AZ-204 Develop for Azure storage Practice Question
Which TWO of the following are valid ways to authenticate to Azure Blob Storage from an application? (Choose two.)
⚠ Common exam trap
Candidates often confuse Microsoft Entra ID authentication (which uses OAuth 2.0 tokens) with personal Microsoft account OAuth tokens, or mistakenly think Cosmos DB keys or SQL Server credentials can be reused across Azure services, when each service has its own distinct authentication mechanism.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Storage account access key
Option C (Storage account access key) is correct because Azure Blob Storage supports authorization using the storage account's access keys, which are shared secrets that grant full access to the storage account and can be used by an application to sign requests. Option D (Shared access signature (SAS) token) is also correct because a SAS is a URI that grants restricted, time-limited access rights to Blob Storage resources, and applications can authenticate by presenting this token. Option A is not valid because personal Microsoft account OAuth tokens are not an authentication mechanism for Blob Storage data-plane access; Microsoft Entra ID (work/school) identities are used instead. Option B is incorrect because SQL Server authentication applies to Azure SQL Database, not Blob Storage. Option E is incorrect because Azure Cosmos DB primary keys authenticate to Cosmos DB, not Blob Storage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft account (personal) OAuth token
Why it's wrong here
Personal Microsoft accounts (e.g., @outlook.com, @hotmail.com) are primarily for consumer services and do not integrate directly with Microsoft Entra ID (Azure AD) for resource authentication. Azure Storage accounts rely on Microsoft Entra ID identities for role-based access control (RBAC) and OAuth token-based authentication. Therefore, an OAuth token issued for a personal Microsoft account cannot be used to authenticate requests to Azure Blob Storage, which requires an Microsoft Entra ID identity.
- ✗
SQL Server authentication
Why it's wrong here
SQL Server authentication is a mechanism specifically designed for authenticating users and applications to SQL Server instances, including Azure SQL Database and Azure SQL Managed Instance. It involves usernames and passwords managed within the database server itself. This authentication method is entirely distinct and incompatible with Azure Blob Storage, which uses different protocols and security models for access control, such as shared keys, SAS tokens, or Microsoft Entra ID.
- ✓
Storage account access key
Why this is correct
A storage account access key is a symmetric key that grants full administrative access to all data within the storage account. There are two such keys (key1 and key2) per account, allowing for key rotation without service interruption. When used, the key is included in the request header to sign the request, and the storage service validates this signature, granting complete control over blobs, files, queues, and tables.
- ✓
Shared access signature (SAS) token
Why this is correct
A Shared Access Signature (SAS) token provides delegated access to specific resources within a storage account for a defined period and with specified permissions. This token is a URI that contains a query string with all the necessary authentication information, including the resource to access, permissions granted, and the validity period. It allows clients to access storage resources without exposing the storage account's primary access keys, enhancing security by limiting scope and duration.
- ✗
Azure Cosmos DB primary key
Why it's wrong here
An Azure Cosmos DB primary key is a security credential used to grant full administrative access to a specific Azure Cosmos DB account. These keys are unique to Cosmos DB and are designed to authenticate requests against its various APIs (e.g., SQL API, MongoDB API). They are fundamentally different from storage account keys or SAS tokens and cannot be used to authenticate requests to Azure Blob Storage, which operates on a distinct authentication and authorization model.
Quick reference
Azure Blob Storage Tier Comparison
| Tier | Storage Cost | Retrieval Cost | Latency | Use Case |
|---|---|---|---|---|
| Hot | Highest | Lowest | Immediate | Active data, frequent reads |
| Cool | Lower | Higher | Immediate | Data accessed < once / month |
| Cold | Lower still | Higher | Immediate | Data accessed < once / quarter |
| Archive | Lowest | Highest + rehydration delay | Hours | Long-term compliance retention |
Go deeper
Related to this question
About these practice questions
This AZ-204 question is part of Courseiva's 883-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.