Microsoft Azure Security Engineer Associate AZ-500 Practice Question

Your company stores sensitive financial reports in a private Azure Blob Storage container. External auditors, who do not have Microsoft Entra ID accounts, need read-only access to a single report for the next two weeks. You must provide them with a URL that prevents container listing and automatically expires after the deadline. Which approach should you use?

  • Generate a service-level shared access signature scoped to the specific blob with Read permission and a two-week expiry.

  • Assign the auditors to the Storage Blob Data Reader role on the storage account and send them the blob URL.

  • Create an Azure AD user delegation SAS on the container with List and Read permissions.

  • Regenerate the storage account access keys immediately and again after two weeks.

Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot