Courseiva
Implement and Manage StoragehardMultiple ChoiceObjective-mapped

AZ-104 Implement and Manage Storage Practice Question

A team needs one Azure Files share that can be mounted by both Windows and Linux VMs. The VMs are joined to the same on-premises Active Directory Domain Services domain, and the security team forbids storage account keys. The team also wants to manage access with existing AD group memberships. What should the administrator configure?

⚠ Common exam trap

Watch out — candidates often confuse NFS with SMB, assuming NFS is the only option for Linux, but Azure Files supports SMB for both Windows and Linux, and AD DS authentication is only available for SMB shares, not NFS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use Azure Files over SMB and enable AD DS authentication

Azure Files supports SMB protocol, which can be mounted by both Windows and Linux VMs. By enabling AD DS authentication, the administrator can use existing on-premises Active Directory group memberships to control access to the file share without requiring storage account keys, satisfying the security team's requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use Azure Files over SMB and enable AD DS authentication

    Why this is correct

    Azure Files over SMB supports both Windows and Linux clients, and AD DS authentication lets the team use existing domain identities and groups instead of storage keys. This keeps permissions centralized and avoids embedding secrets in scripts or mount commands. It is the most appropriate choice when both operating systems must share the same file data and access control should come from the established directory service.

  • Use a blob container and mount it through the Blob API

    Why it's wrong here

    An Azure blob container is object storage, not a distributed file system, and it is exposed via the Blob REST API or SDKs rather than an SMB mount point. While tools like BlobFuse or third-party drivers can expose it as a pseudo-filesystem, these are not native Windows-AD-integrated file share mechanisms and do not deliver the same SMB protocol-level semantics such as byte-range locks, file attributes, or domain-based access control. As a result, it would not satisfy the need for a shared file system mountable by both Windows and Linux with centralized AD DS authentication.

    When this WOULD be correct

    An administrator needs to store and access unstructured data (e.g., images, logs) from applications using REST APIs, and requires AD DS authentication for access control without using storage account keys.

  • Use anonymous access on an Azure File share

    Why it's wrong here

    Anonymous access on an Azure File share means the SMB client connects without any authentication, so the share is effectively open to anyone who can reach the endpoint. Azure Files does not support anonymous SMB access in modern service versions, and even if configured, it provides no per-user or per-group identity enforcement. This completely fails the access control requirement because it cannot use AD DS identities or enforce security principals, making it an insecure choice for enterprise file sharing.

    When this WOULD be correct

    An administrator needs to provide read-only access to a publicly shared file share for anonymous users without requiring authentication, such as for distributing public documents or software installers.

  • Use a premium NFS file share with a shared access signature

    Why it's wrong here

    Azure Files premium NFS shares use the NFS 4.1 protocol, which is primarily designed for Linux clients and does not natively integrate with Active Directory Domain Services for SMB-style identity-based permissions. Windows can mount NFS shares only with the somewhat limited Client for NFS feature, and it does not map AD DS users to NFS permissions in the same way SMB does. Furthermore, a shared access signature (SAS) is a query-string secret that grants access at the share or file level, not an identity-based credential, so it violates the requirement to avoid embedding secrets and does not provide per-user authorization through the domain directory.

    When this WOULD be correct

    An administrator needs to provide high-performance, low-latency file storage for Linux VMs only, and the security team allows SAS tokens for temporary access. In that case, a premium NFS file share with SAS would be correct.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

Use Azure Files over SMB and enable AD DS authenticationCorrect answer

Why this is correct

Azure Files over SMB supports both Windows and Linux clients, and AD DS authentication lets the team use existing domain identities and groups instead of storage keys. This keeps permissions centralized and avoids embedding secrets in scripts or mount commands. It is the most appropriate choice when both operating systems must share the same file data and access control should come from the established directory service.

Use a blob container and mount it through the Blob APIWrong answer — click to see why

Why this is wrong here

Blob containers cannot be mounted as file shares; they require Blob API access, not SMB or NFS, and do not support AD DS authentication for mounting by VMs.

★ When this WOULD be the correct answer

An administrator needs to store and access unstructured data (e.g., images, logs) from applications using REST APIs, and requires AD DS authentication for access control without using storage account keys.

Why candidates choose this

Candidates may confuse blob storage with file shares, thinking both can be mounted as drives, or assume the Blob API can be used for file-level access with AD authentication.

Use anonymous access on an Azure File shareWrong answer — click to see why

Why this is wrong here

Anonymous access on an Azure File share does not allow authentication via AD group memberships, and the security team forbids storage account keys, making it unsuitable for managing access with existing AD groups.

★ When this WOULD be the correct answer

An administrator needs to provide read-only access to a publicly shared file share for anonymous users without requiring authentication, such as for distributing public documents or software installers.

Why candidates choose this

Candidates may think anonymous access simplifies setup by avoiding authentication, but they overlook the requirement to manage access via AD group memberships and the security policy against storage account keys.

Use a premium NFS file share with a shared access signatureWrong answer — click to see why

Why this is wrong here

A premium NFS file share cannot be mounted by Windows VMs, and using a shared access signature (SAS) violates the security team's forbiddance of storage account keys, as SAS tokens are derived from keys.

★ When this WOULD be the correct answer

An administrator needs to provide high-performance, low-latency file storage for Linux VMs only, and the security team allows SAS tokens for temporary access. In that case, a premium NFS file share with SAS would be correct.

Why candidates choose this

Candidates may think NFS is universally mountable by both Windows and Linux, and SAS seems like a secure alternative to storage account keys, overlooking the OS compatibility and key derivation issue.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every AZ-104 question from scratch — 1,049 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.