Courseiva
Implement Azure security →easyMultiple Choice

AZ-204 Implement Azure security Practice Question

You are developing a web application that stores user profile images in an Azure Storage account. The images must be accessible only to authenticated users of your application, and you want to avoid managing access keys. You need to configure the storage account to allow the app to access blobs securely using Microsoft Entra ID. What should you do?

⚠ Common exam trap

The trap here is thinking that using Key Vault to store the storage account key is sufficient, when the requirement is to use Microsoft Entra ID and avoid access keys altogether.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assign the Storage Blob Data Contributor role to the app's managed identity.

The correct approach is to assign the Storage Blob Data Contributor role to the app's managed identity. This enables the app to authenticate to Azure Storage using Microsoft Entra ID and access blobs with role-based permissions, eliminating the need for access keys or SAS tokens. It aligns with the requirement to avoid managing access keys and ensures only authenticated and authorized identities can access the images.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Generate a shared access signature (SAS) token and embed it in the application code.

    Why it's wrong here

    A SAS token is a delegated access credential that must be protected and rotated. Embedding it in code exposes it to leakage and requires management, which contradicts the goal of avoiding access keys and secret management. SAS tokens also do not provide identity-based authentication with Microsoft Entra ID.

  • ✓

    Assign the Storage Blob Data Contributor role to the app's managed identity.

    Why this is correct

    Assigning the Storage Blob Data Contributor role to the app's managed identity grants the app permission to read and write blobs using Microsoft Entra ID authentication. This avoids access keys and allows secure, role-based access. The app can use the Azure Identity SDK to obtain a token and access blobs without managing secrets.

  • ✗

    Store the storage account key in Azure Key Vault and retrieve it at runtime.

    Why it's wrong here

    Storing the storage account key in Key Vault still requires the app to retrieve and use a shared key, which is not identity-based authentication. While Key Vault adds security, the app still manages a key and does not use Microsoft Entra ID for storage access. This does not meet the requirement of avoiding access keys entirely.

  • ✗

    Enable anonymous public access on the container.

    Why it's wrong here

    Enabling anonymous public access allows anyone on the internet to read blobs without authentication, which violates the requirement that only authenticated users can access the images. This also does not use Microsoft Entra ID for access control. It is a security risk and not suitable for protected user data.

Go deeper

Related to this question

About these practice questions

One of 883 original AZ-204 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.