Courseiva

AZ-500 Secure compute, storage, and databases Practice Question

Your company has an Azure Cosmos DB account that stores customer profiles. You need to ensure that only authenticated and authorized users can access the data. Which access control method should you use?

⚠ Common exam trap

A common mix-up: candidates confuse network-level controls (IP firewall) or key-based access (primary keys or resource tokens) with proper identity-based authentication, overlooking that only Azure RBAC with Microsoft Entra ID provides per-user authorization without exposing secrets.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Azure RBAC with Microsoft Entra ID authentication.

Azure RBAC with Microsoft Entra ID authentication provides fine-grained, identity-based access control for Azure Cosmos DB. This method allows you to assign specific roles (e.g., Cosmos DB Built-in Data Reader) to users or service principals, ensuring that only authenticated and authorized identities can access the data plane operations, such as reading or writing documents. It eliminates the need to share or manage keys, aligning with the principle of least privilege.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure an IP firewall rule to allow only corporate IP ranges.

    Why it's wrong here

    An IP firewall rule only restricts network traffic to a specific IP range; it does not identify or authenticate individual users or groups. Even though it narrows who can reach the account, any user inside the corporate network can still access the data without per-user authorization. It also doesn't support granular per-user permissions, auditing of individual actions, or revocation of a specific user's access, so it fails to meet the requirement for user-level access control.

  • ✓

    Use Azure RBAC with Microsoft Entra ID authentication.

    Why this is correct

    Azure RBAC with Microsoft Entra ID (formerly Azure AD) is the correct approach because Cosmos DB supports data-plane role assignments using Microsoft Entra identities. By assigning built-in roles like Cosmos DB Built-in Data Reader or Contributor to a user or group, you can grant fine-grained, identity-based access to specific databases/containers. This provides per-user authentication, follows the principle of least privilege, and integrates with conditional access and auditing, unlike shared secret keys.

  • ✗

    Use primary read-write keys with connection strings.

    Why it's wrong here

    Primary read-write keys are shared secrets that grant full administrative access to all data in the Cosmos DB account, including the ability to read, write, and delete any resource. They are not tied to an individual user's identity, so you cannot control what each user can do or audit their specific actions. Using them also creates a security risk because the key is a single point of compromise; anyone with the key has the same unrestricted access, making it unsuitable for identity-based fine-grained access control.

  • ✗

    Use resource tokens generated from a master key.

    Why it's wrong here

    Resource tokens are generated by a master key to provide scoped, time-limited access to specific containers or partitions, but they still rely on the master key being managed and distributed. They do not authenticate the actual user; instead, they act as bearer tokens that any holder can use, so they lack a direct tie to an individual Entra ID identity. Additionally, managing resource token issuance and expiration at scale is complex, and the master key remains a high-privilege secret that must be protected, making this not equivalent to true per-user RBAC.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.