You are developing a solution that uses Azure Container Instances (ACI) to run a batch processing job. The job runs for approximately 30 minutes and requires access to a configuration file stored in Azure Files. You need to ensure the container instance can access the file share securely without using a public endpoint. Which TWO actions should you take?
Azure Container Instances (ACI) supports mounting Azure Files shares directly, enabling persistent storage for containers. To mount an Azure Files share, the container group requires the storage account name and its corresponding storage account key. This key acts as the primary credential for authentication and authorization to access the file share. For security, the storage account key should be passed to the container securely, typically via environment variables marked as secure or through Azure Key Vault integration, rather than hardcoding it in the container definition.
Why this answer
Mounting an Azure Files share using the storage account name and key is a supported method in Azure Container Instances. This approach uses the SMB protocol to directly attach the file share to the container, providing access to the configuration file without requiring a public endpoint. The storage account key is passed securely as part of the container group configuration, and the mount is handled internally within the Azure infrastructure.
Exam trap
The trap here is that candidates often assume managed identities can be used for any Azure resource authentication, but Azure Container Instances does not support managed identities for Azure Files mounts, and they may overlook that service endpoints provide private connectivity without needing to change the authentication method.