AZ-104 Implement and Manage Storage Practice Question
A team needs one Azure Files share that can be mounted by both Windows and Linux VMs. The VMs are joined to the same on-premises Active Directory Domain Services domain, and the security team forbids storage account keys. The team also wants to manage access with existing AD group memberships. What should the administrator configure?
⚠ Common exam trap
Watch out — candidates often confuse NFS with SMB, assuming NFS is the only option for Linux, but Azure Files supports SMB for both Windows and Linux, and AD DS authentication is only available for SMB shares, not NFS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Azure Files over SMB and enable AD DS authentication
Azure Files supports SMB protocol, which can be mounted by both Windows and Linux VMs. By enabling AD DS authentication, the administrator can use existing on-premises Active Directory group memberships to control access to the file share without requiring storage account keys, satisfying the security team's requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use Azure Files over SMB and enable AD DS authentication
Why this is correct
Azure Files over SMB supports both Windows and Linux clients, and AD DS authentication lets the team use existing domain identities and groups instead of storage keys. This keeps permissions centralized and avoids embedding secrets in scripts or mount commands. It is the most appropriate choice when both operating systems must share the same file data and access control should come from the established directory service.
- ✗
Use a blob container and mount it through the Blob API
Why it's wrong here
An Azure blob container is object storage, not a distributed file system, and it is exposed via the Blob REST API or SDKs rather than an SMB mount point. While tools like BlobFuse or third-party drivers can expose it as a pseudo-filesystem, these are not native Windows-AD-integrated file share mechanisms and do not deliver the same SMB protocol-level semantics such as byte-range locks, file attributes, or domain-based access control. As a result, it would not satisfy the need for a shared file system mountable by both Windows and Linux with centralized AD DS authentication.
When this WOULD be correct
An administrator needs to store and access unstructured data (e.g., images, logs) from applications using REST APIs, and requires AD DS authentication for access control without using storage account keys.
- ✗
Use anonymous access on an Azure File share
Why it's wrong here
Anonymous access on an Azure File share means the SMB client connects without any authentication, so the share is effectively open to anyone who can reach the endpoint. Azure Files does not support anonymous SMB access in modern service versions, and even if configured, it provides no per-user or per-group identity enforcement. This completely fails the access control requirement because it cannot use AD DS identities or enforce security principals, making it an insecure choice for enterprise file sharing.
When this WOULD be correct
An administrator needs to provide read-only access to a publicly shared file share for anonymous users without requiring authentication, such as for distributing public documents or software installers.
- ✗
Use a premium NFS file share with a shared access signature
Why it's wrong here
Azure Files premium NFS shares use the NFS 4.1 protocol, which is primarily designed for Linux clients and does not natively integrate with Active Directory Domain Services for SMB-style identity-based permissions. Windows can mount NFS shares only with the somewhat limited Client for NFS feature, and it does not map AD DS users to NFS permissions in the same way SMB does. Furthermore, a shared access signature (SAS) is a query-string secret that grants access at the share or file level, not an identity-based credential, so it violates the requirement to avoid embedding secrets and does not provide per-user authorization through the domain directory.
When this WOULD be correct
An administrator needs to provide high-performance, low-latency file storage for Linux VMs only, and the security team allows SAS tokens for temporary access. In that case, a premium NFS file share with SAS would be correct.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓Use Azure Files over SMB and enable AD DS authenticationCorrect answer▾
Why this is correct
Azure Files over SMB supports both Windows and Linux clients, and AD DS authentication lets the team use existing domain identities and groups instead of storage keys. This keeps permissions centralized and avoids embedding secrets in scripts or mount commands. It is the most appropriate choice when both operating systems must share the same file data and access control should come from the established directory service.
✗Use a blob container and mount it through the Blob APIWrong answer — click to see why▾
Why this is wrong here
Blob containers cannot be mounted as file shares; they require Blob API access, not SMB or NFS, and do not support AD DS authentication for mounting by VMs.
★ When this WOULD be the correct answer
An administrator needs to store and access unstructured data (e.g., images, logs) from applications using REST APIs, and requires AD DS authentication for access control without using storage account keys.
Why candidates choose this
Candidates may confuse blob storage with file shares, thinking both can be mounted as drives, or assume the Blob API can be used for file-level access with AD authentication.
✗Use anonymous access on an Azure File shareWrong answer — click to see why▾
Why this is wrong here
Anonymous access on an Azure File share does not allow authentication via AD group memberships, and the security team forbids storage account keys, making it unsuitable for managing access with existing AD groups.
★ When this WOULD be the correct answer
An administrator needs to provide read-only access to a publicly shared file share for anonymous users without requiring authentication, such as for distributing public documents or software installers.
Why candidates choose this
Candidates may think anonymous access simplifies setup by avoiding authentication, but they overlook the requirement to manage access via AD group memberships and the security policy against storage account keys.
✗Use a premium NFS file share with a shared access signatureWrong answer — click to see why▾
Why this is wrong here
A premium NFS file share cannot be mounted by Windows VMs, and using a shared access signature (SAS) violates the security team's forbiddance of storage account keys, as SAS tokens are derived from keys.
★ When this WOULD be the correct answer
An administrator needs to provide high-performance, low-latency file storage for Linux VMs only, and the security team allows SAS tokens for temporary access. In that case, a premium NFS file share with SAS would be correct.
Why candidates choose this
Candidates may think NFS is universally mountable by both Windows and Linux, and SAS seems like a secure alternative to storage account keys, overlooking the OS compatibility and key derivation issue.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Managed Identities for Azure Resources
Key term
File share
A file share is a centralized storage location on a network where multiple users can access, read, write, and manage files simultaneously.
Key term
Azure Files
Azure Files is a cloud-based file sharing service that lets you create and access file shares using the Server Message Block (SMB) protocol or Network File System (NFS) protocol, just like you would access files on a local network drive.
About these practice questions
Courseiva writes every AZ-104 question from scratch — 1,049 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.