AZ-104 Implement and Manage Storage Practice Question
You need to give a third-party auditor temporary read-only access to specific blobs in a container without sharing the storage account keys. Which feature should you use?
⚠ Common exam trap
Test-takers frequently confuse resource locks (which prevent deletion) with access control mechanisms, or mistakenly think blob versioning provides access delegation, when in fact only SAS tokens offer granular, time-bound, and keyless access to specific blobs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A shared access signature (SAS)
A shared access signature (SAS) is the correct choice because it provides delegated, time-limited, and permission-restricted access to specific Azure Storage resources—in this case, blobs—without exposing the storage account keys. You can generate a service-level SAS token scoped to individual blobs with read-only permissions and an expiration time, allowing the auditor to access only the required blobs. This meets the requirement for temporary, read-only access while maintaining security and granular control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A storage account key
Why it's wrong here
Sharing a storage account key grants full administrative access to the entire storage account, including the ability to read, write, delete, and modify all data and service configurations. Account keys never expire and are the root credentials for the storage account, so providing one to a third-party auditor violates the principle of least privilege and introduces a significant security risk. Even if the intent is read-only, the key enables far more than reading, and managing its distribution or rotation would be impractical for a temporary audit.
When this WOULD be correct
When the question asks for a method to provide full access to all storage account resources (e.g., for an internal admin) and key rotation is acceptable, a storage account key would be correct.
- ✓
A shared access signature (SAS)
Why this is correct
A shared access signature (SAS) is the correct choice because it provides delegated, time-limited access to specific storage resources with granular permissions, such as read-only, without exposing the storage account keys. SAS tokens can be scoped to a single container or blob, restricted to a defined IP range or protocol, and can be set to expire automatically, making them ideal for a third-party auditor's temporary read-only access. This ensures the auditor can retrieve the required data while maintaining full control over the scope and duration of access, and the token can be revoked or regenerated if necessary.
- ✗
A resource lock
Why it's wrong here
A resource lock is an Azure control-plane governance tool that prevents resources from being accidentally deleted or modified by applying a read-only or delete lock at the subscription, resource group, or resource level. It does not grant any data-plane access to the storage account's contents; a user or application with read permissions in Azure RBAC is still unaffected by a lock unless the lock itself restricts CRUD operations. Therefore, while a lock might protect the audit data from tampering, it cannot give a third-party auditor any ability to actually read the blobs.
When this WOULD be correct
You need to prevent a critical storage container from being deleted or modified by any user, even those with Contributor or Owner permissions. A resource lock (e.g., CanNotDelete) would be the correct feature to use.
- ✗
Blob versioning
Why it's wrong here
Blob versioning is an Azure Storage data protection feature that automatically keeps previous versions of blobs whenever they are modified or deleted, enabling recovery from accidental overwrites. It does not grant any access permissions or alter access control in any way; it merely preserves data history. A third-party auditor would still need a mechanism like SAS or an identity-based role assignment to even read the existing or archived versions, so versioning alone cannot provide temporary read-only access.
When this WOULD be correct
A question asks: 'You need to maintain a history of blob changes to recover from accidental overwrites or deletions. Which feature should you enable?' In that scenario, blob versioning is the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓A shared access signature (SAS)Correct answer▾
Why this is correct
A shared access signature (SAS) is the correct choice because it provides delegated, time-limited access to specific storage resources with granular permissions, such as read-only, without exposing the storage account keys. SAS tokens can be scoped to a single container or blob, restricted to a defined IP range or protocol, and can be set to expire automatically, making them ideal for a third-party auditor's temporary read-only access. This ensures the auditor can retrieve the required data while maintaining full control over the scope and duration of access, and the token can be revoked or regenerated if necessary.
✗A storage account keyWrong answer — click to see why▾
Why this is wrong here
Sharing a storage account key grants full administrative access to the entire storage account, not temporary read-only access to specific blobs, and violates the principle of least privilege.
★ When this WOULD be the correct answer
When the question asks for a method to provide full access to all storage account resources (e.g., for an internal admin) and key rotation is acceptable, a storage account key would be correct.
Why candidates choose this
Candidates may think the key is the simplest way to grant access without realizing it provides unrestricted, permanent access to the entire account, not just specific blobs.
✗A resource lockWrong answer — click to see why▾
Why this is wrong here
A resource lock prevents accidental deletion or modification of resources but does not provide any form of access control or temporary read-only access to specific blobs.
★ When this WOULD be the correct answer
You need to prevent a critical storage container from being deleted or modified by any user, even those with Contributor or Owner permissions. A resource lock (e.g., CanNotDelete) would be the correct feature to use.
Why candidates choose this
Candidates might confuse resource locks with access control mechanisms, thinking they can restrict access to blobs, when in fact locks only protect against deletion/modification, not read access.
✗Blob versioningWrong answer — click to see why▾
Why this is wrong here
Blob versioning preserves previous versions of blobs but does not provide temporary, granular read-only access to specific blobs for a third party without using storage account keys.
★ When this WOULD be the correct answer
A question asks: 'You need to maintain a history of blob changes to recover from accidental overwrites or deletions. Which feature should you enable?' In that scenario, blob versioning is the correct answer.
Why candidates choose this
Candidates may confuse blob versioning with access control mechanisms, thinking it can be used to grant access to specific versions, but it does not provide authentication or authorization.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Managed Identities for Azure Resources
Key term
Container
A container is a lightweight, standalone software package that includes everything needed to run an application, such as code, runtime, system tools, and libraries.
Key term
Shared access signature
A shared access signature (SAS) is a secure, time-limited URL that grants granular access to specific resources in cloud storage, allowing you to delegate permissions without sharing your account keys.
About these practice questions
This AZ-104 question is part of Courseiva's 1,049-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.