Courseiva
Implement and Manage StoragemediumMultiple ChoiceObjective-mapped

AZ-104 Implement and Manage Storage Practice Question

A VM-based app must upload invoices to a blob container every hour. Security prohibits storing account keys or SAS tokens on the VM. The app should authenticate with Microsoft Entra ID and be allowed only to write blobs in one container. What should you configure?

⚠ Common exam trap

It's easy for candidates to confuse the Reader role (which only allows read access to the storage account's control plane) with the ability to write data, or they incorrectly assume that a broad role like Storage Account Contributor is acceptable because it 'covers' the storage account, ignoring the security constraint and the need for data-plane permissions at the container scope.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable a managed identity on the VM and assign Storage Blob Data Contributor at the container scope.

Enabling a managed identity on the VM allows the app to authenticate with Microsoft Entra ID without storing any secrets. Assigning the Storage Blob Data Contributor role at the container scope grants the VM’s managed identity the minimum required permission to write blobs only to that specific container, adhering to the principle of least privilege.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create an account SAS token and store it in the VM's application settings.

    Why it's wrong here

    An account SAS is a shared-signature URL that grants delegated access to storage services, but generating it requires the storage account key, which is a shared secret. Storing that SAS token in the VM's application settings keeps a long-lived credential on disk and in configuration files, creating a serious exposure risk if the VM is compromised; the SAS also typically has a far wider scope than the single container unless carefully constrained. Microsoft Entra ID with a managed identity is the recommended secure authentication method because it eliminates long-lived shared secrets and allows fine-grained, revocable data-plane RBAC.

    When this WOULD be correct

    If the security requirement did not prohibit storing SAS tokens on the VM, and the app needed to access a specific container with write-only permissions, an account SAS token scoped to that container would be a valid solution.

  • Enable a managed identity on the VM and assign Storage Blob Data Contributor at the container scope.

    Why this is correct

    A managed identity lets the VM authenticate to Azure Storage through Microsoft Entra ID without storing credentials on the server. Assigning Storage Blob Data Contributor at the container scope gives the app the ability to upload and modify blob data only where needed. This is the least-privilege approach and aligns with secure operational practice for Azure administrators.

  • Assign Reader on the storage account so the VM can reach the container securely.

    Why it's wrong here

    Reader only authorizes 'read' actions against the storage account resource itself—for example, viewing account properties, keys, and configuration—and provides no access to the blob data plane. Uploading an invoice requires data-plane permission, which is granted by a role like Storage Blob Data Contributor on the container, not by the Reader role on the account. Thus, assigning Reader would let the VM inspect the account metadata but still fail to perform the required upload, and it also introduces unnecessary read access to account-level settings.

    When this WOULD be correct

    If the requirement was to allow a user or application to list or read blobs in a container (e.g., for auditing or reporting) without write permissions, assigning Reader at the storage account scope would be correct.

  • Grant Storage Account Contributor at the subscription scope so the app can manage all storage resources.

    Why it's wrong here

    Storage Account Contributor is a management-plane role that lets the principal manage storage account settings, regenerate access keys, and configure networking across every storage account in the subscription. It does not itself grant data-plane permissions to write blobs, since blob operations require an Azure RBAC data-plane role such as Storage Blob Data Contributor. Applying this at subscription scope massively exceeds the required blasting radius and violates least privilege, as the app would be able to alter storage infrastructure far beyond its intended invoice container.

    When this WOULD be correct

    This option would be correct if the question required a user or application to have full administrative control over a specific storage account (e.g., to create, delete, or configure storage resources) and the scope was limited to that storage account rather than the entire subscription.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

Enable a managed identity on the VM and assign Storage Blob Data Contributor at the container scope.Correct answer

Why this is correct

A managed identity lets the VM authenticate to Azure Storage through Microsoft Entra ID without storing credentials on the server. Assigning Storage Blob Data Contributor at the container scope gives the app the ability to upload and modify blob data only where needed. This is the least-privilege approach and aligns with secure operational practice for Azure administrators.

Create an account SAS token and store it in the VM's application settings.Wrong answer — click to see why

Why this is wrong here

Storing an account SAS token on the VM violates the security requirement that prohibits storing account keys or SAS tokens on the VM. The question explicitly forbids this approach.

★ When this WOULD be the correct answer

If the security requirement did not prohibit storing SAS tokens on the VM, and the app needed to access a specific container with write-only permissions, an account SAS token scoped to that container would be a valid solution.

Why candidates choose this

Candidates may think a SAS token is a secure way to grant limited access without keys, and overlook the explicit prohibition in the question against storing tokens on the VM.

Assign Reader on the storage account so the VM can reach the container securely.Wrong answer — click to see why

Why this is wrong here

The Reader role only allows read access to the storage account, not write access to a blob container. The app needs to upload invoices (write blobs), so Reader is insufficient.

★ When this WOULD be the correct answer

If the requirement was to allow a user or application to list or read blobs in a container (e.g., for auditing or reporting) without write permissions, assigning Reader at the storage account scope would be correct.

Why candidates choose this

Candidates may think Reader provides enough access for the app to reach the container, confusing read access with the ability to write blobs, or they may underestimate the need for a specific write role.

Grant Storage Account Contributor at the subscription scope so the app can manage all storage resources.Wrong answer — click to see why

Why this is wrong here

Storage Account Contributor at subscription scope grants full management access to all storage accounts in the subscription, far exceeding the principle of least privilege required for the app to only write blobs in one container. It also does not restrict the app to blob write operations only.

★ When this WOULD be the correct answer

This option would be correct if the question required a user or application to have full administrative control over a specific storage account (e.g., to create, delete, or configure storage resources) and the scope was limited to that storage account rather than the entire subscription.

Why candidates choose this

Candidates may think that granting a high-level contributor role is a simple way to ensure the app has the necessary permissions, without understanding the security implications of over-privileging or the need for scoped access.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 1,049 original AZ-104 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on AZ-104

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A team runs a Windows service on an Azure virtual machine that uploads invoices to Blob storage every few minutes. Security policy forbids storing account keys or long-lived SAS tokens on the VM. The service must authenticate without human interaction. What should the administrator configure?

medium
  • A.Generate a SAS token with a 1-year expiry and store it in an encrypted file on the VM.
  • B.Assign the VM a managed identity and grant it Storage Blob Data Contributor on the container or storage account.
  • C.Share the storage account access key with the service account and rotate it monthly.
  • D.Create a storage firewall rule that allows the VM's public IP address and keep using anonymous access.

Why B: Assigning a managed identity to the VM allows it to authenticate to Azure Blob Storage without any secrets stored on the VM. The managed identity provides an automatically managed service principal in Azure AD, and by granting the Storage Blob Data Contributor role, the service obtains the necessary permissions to upload invoices. This satisfies the security policy forbidding account keys or long-lived SAS tokens and enables unattended authentication.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.