AZ-305 Design data storage solutions Practice Question
Which TWO options are valid methods to secure access to Azure Cosmos DB?
⚠ Common exam trap
A common mix-up: candidates confuse Azure Cosmos DB authentication with Azure Storage authentication, mistakenly selecting SAS tokens or storage account keys, which are valid for Azure Storage but not for Cosmos DB.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure RBAC roles
Azure RBAC roles (Option C) provide fine-grained, role-based access control to Azure Cosmos DB, allowing you to assign permissions to users, groups, or service principals for operations like read, write, or delete on specific resources. Primary and secondary keys (Option D) are the default authentication method, enabling full access to the Cosmos DB account for data plane operations, and are commonly used for application connections.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
X.509 certificate-based authentication
Why it's wrong here
X.509 certificate-based authentication is not natively supported by Azure Cosmos DB. The Cosmos DB REST API and SDKs do not accept client certificates as a credential for authenticating data-plane requests. Although Microsoft Entra ID can use an X.509 certificate for a service principal in some scenarios, Cosmos DB itself does not offer a native certificate-authentication flow, so this is not a valid method for securing access.
- ✗
Azure Storage account keys
Why it's wrong here
Azure Storage account keys are designed specifically for Azure Storage services such as Blob, Queue, Table, and File storage. They are not usable for authentication against Azure Cosmos DB because Cosmos DB maintains its own account keys and supports Microsoft Entra ID RBAC instead. Supplying a Storage account key to the Cosmos DB endpoint would be rejected because the two services use entirely different authentication mechanisms.
- ✓
Azure RBAC roles
Why this is correct
Azure RBAC roles are a valid method to secure access to Cosmos DB. For the control plane, built-in roles like DocumentDB Account Contributor let you manage the Cosmos DB account, while for the data plane, roles such as Cosmos DB Built-in Data Reader and Data Contributor allow Microsoft Entra ID identities to read or write data without using account keys. This provides fine-grained, identity-based access to databases and containers, making RBAC a supported alternative to key-based authentication.
- ✓
Primary and secondary keys
Why this is correct
Primary and secondary keys are valid authentication credentials for Cosmos DB. These account keys are used to generate the required authorization header for REST API and SDK requests, with secondary keys available for key rotation and read-only keys for limited access. They remain a supported and common method for securing access, though they should be protected in a vault because they grant broad access to account data.
- ✗
Shared access signatures (SAS)
Why it's wrong here
Shared access signatures (SAS) are not supported for Azure Cosmos DB. SAS tokens are a delegated authorization mechanism specific to Azure Storage services such as blobs, files, queues, and tables. Cosmos DB does not accept SAS tokens; it only authenticates requests through its account keys or Microsoft Entra ID RBAC tokens, so using a SAS is not a valid way to secure Cosmos DB access.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Azure Database Migration Service
Key term
Cosmos DB Design
Cosmos DB Design is the process of structuring data and choosing configuration settings in Azure Cosmos DB to ensure fast performance, low cost, and scalability for applications.
Key term
Role Based Access Control Design
Role Based Access Control Design is the process of planning and defining who can access specific resources in a system based on their job role, not their identity.
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.