Courseiva

AZ-500 Secure compute, storage, and databases Practice Question

A company generates shared access signature (SAS) tokens to grant time-limited access to blobs in an Azure Storage container. A security administrator needs the ability to immediately revoke all active SAS tokens for that container if a token is compromised. What should they use?

⚠ Common exam trap

It's easy for candidates to assume that regenerating storage account keys (which invalidates account-level SAS tokens) is the fastest way to revoke access, but that approach is overly broad and disruptive, whereas a stored access policy provides granular, immediate revocation for a specific container without affecting other resources.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a stored access policy on the container and reference it in the SAS token.

A stored access policy on the container provides a centralized way to manage permissions for shared access signatures (SAS). By associating the SAS token with the policy, you can immediately revoke all tokens that reference that policy by simply deleting or modifying the policy's permissions or expiry time. This is the only method that allows instant revocation of multiple SAS tokens without waiting for their individual expiry.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use a stored access policy on the container and reference it in the SAS token.

    Why this is correct

    By attaching the SAS to a stored access policy defined on the container, you gain a centralized revocation point: deleting or shortening the policy's expiry immediately invalidates every SAS token that references it, regardless of the token's own expiry time. Because the policy controls permissions, start time, and expiry, you can also modify access after issuance without redeploying new tokens. This is why a stored access policy is required for full revocation control in Azure Storage.

  • ✗

    Use a user delegation key to create the SAS token.

    Why it's wrong here

    A user delegation SAS is signed with a user delegation key that is obtained from Microsoft Entra ID and valid for at most 7 days. Although this approach avoids using the storage account key, it does not give you per-SAS revocation; you cannot invalidate an individual token without invalidating the entire delegation key, and even then the key remains valid until it expires. Therefore, it fails the requirement of immediate, centralized revocation for a single SAS.

  • ✗

    Use an account-level SAS token.

    Why it's wrong here

    Creating an account-level SAS token grants access to all services (blobs, files, queues, tables) and all containers under the storage account, far exceeding the requested scope of a single container. To revoke that token, you would have to regenerate the storage account key, which breaks every application and SAS token that depends on that key. That is a heavy-handed operation and is not an acceptable solution when you need to invalidate just one SAS token.

  • ✗

    Use a service-level SAS token with IP address restrictions.

    Why it's wrong here

    Scoping a service-level SAS with IP address restrictions only limits which source IP addresses may present the token; it does not provide any mechanism to revoke the token after issuance. The token remains valid until its expiry (or until the storage account key is rotated), so it cannot be invalidated centrally and immediately. Since the request requires delegated access on a container that can be revoked instantly, IP restrictions alone are insufficient.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.