Courseiva

AZ-500 Secure compute, storage, and databases Practice Question

Your company uses Azure Files shares to store business documents. You need to ensure that access to the shares is restricted to users who have been granted explicit permissions. What should you configure?

⚠ Common exam trap

It's easy for candidates to confuse network-level restrictions (firewall rules) or token-based access (SAS) with identity-based access control, mistakenly believing that restricting IP ranges or using SAS tokens satisfies the requirement for explicit user permissions, when in fact only identity-based authentication with Microsoft Entra ID provides per-user authorization.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable identity-based authentication for Azure Files using Microsoft Entra ID and set share-level permissions.

Identity-based authentication for Azure Files using Microsoft Entra ID allows you to assign share-level permissions (e.g., Storage File Data SMB Share Contributor) to specific users or groups, ensuring only explicitly authorized identities can access the share. This meets the requirement of restricting access to users with explicit permissions, as opposed to relying on network rules or shared keys.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a firewall rule to allow only corporate IP ranges.

    Why it's wrong here

    An IP firewall rule restricts access by network origin, not by user identity, so any user on a permitted range reaches the share regardless of granted permissions. It is tempting for narrowing exposure, but the requirement is per-user authorisation, which Microsoft Entra ID authentication with RBAC or ACLs delivers instead.

  • ✗

    Use storage account access keys to mount the file share.

    Why it's wrong here

    Storage account access keys authenticate the account itself, granting full administrative access to anyone possessing the key rather than restricting to individually authorised users. It is tempting because keys mount shares simply, but identity-based authorisation through Microsoft Entra ID with RBAC or NTFS ACLs is what enforces explicit per-user permissions.

  • ✓

    Enable identity-based authentication for Azure Files using Microsoft Entra ID and set share-level permissions.

    Why this is correct

    Identity-based authentication via Microsoft Entra ID maps a user's token to a share-level role assignment (Storage File Data SMB Share Reader, Contributor, or Elevated Contributor), so only principals explicitly granted those roles gain access. This satisfies the stem's requirement that access be restricted to users holding granted permissions, unlike storage account key access, which grants unrestricted share access.

  • ✗

    Generate a shared access signature (SAS) with read permissions.

    Why it's wrong here

    A SAS grants bearer access to anyone holding the token, independent of user identity or explicit permission grants, so it cannot enforce per-user authorisation. It is tempting for scoped, time-limited delegation, but the requirement calls for identity-based access via Microsoft Entra ID with assigned permissions.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.