Microsoft Azure Developer Associate AZ-204 Practice Question

A back-end Azure Function authenticates by using its system-assigned managed identity and obtains an OAuth 2.0 token for Azure Storage. The function must return a URL that lets a client application upload a single blob to the "uploads" container for the next 30 minutes, without exposing any storage account keys. Which type of shared access signature should the function generate?

  • Generate an account SAS that grants write permission to the Blob service.

  • Generate a user delegation SAS signed with the Azure Function's Azure AD credentials.

  • Generate a service SAS scoped to the "uploads" container and signed with the storage account key.

  • Create a stored access policy on the "uploads" container and send its identifier to the client.

Microsoft Azure Developer Associate AZ-204
Implement Azure security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot