Courseiva

AZ-204 Develop Azure compute solutions Practice Question

Your company runs a batch processing job on Azure Batch. The job processes large datasets and requires access to Azure Storage. You need to ensure that the compute nodes can securely access the storage account without exposing credentials. What should you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Managed identity for the Batch pool

Managed identities for Azure resources allow compute nodes to authenticate to Azure Storage without storing credentials. Option A is wrong because Microsoft Entra ID service principals require managing credentials and are not the simplest approach for Batch compute nodes to access storage. Option B is wrong because storage account access keys are shared secrets that should not be exposed. Option D is wrong because shared access signatures (SAS) tokens can be exposed and need to be managed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Entra ID service principal

    Why it's wrong here

    A service principal authenticates the Batch service itself, not the individual compute nodes, so nodes still need credentials or managed identity tokens to reach Storage. Service principals suit unattended application-level access, such as automation scripts or pipelines authenticating to Microsoft Entra ID, rather than node-level storage authorisation.

  • ✗

    Storage account access keys

    Why it's wrong here

    Access keys are long-lived shared secrets that must be distributed to every compute node, directly violating the requirement to avoid exposing credentials. Keys are intended for administrative tooling or legacy applications that cannot use token-based authentication, not for granting pool nodes scoped, revocable access to Storage.

  • ✓

    Managed identity for the Batch pool

    Why this is correct

    Assigning a managed identity to the Batch pool lets compute nodes authenticate to Azure Storage through Microsoft Entra ID and receive tokens automatically, so no credentials are stored or exposed on the nodes. This satisfies the requirement for secure access without embedding secrets.

  • ✗

    Shared access signatures (SAS)

    Why it's wrong here

    SAS tokens are bearer credentials; anyone holding the URL can access storage, and distributing them to nodes still requires managing and rotating secrets. SAS suits scoped, time-limited external sharing, whereas the credential-free requirement is met by a managed identity assigned to the Batch pool.

About these practice questions

One of 883 original AZ-204 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.