Microsoft Azure Security Engineer Associate AZ-500 Practice Question
Your organization runs Windows Server 2019 file servers that are joined to an on-premises Active Directory domain that is synchronized to Azure AD. A site-to-site VPN to Azure already exists. You plan to migrate the departmental shares to Azure Files and map them as drives on the on-premises servers. Administrators must be able to apply user-level NTFS-style permissions and no long-lived secrets may be stored on the servers. Which access method should you configure for the Azure file shares?
Enable Active Directory Domain Services (AD DS) authentication for Azure Files and use Kerberos over SMB when mapping the drives.
Generate a shared access signature (SAS) for the file service and mount the shares with the SAS.
Mount the Azure file shares by using the storage account access keys.
Use Azure AD OAuth 2.0 authentication and pass an access token each time the drive is mapped.
Active Directory Domain Services (AD DS) authentication for Azure Files enables Kerberos over SMB, so users log on with their existing domain credentials and ACLs are enforced on the share and files. Because Kerberos tickets are obtained at logon, no storage account keys or SAS tokens need to be saved on the servers.
Using a storage account key grants share-wide access and requires the key to be stored on each server. A shared access signature still requires persisting the token and cannot enforce user-level access. Azure AD OAuth tokens work only with the file REST API, not with SMB drive mapping, so they cannot satisfy the requirement to map the share for Windows servers.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Kerberos authentication and why is it used for Azure Files?
Open an interactive chat with Bash
What are NTFS permissions and how do they integrate with Azure Files?
Open an interactive chat with Bash
Why can't Azure AD OAuth tokens or SAS tokens be used for Azure Files drive mapping?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .