AZ-204 Implement Azure security Practice Question
You need to secure access to an Azure Storage account that contains sensitive data. Which TWO of the following are recommended best practices?
⚠ Common exam trap
Watch out — candidates often think rotating keys frequently (Option A) is always better, but Azure's best practices emphasize reducing key usage entirely via managed identities, not just rotating keys more often.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use managed identities to access storage from Azure services
Option B is correct because managed identities let Azure services (such as VMs, App Service, or Functions) authenticate to Storage using Microsoft Entra ID tokens, eliminating the need to store and manage storage account keys or connection strings in code or configuration. Option C is correct because configuring firewall rules on the storage account to allow only specific public IP addresses or Azure virtual networks (via service endpoints or private endpoints) restricts network-level access to trusted sources, which is a core defense-in-depth practice for sensitive data. Option A is not recommended because rotating keys every 24 hours is operationally impractical and unnecessary; Microsoft recommends periodic rotation (for example, every 90 days) or, better, avoiding keys entirely by using Microsoft Entra ID/managed identities. Option D is wrong because long-lived SAS tokens increase the exposure window if leaked; SAS tokens should be short-lived and scoped with least privilege. Option E is wrong because enabling anonymous public access to all containers exposes data to anyone on the internet and directly violates the goal of securing sensitive data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Rotate storage account keys every 24 hours
Why it's wrong here
Rotating storage account keys every 24 hours is an excessively frequent practice that introduces significant operational overhead and potential for service disruption. While key rotation is crucial for security, best practices typically recommend rotation intervals of 90 to 180 days, allowing sufficient time for key updates across dependent applications without constant, high-risk changes.
- ✓
Use managed identities to access storage from Azure services
Why this is correct
Using managed identities is a highly recommended security practice for Azure services accessing storage, as it eliminates the need to store or manage credentials within application code. Managed identities provide an automatically managed identity in Microsoft Entra ID, enabling secure authentication and authorization to storage accounts via Azure Role-Based Access Control (RBAC). This approach significantly reduces the risk of credential leakage and simplifies security management.
- ✓
Configure firewall rules to restrict access to specific IP addresses or VNets
Why this is correct
Configuring firewall rules to restrict access to specific IP addresses or virtual networks is a fundamental security measure for Azure Storage accounts. This practice creates a network perimeter, ensuring that only authorized traffic originating from trusted sources can reach the storage account. By limiting the network attack surface, it significantly reduces the risk of unauthorized access attempts from the public internet.
- ✗
Use SAS tokens with long expiry dates
Why it's wrong here
Using Shared Access Signatures (SAS) tokens with long expiry dates is a significant security anti-pattern that drastically increases the risk of unauthorized access. If a long-lived SAS token is compromised, an attacker gains extended, unauthenticated access to the specified storage resources, making it challenging to revoke promptly. Best practice dictates using SAS tokens with the shortest possible expiry and least privilege necessary for the task.
- ✗
Enable anonymous public access for all containers
Why it's wrong here
Enabling anonymous public access for all containers is a critical security vulnerability that allows anyone on the internet to read data without any authentication. This setting bypasses all access control mechanisms, exposing potentially sensitive information to the public. For most enterprise scenarios, public access should be disabled by default and only selectively granted for specific, non-sensitive content like static website assets, under strict control.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-204 question from scratch — 883 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.