A research group needs to grant read-only access to a storage blob. What should they use?
Choose an answer
Tap an option to check your answer.
Correct answer: Shared Access Signature (SAS).
Why this is the answer
A Shared Access Signature (SAS) is the correct choice because it provides delegated access to resources in your storage account with fine-grained control over what a client can access, for how long, and with what permissions. For read-only access to a specific blob, a SAS token can be generated with only read permissions for that blob, ensuring the research group can view the data without modifying or deleting it. Azure Monitor is for collecting, analyzing, and acting on telemetry data. Azure Logic Apps are for automating workflows and integrating systems. Azure ExpressRoute is for creating private connections between Azure data centers and on-premises infrastructure. None of these alternatives are designed for granting granular, time-limited access to storage resources.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed