Courseiva

AZ-500 Secure compute, storage, and databases Practice Question

You are deploying a web application that stores user-uploaded files in Azure Blob Storage. You need to ensure that only authenticated users can upload files, and that uploaded files are automatically scanned for malware. What should you use?

⚠ Common exam trap

It's easy for candidates to choose Event Grid (Option A) thinking it handles both authentication and scanning, but it only triggers scanning after upload and does not enforce authentication, missing the core requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Microsoft Entra ID authentication for the storage account and enable Microsoft Defender for Storage

Enabling Microsoft Entra ID authentication for the storage account ensures that only authenticated users (via Microsoft Entra ID) can upload files, while Microsoft Defender for Storage provides built-in malware scanning for uploaded blobs. This combination directly addresses both requirements without additional infrastructure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Azure Event Grid to trigger a function for malware scanning

    Why it's wrong here

    Event Grid can certainly publish blob-created events to an Azure Function for scanning, but that only creates an asynchronous event pipeline. It doesn't control or authenticate who performed the upload, because Event Grid is a message broker, not an authentication service. Any subject with write access to the storage account can still upload a malicious file, and the function would just scan it after the fact. Therefore, this option fails to meet the fundamental requirement of user authentication.

  • ✓

    Enable Microsoft Entra ID authentication for the storage account and enable Microsoft Defender for Storage

    Why this is correct

    Enabling Microsoft Entra ID authentication for the storage account replaces shared-key or SAS access with OAuth 2.0 tokens, allowing you to assign RBAC roles such as Storage Blob Data Contributor to individual users or service principals. This gives you per-user identity, conditional access, and audit logs for every upload. Microsoft Defender for Storage then continuously analyzes blob activity and scans files for malware using threat intelligence and hash reputation, alerting on detections and optionally applying high-confidence malware scans. Together these two controls address both identity and content security, which is exactly what the scenario requires.

  • ✗

    Configure Azure Firewall to allow only the web app's IP address

    Why it's wrong here

    Azure Firewall restricts network traffic based on source IP addresses and destination ports, but it cannot distinguish between different users behind the same IP. The web app's outbound IP is a shared public IP that represents the entire app service, so allowing it simply says 'this source is allowed' without verifying which user is making the request. It also provides no malware scanning of uploaded files. This is a network security control, not an identity or content-inspection control, so it doesn't satisfy the requirement.

  • ✗

    Use shared access signatures (SAS) with stored access policies

    Why it's wrong here

    A shared access signature with a stored access policy grants time-limited, permission-scoped access to a container or blob, but the SAS token itself is a secret string that is not tied to any individual user's identity. Anyone who obtains the SAS URL, even if it was issued for someone else, can use it to upload files, so there is no per-user authentication. The stored access policy only lets you revoke or set permissions/expiry; it doesn't create an audit trail of which person performed the upload. Additionally, SAS provides no malware detection.

Quick reference

Azure Blob Storage Tier Comparison

TierStorage CostRetrieval CostLatencyUse Case
HotHighestLowestImmediateActive data, frequent reads
CoolLowerHigherImmediateData accessed < once / month
ColdLower stillHigherImmediateData accessed < once / quarter
ArchiveLowestHighest + rehydration delayHoursLong-term compliance retention

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.