AZ-204 Implement Azure security Practice Question
You are developing a web application that stores user profile images in an Azure Storage account. The images must be accessible only to authenticated users of your application, and you want to avoid managing access keys. You need to configure the storage account to allow the app to access blobs securely using Microsoft Entra ID. What should you do?
⚠ Common exam trap
The trap here is thinking that using Key Vault to store the storage account key is sufficient, when the requirement is to use Microsoft Entra ID and avoid access keys altogether.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign the Storage Blob Data Contributor role to the app's managed identity.
The correct approach is to assign the Storage Blob Data Contributor role to the app's managed identity. This enables the app to authenticate to Azure Storage using Microsoft Entra ID and access blobs with role-based permissions, eliminating the need for access keys or SAS tokens. It aligns with the requirement to avoid managing access keys and ensures only authenticated and authorized identities can access the images.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Generate a shared access signature (SAS) token and embed it in the application code.
Why it's wrong here
A SAS token is a delegated access credential that must be protected and rotated. Embedding it in code exposes it to leakage and requires management, which contradicts the goal of avoiding access keys and secret management. SAS tokens also do not provide identity-based authentication with Microsoft Entra ID.
- ✓
Assign the Storage Blob Data Contributor role to the app's managed identity.
Why this is correct
Assigning the Storage Blob Data Contributor role to the app's managed identity grants the app permission to read and write blobs using Microsoft Entra ID authentication. This avoids access keys and allows secure, role-based access. The app can use the Azure Identity SDK to obtain a token and access blobs without managing secrets.
- ✗
Store the storage account key in Azure Key Vault and retrieve it at runtime.
Why it's wrong here
Storing the storage account key in Key Vault still requires the app to retrieve and use a shared key, which is not identity-based authentication. While Key Vault adds security, the app still manages a key and does not use Microsoft Entra ID for storage access. This does not meet the requirement of avoiding access keys entirely.
- ✗
Enable anonymous public access on the container.
Why it's wrong here
Enabling anonymous public access allows anyone on the internet to read blobs without authentication, which violates the requirement that only authenticated users can access the images. This also does not use Microsoft Entra ID for access control. It is a security risk and not suitable for protected user data.
Go deeper
Related to this question
Learn chapter
Managed Certificates in App Service
Key term
Key Vault Secrets
Key Vault Secrets are secure containers in Microsoft Azure that store sensitive information like passwords, connection strings, and API keys, keeping them encrypted and accessible only to authorized applications and users.
Key term
Managed identity
A managed identity is an automatically managed service principal in Azure that allows your code to authenticate to any service that supports Microsoft Entra ID authentication without storing credentials.
About these practice questions
One of 883 original AZ-204 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.