AZ-500 Secure compute, storage, and databases Practice Question
You have an Azure Storage account that contains sensitive documents. You need to generate a time-limited, secure URL that allows a specific user to download a file without requiring storage account keys. What should you use?
⚠ Common exam trap
It's easy for candidates to confuse RBAC (which controls access via Microsoft Entra ID roles) with SAS (which generates a time-limited URL), leading them to choose RBAC because it seems more secure, but RBAC does not produce a direct download link and requires the user to have an Microsoft Entra ID identity and appropriate permissions at the time of access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Shared Access Signature (SAS)
A Shared Access Signature (SAS) is the correct choice because it provides delegated, time-limited access to a specific storage resource (e.g., a blob) without exposing the storage account keys. You can scope the SAS to a specific user by using a stored access policy or by generating a service SAS with fine-grained permissions, and you can enforce expiration and allowed IP ranges. This meets the requirement of a secure, time-bound URL for a single file download.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Front Door custom domain
Why it's wrong here
Azure Front Door custom domain is not a mechanism for generating time-limited access URLs. Front Door is a global load-balancing and content-delivery service that fronts origins, and a custom domain merely changes the endpoint's hostname. It provides no token-based authorization and cannot restrict access to a specific storage resource for a defined time window. SAS remains the service designed for delegated, expiry-bound URLs.
- ✗
Storage account access key
Why it's wrong here
Storage account access keys are master keys that grant full administrative and data-plane access to all resources within the storage account. They are static, persistent credentials with no built-in expiry, scoping, or permission granularity. Using a key to share a blob would expose the entire account and require manually rotating the key to revoke access, making it unsafe and unsuitable for time-limited sharing. SAS tokens are the correct alternative because they containerize permissions and duration.
- ✓
Shared Access Signature (SAS)
Why this is correct
A Shared Access Signature (SAS) is URI-based delegated authorization that grants time-limited, permission-scoped access to a specific blob, container, or service. You can set an expiration time, allowed permissions (read, write, delete, etc.), and even IP restrictions if needed. This makes it the ideal way to share sensitive data securely without exposing account keys. SAS tokens are the only option here that directly produce a URL with embedded authorization for direct access.
- ✗
Azure RBAC role assignment
Why it's wrong here
Azure RBAC role assignments control what an identity (user, group, or service principal) can do, such as granting the Storage Blob Data Reader role. However, RBAC does not generate a URL for direct anonymous access to a blob; it requires the client to authenticate with Entra ID and obtain an OAuth2 token. For sharing a specific blob via a URL, RBAC lacks the temporal and scoped link generation capability that SAS provides. Also, an RBAC role is tied to a principal, not to a requestor-agnostic link.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.