Courseiva

AZ-204 Practice Question: Connect to and consume Azure services and third-party services

A developer is building a .NET console application that needs to read and write files in an Azure Storage account. The application will run on a developer's workstation and must authenticate using Microsoft Entra ID (Azure AD). The developer has been granted the Storage Blob Data Contributor role on the storage account. Which method should the developer use to authenticate the application to Azure Storage?

⚠ Common exam trap

The trap here is assuming that a SAS token or account key is acceptable because it works, but the requirement specifically mandates Microsoft Entra ID authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the DefaultAzureCredential class from the Azure.Identity library.

DefaultAzureCredential simplifies authentication by trying several methods in order, including environment variables, managed identity, and developer tool credentials. On a workstation, it will use the signed-in user's Microsoft Entra ID identity from Azure CLI or Visual Studio. Because the developer has the Storage Blob Data Contributor role, this credential will have the necessary permissions to read and write blobs, satisfying the Microsoft Entra ID requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the storage account's connection string with the account name and key.

    Why it's wrong here

    A connection string with the account name and key uses shared key authorization, not Microsoft Entra ID. This method grants full access to the storage account and does not respect the Storage Blob Data Contributor role. It is not the correct approach when Microsoft Entra ID authentication is required. The developer should avoid using account keys and instead use Microsoft Entra ID credentials.

  • ✓

    Use the DefaultAzureCredential class from the Azure.Identity library.

    Why this is correct

    DefaultAzureCredential automatically attempts multiple authentication methods, including Azure CLI credentials, managed identity, and Visual Studio account. On a developer workstation, it can use the developer's Microsoft Entra ID login from tools like Azure CLI or Visual Studio. Since the developer has the Storage Blob Data Contributor role, this credential will authenticate successfully and is the recommended approach for Microsoft Entra ID authentication.

  • ✗

    Use the storage account's primary access key in the connection string.

    Why it's wrong here

    Using the primary access key provides full access to the storage account and bypasses Microsoft Entra ID authentication. While it works, it does not meet the requirement to authenticate using Microsoft Entra ID. Additionally, access keys are sensitive and should not be used when Microsoft Entra ID authentication is available. The developer should leverage the assigned role for better security and management.

  • ✗

    Generate a shared access signature (SAS) token with read and write permissions.

    Why it's wrong here

    A SAS token is a delegated access method that grants specific permissions without requiring Microsoft Entra ID. However, the scenario explicitly requires Microsoft Entra ID authentication. While a SAS token can be used, it does not fulfill the requirement and may be less secure if not managed properly. The developer should use Microsoft Entra ID to align with the role assignment and security best practices.

Go deeper

Related to this question

About these practice questions

This AZ-204 question is part of Courseiva's 883-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.