Courseiva

AZ-305 Design data storage solutions Practice Question

Which TWO options are valid methods to secure access to Azure Cosmos DB?

⚠ Common exam trap

A common mix-up: candidates confuse Azure Cosmos DB authentication with Azure Storage authentication, mistakenly selecting SAS tokens or storage account keys, which are valid for Azure Storage but not for Cosmos DB.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure RBAC roles

Azure RBAC roles (Option C) provide fine-grained, role-based access control to Azure Cosmos DB, allowing you to assign permissions to users, groups, or service principals for operations like read, write, or delete on specific resources. Primary and secondary keys (Option D) are the default authentication method, enabling full access to the Cosmos DB account for data plane operations, and are commonly used for application connections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    X.509 certificate-based authentication

    Why it's wrong here

    X.509 certificate-based authentication is not natively supported by Azure Cosmos DB. The Cosmos DB REST API and SDKs do not accept client certificates as a credential for authenticating data-plane requests. Although Microsoft Entra ID can use an X.509 certificate for a service principal in some scenarios, Cosmos DB itself does not offer a native certificate-authentication flow, so this is not a valid method for securing access.

  • ✗

    Azure Storage account keys

    Why it's wrong here

    Azure Storage account keys are designed specifically for Azure Storage services such as Blob, Queue, Table, and File storage. They are not usable for authentication against Azure Cosmos DB because Cosmos DB maintains its own account keys and supports Microsoft Entra ID RBAC instead. Supplying a Storage account key to the Cosmos DB endpoint would be rejected because the two services use entirely different authentication mechanisms.

  • ✓

    Azure RBAC roles

    Why this is correct

    Azure RBAC roles are a valid method to secure access to Cosmos DB. For the control plane, built-in roles like DocumentDB Account Contributor let you manage the Cosmos DB account, while for the data plane, roles such as Cosmos DB Built-in Data Reader and Data Contributor allow Microsoft Entra ID identities to read or write data without using account keys. This provides fine-grained, identity-based access to databases and containers, making RBAC a supported alternative to key-based authentication.

  • ✓

    Primary and secondary keys

    Why this is correct

    Primary and secondary keys are valid authentication credentials for Cosmos DB. These account keys are used to generate the required authorization header for REST API and SDK requests, with secondary keys available for key rotation and read-only keys for limited access. They remain a supported and common method for securing access, though they should be protected in a vault because they grant broad access to account data.

  • ✗

    Shared access signatures (SAS)

    Why it's wrong here

    Shared access signatures (SAS) are not supported for Azure Cosmos DB. SAS tokens are a delegated authorization mechanism specific to Azure Storage services such as blobs, files, queues, and tables. Cosmos DB does not accept SAS tokens; it only authenticates requests through its account keys or Microsoft Entra ID RBAC tokens, so using a SAS is not a valid way to secure Cosmos DB access.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.