SC-100 Practice Question: Design security solutions for applications and data
A company is designing a secure data sharing solution with a partner organization. The data will be stored in Azure Blob Storage. Requirements include: encryption at rest with customer-managed keys, granular access control to specific blobs, and the ability to expire access automatically. Which TWO solutions should you combine? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Generate shared access signatures (SAS) with specific permissions and expiry times.
Option A is correct because shared access signatures (SAS) let you delegate granular, time-limited access to specific blobs or containers, specifying exact permissions (read, write, etc.) and an expiry time, which directly satisfies the requirements for granular access control and automatic access expiration. Option E is correct because Azure Storage Service Encryption with customer-managed keys stored in Azure Key Vault provides encryption at rest where the customer controls the key lifecycle, meeting the customer-managed key requirement. Option B is not correct because enabling Microsoft Entra ID authentication alone does not provide granular per-blob access or automatic expiry; it is an authentication mechanism, not an access delegation or expiration feature. Option C is not correct because IP firewall rules restrict network access but do not provide granular blob-level permissions or automatic access expiration. Option D is not correct because the Storage Blob Data Reader role grants broad read access at the scope assigned and does not inherently expire, so it fails the granularity and automatic expiration requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Generate shared access signatures (SAS) with specific permissions and expiry times.
Why this is correct
SAS tokens provide granular, delegated access to specific Azure Storage resources, such as a single blob or container, with custom permissions (read, write, delete, list) and an expiry time. Because the token is signed with the storage account key or a user delegation key, the partner only needs the SAS URL, not Microsoft Entra ID credentials or network access, making it ideal for time-boxed data sharing. The ability to revoke a SAS before expiry (by regenerating the account key or using a stored access policy) adds operational control.
- ✗
Enable Microsoft Entra ID authentication for the storage account.
Why it's wrong here
Microsoft Entra ID authentication for Azure Storage (now called Entra ID) provides identity-based access control but does not natively support per-blob time-limited delegation; access is determined by RBAC role assignments that are not automatically time-bound. Furthermore, the partner organization would need to have Microsoft Entra ID identities that are trusted by the customer's tenant (via B2B collaboration) or be in the same tenant, which adds significant federation overhead. For a lightweight, expiring share of a single blob, SAS is simpler and does not require cross-tenant identity management.
- ✗
Configure a firewall on the storage account to allow only partner IP addresses.
Why it's wrong here
Storage account firewalls restrict network traffic to the storage endpoint based on source IP addresses or virtual networks, but they do not control who can access which blob; any client from an allowed IP can still attempt to access any blob, subject to other authorization (e.g., SAS or key). IP-based allow-listing is also fragile because partners may have dynamic or shared IP addresses, and it does not provide time-limited or permission-scoped access. This option solves the network boundary concern, not the data access granularity or expiry requirement.
- ✗
Use Azure RBAC to assign the Storage Blob Data Reader role to partner users.
Why it's wrong here
Azure RBAC, such as the Storage Blob Data Reader role, applies at the scope of a storage account, container, or individual blob, so it can technically be scoped to a blob, but role assignments do not include an expiry time by default and must be manually removed. Assigning the role to partner users requires those users to exist in the customer's Microsoft Entra ID, which again necessitates cross-tenant identity setup or guest accounts. SAS is more appropriate because it embeds expiration and permissions directly in the token, avoiding long-lived RBAC assignments that increase the risk of lingering access.
- ✓
Use Azure Storage Service Encryption with customer-managed keys in Azure Key Vault.
Why this is correct
Storage Service Encryption with customer-managed keys (CMK) in Azure Key Vault encrypts data at rest, but it is not an access control mechanism; it protects against unauthorized access to the underlying storage media or backup tapes, not against authorized clients with valid credentials. That said, for a secure data sharing solution, encryption at rest is a complementary security layer—using CMK gives the data owner independent control over key rotation and revocation, so if a key is disabled, the data becomes effectively inaccessible even to authorized users. Therefore, while not the primary mechanism for sharing, it is a valid and necessary part of a defense-in-depth design.
Quick reference
Azure Blob Storage Tier Comparison
| Tier | Storage Cost | Retrieval Cost | Latency | Use Case |
|---|---|---|---|---|
| Hot | Highest | Lowest | Immediate | Active data, frequent reads |
| Cool | Lower | Higher | Immediate | Data accessed < once / month |
| Cold | Lower still | Higher | Immediate | Data accessed < once / quarter |
| Archive | Lowest | Highest + rehydration delay | Hours | Long-term compliance retention |
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.