AZ-204 Develop for Azure storage Practice Question
A storage account for thumbnail metadata must allow an application to read only blobs under one container for two hours. The application should not receive the account key. What should be issued?
⚠ Common exam trap
Candidates often confuse a service SAS with a public access level or account key, failing to recognize that a SAS provides granular, time-bound delegation without exposing the account key, while public access is permanent and account keys grant full control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A service SAS scoped to the container with read permission and expiry
A service SAS scoped to a container with read permission and an expiry of two hours is the correct approach because it provides delegated, time-limited access to specific blobs under that container without exposing the storage account key. The SAS token is generated using the account key but the application only receives the token, not the key itself, ensuring the key remains secure. This meets the requirement for read-only access to a single container for a limited duration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A public access level on the container
Why it's wrong here
Public access on the container grants anonymous read to every blob indefinitely, with no per-application credential, expiry or revocation. It is tempting because it requires no key distribution, and would be correct only for genuinely public content such as website images that anyone may retrieve without authentication.
- ✓
A service SAS scoped to the container with read permission and expiry
Why this is correct
A service SAS is signed with the account key but delegates only scoped permissions, so the application receives a time-limited token rather than the key itself. Scoping to the container with read permission and a two-hour expiry satisfies both the least-privilege and no-account-key constraints.
- ✗
A management group assignment
Why it's wrong here
A management group assignment governs Azure RBAC inheritance across subscriptions and resources; it cannot grant blob-level read access scoped to a single container for two hours. It is tempting because management groups organise governance at scale, and would be correct when assigning policy or role inheritance across many subscriptions.
- ✗
The storage account access key
Why it's wrong here
The account key grants full control over the entire storage account, including write and delete on every container, and cannot be scoped or time-limited. It is tempting because it is the simplest credential for authenticating blob requests, and would be correct only for trusted backend services that require unrestricted account-level access.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-204 question from scratch — 883 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.