A blob container in an Azure subscription must be accessible to ten finance department users only for the month of April. Which security mechanism should you recommend to provide access limited to that period?
Choose an answer
Tap an option to check your answer.
Correct answer: shared access signatures (SAS).
Why this is the answer
Shared Access Signatures (SAS) are the most suitable mechanism for time-limited, granular access to Azure Storage resources. A SAS token can be configured to grant specific permissions (e.g., read, write, list) to a particular resource (e.g., a blob container) for a defined duration, such as the month of April. This allows access without sharing account keys. Conditional Access policies are for controlling access to applications and resources based on conditions like user location or device, not for granting time-limited access to storage containers directly. Certificates are used for authentication and encryption but don't inherently provide time-bound access to storage resources. Access keys provide full, unrestricted access to an entire storage account and are not suitable for granting limited, temporary access to specific users or resources.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed