AZ-500 Secure compute, storage, and databases Practice Question
Your company has an Azure Cosmos DB account that stores customer profiles. You need to ensure that only authenticated and authorized users can access the data. Which access control method should you use?
⚠ Common exam trap
A common mix-up: candidates confuse network-level controls (IP firewall) or key-based access (primary keys or resource tokens) with proper identity-based authentication, overlooking that only Azure RBAC with Microsoft Entra ID provides per-user authorization without exposing secrets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Azure RBAC with Microsoft Entra ID authentication.
Azure RBAC with Microsoft Entra ID authentication provides fine-grained, identity-based access control for Azure Cosmos DB. This method allows you to assign specific roles (e.g., Cosmos DB Built-in Data Reader) to users or service principals, ensuring that only authenticated and authorized identities can access the data plane operations, such as reading or writing documents. It eliminates the need to share or manage keys, aligning with the principle of least privilege.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure an IP firewall rule to allow only corporate IP ranges.
Why it's wrong here
An IP firewall rule only restricts network traffic to a specific IP range; it does not identify or authenticate individual users or groups. Even though it narrows who can reach the account, any user inside the corporate network can still access the data without per-user authorization. It also doesn't support granular per-user permissions, auditing of individual actions, or revocation of a specific user's access, so it fails to meet the requirement for user-level access control.
- ✓
Use Azure RBAC with Microsoft Entra ID authentication.
Why this is correct
Azure RBAC with Microsoft Entra ID (formerly Azure AD) is the correct approach because Cosmos DB supports data-plane role assignments using Microsoft Entra identities. By assigning built-in roles like Cosmos DB Built-in Data Reader or Contributor to a user or group, you can grant fine-grained, identity-based access to specific databases/containers. This provides per-user authentication, follows the principle of least privilege, and integrates with conditional access and auditing, unlike shared secret keys.
- ✗
Use primary read-write keys with connection strings.
Why it's wrong here
Primary read-write keys are shared secrets that grant full administrative access to all data in the Cosmos DB account, including the ability to read, write, and delete any resource. They are not tied to an individual user's identity, so you cannot control what each user can do or audit their specific actions. Using them also creates a security risk because the key is a single point of compromise; anyone with the key has the same unrestricted access, making it unsuitable for identity-based fine-grained access control.
- ✗
Use resource tokens generated from a master key.
Why it's wrong here
Resource tokens are generated by a master key to provide scoped, time-limited access to specific containers or partitions, but they still rely on the master key being managed and distributed. They do not authenticate the actual user; instead, they act as bearer tokens that any holder can use, so they lack a direct tie to an individual Entra ID identity. Additionally, managing resource token issuance and expiration at scale is complex, and the master key remains a high-privilege secret that must be protected, making this not equivalent to true per-user RBAC.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.