Microsoft Azure Administrator Associate AZ-104 Practice Question
An Azure administrator needs to ensure that members of a specific user group have access to blob data in a storage account using identity-based authentication. What is the best way to configure this?
You selected this option
Generate shared access signatures and distribute them to the users
You selected this option
Provide the storage account access keys to the users
You selected this option
Assign the Storage Blob Data Contributor role to the group for the storage account
You selected this option
Enable access policies in the storage account settings for the group
Assigning the Storage Blob Data Contributor role to the Azure Active Directory (Azure AD) group for the storage account is the best approach. This grants the group permissions to read, write, and delete blob data, and leverages Azure AD for authentication and authorization. It provides fine-grained access control and is managed centrally through Azure AD. Generating shared access signatures or distributing access keys is less secure and doesn't utilize identity-based access control. Enabling access policies in the storage account settings is not a method for granting permissions to Azure AD groups.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the Storage Blob Data Contributor role?
Open an interactive chat with Bash
What is identity-based authentication in Azure?
Open an interactive chat with Bash
What are Shared Access Signatures (SAS) and how do they compare to role-based access control?
Open an interactive chat with Bash
Microsoft Azure Administrator Associate AZ-104
Implement and manage storage
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Oh snap!
Loading...
Loading...
Loading...
Information Technology Package Join Premium for Full Access