Courseiva
Develop for Azure storage →mediumMultiple Select

AZ-204 Develop for Azure storage Practice Question

Which FOUR are valid ways to authenticate to Azure Blob Storage from an application? (Choose four.)

⚠ Common exam trap

Common mistake: Candidates often assume that only one of OAuth2 user token (B) and managed identity (E) is valid, but both are supported methods. Also, client certificates (D) are not directly supported for Blob Storage authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the storage account access key.

Option A is correct because the storage account access key (key1/key2) is a shared secret that authorizes full access to the account's data plane and is a standard authentication method for Blob Storage. Option B is correct because OAuth2 bearer tokens issued by Microsoft Entra ID (for a user principal) can be presented to the Blob service and validated via Azure RBAC roles such as Storage Blob Data Reader/Contributor. Option C is correct because a shared access signature is a signed URL/token delegating scoped, time-limited permissions to blob resources, and it is a supported authentication mechanism. Option E is correct because a managed identity assigned to an Azure resource (system- or user-assigned) obtains an Entra ID token that the Blob SDK can use without storing credentials. Option D is not a valid Blob Storage authentication method; client certificates are used for other services (for example, service principals with certificate credentials authenticate to Entra ID, not directly to Blob Storage).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use the storage account access key.

    Why this is correct

    The storage account access key is a shared secret granting full access to the account's blob data, and applications can pass it via connection string or SharedKey authorisation. It is a valid authentication method, though less granular than Microsoft Entra ID.

  • ✓

    Use an OAuth2 token obtained from Microsoft Entra ID for a user.

    Why this is correct

    An OAuth2 bearer token issued by Microsoft Entra ID for a signed-in user can be presented in the Authorization header to Blob Storage, granting delegated access scoped by the user's RBAC role assignments, satisfying the requirement for a valid application authentication method.

  • ✓

    Use a shared access signature (SAS) token.

    Why this is correct

    A shared access signature is a delegated, time-limited token granting scoped permissions to blob resources without exposing account keys. It authenticates the application to Azure Blob Storage, satisfying the stem's requirement for a valid authentication method.

  • ✗

    Use a client certificate.

    Why it's wrong here

    Client certificates are not a supported authentication method for Azure Blob Storage. They can be used for device authentication or to authenticate to Microsoft Entra ID as a service principal, but not directly for Blob Storage access.

  • ✓

    Use a managed identity assigned to an Azure resource.

    Why this is correct

    A managed identity assigned to an Azure resource obtains tokens from Microsoft Entra ID, letting the application authenticate to Azure Blob Storage without stored credentials. This satisfies the stem's requirement for a valid authentication method.

Quick reference

Azure Blob Storage Tier Comparison

TierStorage CostRetrieval CostLatencyUse Case
HotHighestLowestImmediateActive data, frequent reads
CoolLowerHigherImmediateData accessed < once / month
ColdLower stillHigherImmediateData accessed < once / quarter
ArchiveLowestHighest + rehydration delayHoursLong-term compliance retention

About these practice questions

Courseiva writes every AZ-204 question from scratch — 883 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.