Courseiva

SC-100 Practice Question: Design security solutions for applications and data

Your organization uses Azure Data Lake Storage Gen2 for big data analytics. You need to secure access to the data using Azure RBAC and ACLs. Which two methods can you use to authorize access? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assign Azure RBAC roles such as Storage Blob Data Contributor to security principals.

Option B is correct because Azure Data Lake Storage Gen2 supports Azure RBAC role assignments, such as Storage Blob Data Contributor, Storage Blob Data Reader, and Storage Blob Data Owner, to authorize security principals (users, groups, service principals, managed identities) at the container or account scope. Option C is correct because ADLS Gen2 implements a POSIX-like ACL model at the directory and file level, allowing fine-grained read, write, and execute permissions for named users and groups in addition to RBAC. Option A is not a valid authorization method here; IP firewall rules are network-level access restrictions, not an authorization mechanism for data access. Option D is not itself an authorization method—managed identities are an identity type that must still be granted access via RBAC or ACLs. Option E is not the intended answer because SAS tokens are a delegation mechanism primarily associated with Blob Storage and are not the standard authorization approach for ADLS Gen2 hierarchical namespace access via RBAC and ACLs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure IP firewall rules to restrict access.

    Why it's wrong here

    IP firewall rules operate at the network layer, filtering traffic based on the source IP address or virtual network of the client attempting to reach the storage account endpoint. They do not authenticate or authorize the caller; a user who connects from an allowed IP still requires an identity-based permission (RBAC, ACL, SAS, or account key) to read or write data. Thus, IP rules are a network security control, not a data-plane authorization mechanism.

  • ✓

    Assign Azure RBAC roles such as Storage Blob Data Contributor to security principals.

    Why this is correct

    Azure RBAC role assignments are the recommended, identity-based authorization method for controlling access to Azure Data Lake Storage Gen2. Roles like Storage Blob Data Contributor grant a security principal (user, group, service principal, or managed identity) permissions at the storage account, container, or directory/file scope using Azure's centralized control plane. When a principal makes a request, Azure evaluates RBAC assignments, integrating with Microsoft Entra ID, to determine coarse-grained access such as read, write, delete, and list, making this the go-to choice for broad or automated access control.

  • ✓

    Set POSIX-like access control lists (ACLs) on directories and files.

    Why this is correct

    Azure Data Lake Storage Gen2 supports hierarchical ACLs that mirror POSIX permissions, allowing you to define read, write, and execute permissions for the owning user, owning group, named users, named groups, and others on each directory and file. ACLs operate at the data plane and are evaluated after RBAC, providing fine-grained, per-file/per-directory control required in a hierarchical namespace. This mechanism is essential when you need to distinguish access between different users within the same container, with effective permissions computed recursively through the directory tree.

  • ✗

    Use managed identities for Azure resources.

    Why it's wrong here

    Managed identities are Azure-issued service principals that provide an automatically rotated, secure identity for Azure resources like VMs, Logic Apps, and Function Apps to authenticate to services. They are a form of authentication, not an authorization method; authorization still requires assigning permissions to that identity (e.g., via RBAC or ACLs) before it can access storage data. Therefore, choosing managed identities alone does not grant any access — you must still explicitly assign a role such as Storage Blob Data Contributor, making this option incomplete for the authorization question.

  • ✗

    Generate shared access signatures (SAS) for delegated access.

    Why it's wrong here

    A shared access signature (SAS) is a cryptographically signed URI token that grants scoped, time-limited access to specific resources, but it is a delegation mechanism created from root credentials (account key, user delegation key, or stored access policy), not a permanent, identity-based authorization method. SAS tokens must be managed, rotated, and guarded like secrets, and they default to no integration with Microsoft Entra ID, so they aren't suitable for long-lived, identity-managed access. While user-delegation SAS can be backed by Microsoft Entra credentials, the design intent is short-lived client access, not the continuous authorization of security principals that RBAC/ACLs provide.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.