Courseiva

SC-100 Practice Question: Design security solutions for applications and data

A company is designing a secure data sharing solution with a partner organization. The data will be stored in Azure Blob Storage. Requirements include: encryption at rest with customer-managed keys, granular access control to specific blobs, and the ability to expire access automatically. Which TWO solutions should you combine? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Generate shared access signatures (SAS) with specific permissions and expiry times.

Option A is correct because shared access signatures (SAS) let you delegate granular, time-limited access to specific blobs or containers, specifying exact permissions (read, write, etc.) and an expiry time, which directly satisfies the requirements for granular access control and automatic access expiration. Option E is correct because Azure Storage Service Encryption with customer-managed keys stored in Azure Key Vault provides encryption at rest where the customer controls the key lifecycle, meeting the customer-managed key requirement. Option B is not correct because enabling Microsoft Entra ID authentication alone does not provide granular per-blob access or automatic expiry; it is an authentication mechanism, not an access delegation or expiration feature. Option C is not correct because IP firewall rules restrict network access but do not provide granular blob-level permissions or automatic access expiration. Option D is not correct because the Storage Blob Data Reader role grants broad read access at the scope assigned and does not inherently expire, so it fails the granularity and automatic expiration requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Generate shared access signatures (SAS) with specific permissions and expiry times.

    Why this is correct

    SAS tokens provide granular, delegated access to specific Azure Storage resources, such as a single blob or container, with custom permissions (read, write, delete, list) and an expiry time. Because the token is signed with the storage account key or a user delegation key, the partner only needs the SAS URL, not Microsoft Entra ID credentials or network access, making it ideal for time-boxed data sharing. The ability to revoke a SAS before expiry (by regenerating the account key or using a stored access policy) adds operational control.

  • ✗

    Enable Microsoft Entra ID authentication for the storage account.

    Why it's wrong here

    Microsoft Entra ID authentication for Azure Storage (now called Entra ID) provides identity-based access control but does not natively support per-blob time-limited delegation; access is determined by RBAC role assignments that are not automatically time-bound. Furthermore, the partner organization would need to have Microsoft Entra ID identities that are trusted by the customer's tenant (via B2B collaboration) or be in the same tenant, which adds significant federation overhead. For a lightweight, expiring share of a single blob, SAS is simpler and does not require cross-tenant identity management.

  • ✗

    Configure a firewall on the storage account to allow only partner IP addresses.

    Why it's wrong here

    Storage account firewalls restrict network traffic to the storage endpoint based on source IP addresses or virtual networks, but they do not control who can access which blob; any client from an allowed IP can still attempt to access any blob, subject to other authorization (e.g., SAS or key). IP-based allow-listing is also fragile because partners may have dynamic or shared IP addresses, and it does not provide time-limited or permission-scoped access. This option solves the network boundary concern, not the data access granularity or expiry requirement.

  • ✗

    Use Azure RBAC to assign the Storage Blob Data Reader role to partner users.

    Why it's wrong here

    Azure RBAC, such as the Storage Blob Data Reader role, applies at the scope of a storage account, container, or individual blob, so it can technically be scoped to a blob, but role assignments do not include an expiry time by default and must be manually removed. Assigning the role to partner users requires those users to exist in the customer's Microsoft Entra ID, which again necessitates cross-tenant identity setup or guest accounts. SAS is more appropriate because it embeds expiration and permissions directly in the token, avoiding long-lived RBAC assignments that increase the risk of lingering access.

  • ✓

    Use Azure Storage Service Encryption with customer-managed keys in Azure Key Vault.

    Why this is correct

    Storage Service Encryption with customer-managed keys (CMK) in Azure Key Vault encrypts data at rest, but it is not an access control mechanism; it protects against unauthorized access to the underlying storage media or backup tapes, not against authorized clients with valid credentials. That said, for a secure data sharing solution, encryption at rest is a complementary security layer—using CMK gives the data owner independent control over key rotation and revocation, so if a key is disabled, the data becomes effectively inaccessible even to authorized users. Therefore, while not the primary mechanism for sharing, it is a valid and necessary part of a defense-in-depth design.

Quick reference

Azure Blob Storage Tier Comparison

TierStorage CostRetrieval CostLatencyUse Case
HotHighestLowestImmediateActive data, frequent reads
CoolLowerHigherImmediateData accessed < once / month
ColdLower stillHigherImmediateData accessed < once / quarter
ArchiveLowestHighest + rehydration delayHoursLong-term compliance retention

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.