AZ-305 Design data storage solutions Practice Question
You need to provide temporary shared access to a specific blob in Azure Storage for a contractor. The access must expire after 24 hours. Which feature should you use?
⚠ Common exam trap
Candidates often confuse managed identities or RBAC as suitable for temporary access, but neither provides time-bound, scoped delegation to a single blob without persistent permissions or full account access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Shared access signature (SAS)
A shared access signature (SAS) provides delegated, time-limited access to a specific Azure Storage resource, such as a blob, without exposing the storage account key. By configuring the SAS with an expiration time of 24 hours, you grant the contractor temporary access that automatically revokes after that period, meeting the requirement precisely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Managed identity
Why it's wrong here
A managed identity is an Microsoft Entra ID identity automatically assigned to an Azure resource (e.g., a VM, App Service, or Function) for authenticating to Azure services such as Blob Storage. It is not a credential that can be shared externally—it represents the resource itself, not an external user, and cannot generate a scoped, expiring URL for a specific blob. Therefore, using a managed identity would not satisfy the need to grant temporary, anonymous or user-specific access to a particular blob.
- ✗
Azure role-based access control (RBAC)
Why it's wrong here
Azure RBAC grants permissions to security principals (users, groups, or service principals) using role assignments that remain in effect until changed—they do not have a built-in expiration for a single operation. While you could assign a user the Storage Blob Data Reader role at blob scope, the assignment is persistent and cannot be embedded in a URL or automatically expire to meet a temporary shared access requirement. The proper use of RBAC would require adding and later manually removing the assignment, which is exactly the kind of time-limited, granular delegation SAS is designed to avoid.
- ✗
Storage account access key
Why it's wrong here
The storage account access key is the root-level credential for the entire storage account, granting full administrative control over all blobs, tables, queues, and files, and it has no built-in expiration or resource-level scope. Providing the account key would expose the whole account to the external party, not just the specific blob, and unlike a SAS, it cannot be distributed as a temporary, granular URL. Because the key is not time-limited and is not scoped to a single blob, it fails the core requirement.
- ✓
Shared access signature (SAS)
Why this is correct
A shared access signature (SAS) is a signed URI that contains query parameters (e.g., 'sp' for permissions, 'se' for expiry, 'sr' for resource type) and can be scoped precisely to a single blob while the signature is validated by Azure Storage. You can specify read permissions and a short expiration window, and optionally use a user delegation SAS signed with Microsoft Entra ID credentials to avoid using an account key. This is the standard Azure mechanism for granting temporary, delegated access to a specific blob without exposing the account key or requiring a persistent role assignment.
Go deeper
Related to this question
About these practice questions
One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.