Courseiva

AZ-104 · topic practice

Storage Account practice questions

Practise AZ-104 Storage Account practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Storage Account

What the exam tests

What to know about Storage Account

Storage Account questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Storage Account exam traps

  • ▸Answering from memory before reading the full scenario.
  • ▸Missing a constraint such as cost, availability, security, scope or command context.
  • ▸Choosing a broad answer when the question asks for the most specific fix.
  • ▸Ignoring why the wrong options are tempting.

Practice set

Storage Account questions

20 questions · select your answer, then reveal the explanation

Match each access scenario to the SAS or key type that best fits it.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

User delegation SAS

Service SAS

Account SAS

Storage account key

Match each workload requirement to the Azure storage account kind that best fits it.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

General-purpose v2

FileStorage

BlockBlobStorage

BlobStorage

Question 3mediummultiple choice
Read the full Storage Account explanation →

A storage account has public network access disabled. A VM in VNet-App can reach a private endpoint for the account, but the storage name still resolves to the public IP address from the VM, and connections are denied. What should the administrator configure?

Question 4easymultiple choice
Review the full subnetting walkthrough →

A storage account should accept traffic only from one subnet, but the team does not want to create a private IP address for the service in the virtual network. What should they enable?

Question 5mediummultiple choice
Read the full Storage Account explanation →

A storage account must stay online for applications, but administrators have a temporary freeze on configuration changes. Users can still view the account, but attempts to change the access tier, create a container, or update networking all fail. What most likely caused the behavior?

Arrange the steps to create an Azure Storage account with a container and upload a blob.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
Question 7mediummultiple choice
Read the full Storage Account explanation →

Based on the exhibit, what should the administrator do so VM-B resolves the storage account name to the private IP address?

Exhibit

From VM-B in VNet-B: nslookup mystorage.blob.core.windows.net returns 20.52.10.7; the storage account has a private endpoint in VNet-A at 10.4.1.5; the private DNS zone privatelink.blob.core.windows.net is linked only to VNet-A.

Based on the exhibit, a policy assigned at the subscription denies storage accounts that allow public network access. One existing storage account in RG-Legacy must remain publicly reachable for 30 days while a migration is completed. What should the administrator use?

Exhibit

Policy compliance details

Assignment name: Deny-Public-Storage
Scope: Subscription / Contoso-Prod
Effect: Deny
Condition: Microsoft.Storage/storageAccounts/publicNetworkAccess = 'Enabled'
Compliance state:
- stapp01: Non-compliant, creation denied
- stlegacy01: Non-compliant, existing exception requested by application team
Request note:
- Keep stlegacy01 publicly reachable until migration is complete
- Do not change the policy for all other resources
Question 9mediummultiple choice
Read the full Storage Account explanation →

A contractor must import data into one blob container for six hours. The contractor should not receive the storage account key, and access must be limited to that container only. Which credential should the administrator generate?

Question 10mediummultiple choice
Read the full Storage Account explanation →

A Windows file server VM in Azure must mount an Azure file share by using existing Active Directory Domain Services credentials instead of a storage account key. The organization already has domain-joined Windows servers in the environment. What should the administrator configure on the storage account?

Question 11mediummultiple choice
Read the full Storage Account explanation →

A contractor needs to upload data into one specific blob container for six hours. The administrator must avoid sharing the storage account key and should grant only the minimum permissions needed. Which access method should be used?

Question 12easymultiple choice
Review the full subnetting walkthrough →

A storage account must be reachable only from resources in one Azure subnet, and public network access should not be used. Which configuration best meets this requirement?

Question 13hardmultiple choice
Read the full Storage Account explanation →

A new Windows VM must be deployed with an application installed, a configuration file copied from a storage account, and a bootstrap script run automatically after the operating system is provisioned. The operations team does not want to log in manually after deployment. What should they use?

Question 14easymultiple choice
Read the full Storage Account explanation →

A contractor needs temporary access to upload files into one Azure Blob container for six hours. The administrator does not want to share the storage account key. What should the administrator create?

Question 15mediummultiple choice
Read the full Storage Account explanation →

A contractor needs temporary access to upload and download files in only one blob container for 8 hours. You do not want to share the storage account key, and you want to revoke access later without affecting other containers. What should you create?

Question 16mediummultiple choice
Read the full Storage Account explanation →

A web app running in Azure App Service must upload images to a blob container without storing any account keys, passwords, or connection strings in configuration. The app uses only one Azure resource. What should the administrator configure?

Question 17mediummultiple choice
Read the full Storage Account explanation →

A VM in a virtual network must access an Azure Storage account over a private IP address, and the storage account's public endpoint must be disabled. Name resolution from the VM should resolve the storage name to the private IP. Which configuration should you use?

Question 18easymultiple choice
Read the full Storage Account explanation →

Based on the exhibit, a shared resource group contains a production virtual machine and a storage account. Administrators must be able to update settings, but they must not be able to delete either resource by mistake. Which lock should be applied at the resource group scope?

Exhibit

Resource group: RG-Prod-Shared
Resources:
- prodvm01 (Microsoft.Compute/virtualMachines)
- prodstore01 (Microsoft.Storage/storageAccounts)

Change control note:
- Updates must still be allowed
- Accidental deletion must be prevented
- Lock should apply to both resources in the group
Question 19easymultiple choice
Read the full Storage Account explanation →

Based on the exhibit, a compliance dashboard shows that several storage accounts are marked noncompliant because they do not have the required tag. The policy itself is correct, but one business unit needs a temporary exception for a single resource group during a merger. What should the administrator configure?

Exhibit

Compliance report excerpt

Policy assignment: Require-department-tag
Scope: corp-root management group
Effect: Deny
Noncompliant resources:
- rg-merger01/storage accounts
- rg-merger02/storage accounts
Exception request:
- Allow only resource group rg-merger01 to bypass this policy for 45 days
- Keep the policy active for everyone else
Question 20mediummultiple choice
Read the full Storage Account explanation →

A production resource group contains several VMs and a storage account. The operations manager wants to prevent accidental deletion of the resource group and its resources, but still allow normal configuration changes during maintenance windows. Which lock should be applied to the resource group?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Storage Account sessions

Start a Storage Account only practice session

Every question in these sessions is drawn from the Storage Account domain — nothing else.

Related practice questions

Related AZ-104 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the AZ-104 exam test about Storage Account?
Storage Account questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Storage Account questions in a focused session?
Yes — the session launcher on this page draws every question from the Storage Account domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other AZ-104 topics?
Use the topic links above to move to related areas, or go back to the AZ-104 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the AZ-104 exam covers. They are not copied from any real exam or dump site.