AZ-500 Secure compute, storage, and databases Practice Question
You are deploying a web application that stores user-uploaded files in Azure Blob Storage. You need to ensure that only authenticated users can upload files, and that uploaded files are automatically scanned for malware. What should you use?
⚠ Common exam trap
It's easy for candidates to choose Event Grid (Option A) thinking it handles both authentication and scanning, but it only triggers scanning after upload and does not enforce authentication, missing the core requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Microsoft Entra ID authentication for the storage account and enable Microsoft Defender for Storage
Enabling Microsoft Entra ID authentication for the storage account ensures that only authenticated users (via Microsoft Entra ID) can upload files, while Microsoft Defender for Storage provides built-in malware scanning for uploaded blobs. This combination directly addresses both requirements without additional infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Azure Event Grid to trigger a function for malware scanning
Why it's wrong here
Event Grid can certainly publish blob-created events to an Azure Function for scanning, but that only creates an asynchronous event pipeline. It doesn't control or authenticate who performed the upload, because Event Grid is a message broker, not an authentication service. Any subject with write access to the storage account can still upload a malicious file, and the function would just scan it after the fact. Therefore, this option fails to meet the fundamental requirement of user authentication.
- ✓
Enable Microsoft Entra ID authentication for the storage account and enable Microsoft Defender for Storage
Why this is correct
Enabling Microsoft Entra ID authentication for the storage account replaces shared-key or SAS access with OAuth 2.0 tokens, allowing you to assign RBAC roles such as Storage Blob Data Contributor to individual users or service principals. This gives you per-user identity, conditional access, and audit logs for every upload. Microsoft Defender for Storage then continuously analyzes blob activity and scans files for malware using threat intelligence and hash reputation, alerting on detections and optionally applying high-confidence malware scans. Together these two controls address both identity and content security, which is exactly what the scenario requires.
- ✗
Configure Azure Firewall to allow only the web app's IP address
Why it's wrong here
Azure Firewall restricts network traffic based on source IP addresses and destination ports, but it cannot distinguish between different users behind the same IP. The web app's outbound IP is a shared public IP that represents the entire app service, so allowing it simply says 'this source is allowed' without verifying which user is making the request. It also provides no malware scanning of uploaded files. This is a network security control, not an identity or content-inspection control, so it doesn't satisfy the requirement.
- ✗
Use shared access signatures (SAS) with stored access policies
Why it's wrong here
A shared access signature with a stored access policy grants time-limited, permission-scoped access to a container or blob, but the SAS token itself is a secret string that is not tied to any individual user's identity. Anyone who obtains the SAS URL, even if it was issued for someone else, can use it to upload files, so there is no per-user authentication. The stored access policy only lets you revoke or set permissions/expiry; it doesn't create an audit trail of which person performed the upload. Additionally, SAS provides no malware detection.
Quick reference
Azure Blob Storage Tier Comparison
| Tier | Storage Cost | Retrieval Cost | Latency | Use Case |
|---|---|---|---|---|
| Hot | Highest | Lowest | Immediate | Active data, frequent reads |
| Cool | Lower | Higher | Immediate | Data accessed < once / month |
| Cold | Lower still | Higher | Immediate | Data accessed < once / quarter |
| Archive | Lowest | Highest + rehydration delay | Hours | Long-term compliance retention |
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.