Microsoft Azure Security Engineer Associate AZ-500 Practice Question

You manage an Azure Storage account that contains multiple blob containers. A managed identity named app-mi used by a web app must be able to upload and download blobs only from the container named images. The solution must use Azure AD authorization and must not expose any shared keys or SAS tokens. Which action should you perform?

  • Generate a user-delegation SAS for app-mi with read and write permissions on the images container.

  • Assign the built-in role Storage Blob Data Owner to app-mi, scoped to the storage account.

  • Assign the built-in role Storage Account Contributor to app-mi at the resource-group level.

  • Assign the built-in role Storage Blob Data Contributor to app-mi, scoped to the images container.

Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot