AZ-204 Develop for Azure storage Practice Question
Which FOUR are valid ways to authenticate to Azure Blob Storage from an application? (Choose four.)
⚠ Common exam trap
Common mistake: Candidates often assume that only one of OAuth2 user token (B) and managed identity (E) is valid, but both are supported methods. Also, client certificates (D) are not directly supported for Blob Storage authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the storage account access key.
Option A is correct because the storage account access key (key1/key2) is a shared secret that authorizes full access to the account's data plane and is a standard authentication method for Blob Storage. Option B is correct because OAuth2 bearer tokens issued by Microsoft Entra ID (for a user principal) can be presented to the Blob service and validated via Azure RBAC roles such as Storage Blob Data Reader/Contributor. Option C is correct because a shared access signature is a signed URL/token delegating scoped, time-limited permissions to blob resources, and it is a supported authentication mechanism. Option E is correct because a managed identity assigned to an Azure resource (system- or user-assigned) obtains an Entra ID token that the Blob SDK can use without storing credentials. Option D is not a valid Blob Storage authentication method; client certificates are used for other services (for example, service principals with certificate credentials authenticate to Entra ID, not directly to Blob Storage).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use the storage account access key.
Why this is correct
The storage account access key is a shared secret granting full access to the account's blob data, and applications can pass it via connection string or SharedKey authorisation. It is a valid authentication method, though less granular than Microsoft Entra ID.
- ✓
Use an OAuth2 token obtained from Microsoft Entra ID for a user.
Why this is correct
An OAuth2 bearer token issued by Microsoft Entra ID for a signed-in user can be presented in the Authorization header to Blob Storage, granting delegated access scoped by the user's RBAC role assignments, satisfying the requirement for a valid application authentication method.
- ✓
Use a shared access signature (SAS) token.
Why this is correct
A shared access signature is a delegated, time-limited token granting scoped permissions to blob resources without exposing account keys. It authenticates the application to Azure Blob Storage, satisfying the stem's requirement for a valid authentication method.
- ✗
Use a client certificate.
Why it's wrong here
Client certificates are not a supported authentication method for Azure Blob Storage. They can be used for device authentication or to authenticate to Microsoft Entra ID as a service principal, but not directly for Blob Storage access.
- ✓
Use a managed identity assigned to an Azure resource.
Why this is correct
A managed identity assigned to an Azure resource obtains tokens from Microsoft Entra ID, letting the application authenticate to Azure Blob Storage without stored credentials. This satisfies the stem's requirement for a valid authentication method.
Quick reference
Azure Blob Storage Tier Comparison
| Tier | Storage Cost | Retrieval Cost | Latency | Use Case |
|---|---|---|---|---|
| Hot | Highest | Lowest | Immediate | Active data, frequent reads |
| Cool | Lower | Higher | Immediate | Data accessed < once / month |
| Cold | Lower still | Higher | Immediate | Data accessed < once / quarter |
| Archive | Lowest | Highest + rehydration delay | Hours | Long-term compliance retention |
Go deeper
Related to this question
Learn chapter
Microsoft Graph API Integration
Key term
Shared Access Signatures
A Shared Access Signature (SAS) is a secure token that grants limited, time-bound access to specific Azure Storage resources without exposing your account key.
Key term
Managed identity
A managed identity is an automatically managed service principal in Azure that allows your code to authenticate to any service that supports Microsoft Entra ID authentication without storing credentials.
About these practice questions
Courseiva writes every AZ-204 question from scratch — 883 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.