AZ-305 Design data storage solutions Practice Question
Exhibit
Refer to the exhibit. ```sql SELECT OperationName, COUNT(*) AS OperationCount FROM StorageBlobLogs WHERE TimeGenerated > ago(1h) AND StatusCode == 404 GROUP BY OperationName ORDER BY OperationCount DESC ```
Refer to the exhibit. A KQL query is run against Azure Storage logs. The result shows a high number of 404 errors for 'GetBlob' operations. What is the most likely cause?
⚠ Common exam trap
Many exam-takers confuse 404 (Not Found) with 403 (Forbidden), assuming that a missing blob is caused by a permissions problem, but Azure strictly differentiates these status codes based on whether the resource exists versus whether access is denied.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The blobs being requested do not exist
A 404 (Not Found) error for 'GetBlob' operations in Azure Storage logs specifically indicates that the requested blob resource does not exist at the specified URI. This is distinct from authorization failures (which return 403) or throttling (which returns 503). The high number of 404 errors suggests the client is attempting to retrieve blobs that have been deleted, never created, or are referenced with an incorrect path.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The client does not have permission to access the blobs
Why it's wrong here
Permission failures in Azure Storage are surfaced as HTTP 403 Forbidden (with error code AuthorizationFailure or AuthenticationFailed). The KQL result shows StatusCode=404, which is a distinct class of error: the client was allowed to access the resource hierarchy, but the requested blob path has no object. A 403 is returned even before blob existence is checked when the client lacks identity, RBAC, or SAS permissions, so this option cannot explain a 404.
- ✗
The storage account is throttling requests
Why it's wrong here
Throttling by the storage account does not produce HTTP 404. When an account exceeds its ingress/egress limits, or a blob partition is heavily loaded, Azure Storage returns HTTP 503 (Server Busy) or 429 (Too Many Requests) with a Retry-After header to drive exponential backoff. In the exhibit, status code is 404, which unambiguously maps to BlobNotFound; throttling would instead show 429/503 and would affect all requests to that account or partition, not selectively lose a single blob.
- ✓
The blobs being requested do not exist
Why this is correct
A 404 response for a blob operation in Azure Storage corresponds to the BlobNotFound error code, meaning the specified blob does not exist at that path or has been deleted. Because the query returned this code rather than 403 or 429, authentication and rate limits were satisfied. The only remaining conclusion is that the requested blob (or its container) is missing, perhaps due to an incorrect name, a different container, or lifecycle policy deletion.
- ✗
The client is using an incorrect authentication method
Why it's wrong here
Using an incorrect authentication method—for example, presenting a Shared Key signature that doesn't match, an expired SAS, or an invalid OAuth token—causes Azure Storage to respond with HTTP 403 Forbidden or AuthenticationFailed, not 404. A 404 indicates the Storage service successfully validated the identity and the request signed correctly, and then began path lookup, which failed because the blob doesn't exist. Therefore, the authentication mechanism was irrelevant or correct; the cause is resource absence.
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.