

    When this WOULD be correct

    If the question stated that the administrator is allowed to use the storage account key and needs to grant temporary access to a specific container or blob, a service SAS with a short expiry would be correct.

  • ✓

    Set the SAS expiry to six hours.

    Why this is correct

    Setting the SAS expiry to six hours makes the delegated token lapse automatically, matching the contractor's upload window. This satisfies the stem's requirement that access expire without manual revocation, working alongside the user delegation SAS.

  • ✗

    Enable anonymous blob access on the container.

    Why it's wrong here

    Anonymous access grants read or write to anyone with the URL and never expires, so the six-hour automatic expiry requirement is unmet. It is tempting because it removes key sharing entirely, and it would suit deliberately public, non-sensitive content such as an open marketing asset.

    When this WOULD be correct

    When the requirement is to allow public read access to blobs in a container for a specific period (e.g., for hosting static website content) and there is no need for write access or expiration control.

  • ✗

    Create a storage account access key specifically for the contractor.

    Why it's wrong here

    A storage account access key grants full account-level privileges and carries no expiry, so it neither limits the contractor to one container nor expires after six hours. It is tempting as the quickest credential to issue, and would fit a trusted internal application needing persistent account-wide access.

    When this WOULD be correct

    If the question required granting permanent access to a contractor without time constraints and the administrator was allowed to share keys, creating a dedicated key would isolate access for auditing.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

✓Generate a user delegation SAS for the contractor.Correct answer▾

Why this is correct

A user delegation SAS is signed with Microsoft Entra ID credentials rather than the storage account key, so the contractor never receives that key. This satisfies the stem's constraint while still granting scoped upload permission to the blob container.

✗Generate a service SAS by using the account key.Wrong answer — click to see why▾

Why this is wrong here

A service SAS generated with the account key exposes the account key indirectly and does not meet the requirement to avoid sharing the storage account key. The question explicitly requires not sharing the account key.

★ When this WOULD be the correct answer

If the question stated that the administrator is allowed to use the storage account key and needs to grant temporary access to a specific container or blob, a service SAS with a short expiry would be correct.

Why candidates choose this

Candidates may think a service SAS is sufficient for temporary access and overlook the requirement to avoid using the account key, or they may confuse service SAS with user delegation SAS.

✗Enable anonymous blob access on the container.Wrong answer — click to see why▾

Why this is wrong here

Enabling anonymous blob access would allow anyone to read blobs without authentication, which violates the requirement to avoid sharing the storage account key and does not provide automatic expiration of access.

★ When this WOULD be the correct answer

When the requirement is to allow public read access to blobs in a container for a specific period (e.g., for hosting static website content) and there is no need for write access or expiration control.

Why candidates choose this

Candidates may think anonymous access is a simple way to grant access without keys, but they overlook the lack of expiration and the security risk of public access.

✗Create a storage account access key specifically for the contractor.Wrong answer — click to see why▾

Why this is wrong here

Creating a storage account access key specifically for the contractor still exposes a long-lived key that does not automatically expire, violating the requirement for automatic expiration and avoiding key sharing.

★ When this WOULD be the correct answer

If the question required granting permanent access to a contractor without time constraints and the administrator was allowed to share keys, creating a dedicated key would isolate access for auditing.

Why candidates choose this

Candidates may think a dedicated key provides controlled access without sharing the primary key, but it still fails to meet the automatic expiration requirement.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This AZ-104 question is part of Courseiva's 1,053-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.