AZ-204 Develop for Azure storage Practice Question
Which FOUR are valid ways to authenticate to Azure Blob Storage from an application? (Choose four.)
⚠ Common exam trap
Common mistake: Candidates often assume that only one of OAuth2 user token (B) and managed identity (E) is valid, but both are supported methods. Also, client certificates (D) are not directly supported for Blob Storage authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the storage account access key.
The storage account access key provides full administrative access to the storage account, including Blob Storage. It is a simple, shared-key authentication method using HMAC-SHA256 to sign requests. Option B is correct because OAuth2 tokens obtained from Microsoft Entra ID for a user are a supported authentication method for Azure Blob Storage, enabling fine-grained access control. Option C is correct because a shared access signature (SAS) token provides delegated access to storage resources with specified permissions and expiry. Option E is correct because a managed identity assigned to an Azure resource (e.g., a VM or App Service) can be used to authenticate to Blob Storage without storing credentials. Option D is incorrect because client certificates are not a supported authentication method for direct access to Azure Blob Storage; they are used for device authentication or authenticating to Azure AD as a service principal.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use the storage account access key.
Why this is correct
The storage account access key is a valid authentication method, providing full access to the account. It is commonly used for administrative tasks or when fine-grained control is not required.
- ✓
Use an OAuth2 token obtained from Microsoft Entra ID for a user.
Why this is correct
An OAuth2 token obtained from Microsoft Entra ID for a user identity is a supported authentication method for Azure Blob Storage. It enables role-based access and is ideal for user-facing applications.
- ✓
Use a shared access signature (SAS) token.
Why this is correct
A shared access signature (SAS) token is a valid method for granting delegated access to Blob Storage resources with controlled permissions and expiry. It is useful for providing time-limited access.
- ✗
Use a client certificate.
Why it's wrong here
Client certificates are not a supported authentication method for Azure Blob Storage. They can be used for device authentication or to authenticate to Azure AD as a service principal, but not directly for Blob Storage access.
- ✓
Use a managed identity assigned to an Azure resource.
Why this is correct
A managed identity assigned to an Azure resource (e.g., a virtual machine or App Service) is a valid authentication method for Azure Blob Storage. It allows secure authentication without storing credentials.
Quick reference
Azure Blob Storage Tier Comparison
| Tier | Storage Cost | Retrieval Cost | Latency | Use Case |
|---|---|---|---|---|
| Hot | Highest | Lowest | Immediate | Active data, frequent reads |
| Cool | Lower | Higher | Immediate | Data accessed < once / month |
| Cold | Lower still | Higher | Immediate | Data accessed < once / quarter |
| Archive | Lowest | Highest + rehydration delay | Hours | Long-term compliance retention |
Go deeper
Related to this question
Learn chapter
Azure Functions Development
Key term
Shared Access Signatures
A Shared Access Signature (SAS) is a secure token that grants limited, time-bound access to specific Azure Storage resources without exposing your account key.
Key term
Managed identity
A managed identity is an automatically managed service principal in Azure that allows your code to authenticate to any service that supports Azure AD authentication without storing credentials.
About these practice questions
Courseiva writes every AZ-204 question from scratch — 881 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.