AZ-104 Implement and Manage Storage Practice Question
A team enabled Azure Files for a Windows-based application. The app can reach the storage account, but the mount fails because users cannot authenticate with the share. The team does not want to use the storage account key. What is the best next step?
⚠ Common exam trap
Many exam-takers confuse network-level connectivity (TCP 445) with authentication requirements, assuming that opening the port alone will fix the mount failure, when in fact the issue is the lack of a valid identity-based authentication mechanism.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant the VM or user an Azure Files data-plane role, such as Storage File Data SMB Share Contributor, and use identity-based authentication.
Azure Files supports identity-based authentication over SMB using either on-premises Active Directory Domain Services (AD DS) or Azure Active Directory Domain Services (Azure AD DS). By granting the VM or user the Storage File Data SMB Share Contributor role, the team enables Kerberos-based authentication, eliminating the need for the storage account key. This approach allows the mount to succeed while meeting the requirement to avoid using the shared key.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Turn off the storage account firewall and retry the mount anonymously.
Why it's wrong here
Disabling the storage account firewall only removes network-level filtering; it does not bypass the share's authentication requirements. Azure Files never allows anonymous SMB access — a valid storage account key or identity-based credential is always required. Turning off the firewall also exposes the account to broader network traffic and still leaves the VM without permission, so the mount remains unauthorized.
When this WOULD be correct
If the question stated that the storage account firewall is blocking access and the goal is to allow access from a specific trusted network or IP range, then adjusting the firewall rules (not turning it off completely) would be appropriate. However, the question's issue is authentication, not network connectivity.
- ✓
Grant the VM or user an Azure Files data-plane role, such as Storage File Data SMB Share Contributor, and use identity-based authentication.
Why this is correct
When Azure Files is accessed over SMB without storage keys, the administrator should use identity-based authentication and assign the appropriate Azure Files data-plane role. This provides the permissions needed to mount and use the share while avoiding storage account keys. It is the correct fix when network access works but authorization fails.
- ✗
Create a network security group rule that allows TCP 445 to the share.
Why it's wrong here
Creating an NSG rule for TCP 445 only opens the SMB network path; the error here is an authorization failure, not a connectivity timeout. Since the VM can already reach the share but is denied access, the port is already open. Even with the rule, the VM still lacks the required RBAC role or credentials to authenticate, so the mount would still fail.
When this WOULD be correct
This option would be correct if the question described a scenario where the VM cannot reach the storage account due to a network restriction, such as a blocked port 445, and the goal is to enable SMB connectivity for Azure Files.
- ✗
Convert the storage account to a premium block blob account.
Why it's wrong here
A premium block blob account is designed solely for blob storage and does not support Azure Files SMB shares at all. Converting the account would delete the file share or make it inaccessible, breaking the Windows application instead of fixing it. The underlying problem is that permissions are not assigned to the VM/user, which is independent of the storage account tier or kind.
When this WOULD be correct
This option would be correct if the question asked how to improve performance for a blob storage workload requiring low latency and high IOPS, such as a media streaming application, where upgrading to premium block blob storage is appropriate.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓Grant the VM or user an Azure Files data-plane role, such as Storage File Data SMB Share Contributor, and use identity-based authentication.Correct answer▾
Why this is correct
When Azure Files is accessed over SMB without storage keys, the administrator should use identity-based authentication and assign the appropriate Azure Files data-plane role. This provides the permissions needed to mount and use the share while avoiding storage account keys. It is the correct fix when network access works but authorization fails.
✗Turn off the storage account firewall and retry the mount anonymously.Wrong answer — click to see why▾
Why this is wrong here
Turning off the storage account firewall and mounting anonymously would bypass authentication entirely, which is insecure and not a supported method for Azure Files SMB access. Azure Files requires proper authentication, and anonymous access is not available for SMB shares.
★ When this WOULD be the correct answer
If the question stated that the storage account firewall is blocking access and the goal is to allow access from a specific trusted network or IP range, then adjusting the firewall rules (not turning it off completely) would be appropriate. However, the question's issue is authentication, not network connectivity.
Why candidates choose this
Candidates may think that disabling the firewall simplifies connectivity, assuming the mount failure is due to network restrictions rather than authentication. They might overlook that Azure Files SMB requires identity-based authentication or a storage account key.
✗Create a network security group rule that allows TCP 445 to the share.Wrong answer — click to see why▾
Why this is wrong here
The mount failure is due to authentication, not network connectivity. NSG rules control network traffic but do not address identity-based authentication required for accessing Azure Files without the storage account key.
★ When this WOULD be the correct answer
This option would be correct if the question described a scenario where the VM cannot reach the storage account due to a network restriction, such as a blocked port 445, and the goal is to enable SMB connectivity for Azure Files.
Why candidates choose this
Candidates may confuse network connectivity issues with authentication issues, assuming that allowing port 445 will resolve all Azure Files mount problems, especially since SMB requires this port.
✗Convert the storage account to a premium block blob account.Wrong answer — click to see why▾
Why this is wrong here
Converting to a premium block blob account does not address authentication for Azure Files; block blobs are for object storage, not SMB file shares, and the issue is identity-based access, not performance.
★ When this WOULD be the correct answer
This option would be correct if the question asked how to improve performance for a blob storage workload requiring low latency and high IOPS, such as a media streaming application, where upgrading to premium block blob storage is appropriate.
Why candidates choose this
Candidates may think 'premium' solves all problems or confuse Azure Files with blob storage, assuming a premium tier would fix access issues without understanding the fundamental difference between file and blob services.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Privileged Identity Management (PIM)
Key term
Azure Active Directory
Azure Active Directory is Microsoft's cloud-based identity and access management service that lets employees sign in and access resources both in the cloud and on-premises.
Key term
Contributor role
The Contributor role is a built-in Azure role that grants full access to manage resources within a scope but does not allow granting access to other users.
About these practice questions
Courseiva writes every AZ-104 question from scratch — 1,049 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.